# Looking for Alert rule dataview and index

**URL:** <https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-alerting\
**Created:** [March 27, 2026, 2:03am UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650 "2026-03-27T02:03:00Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [March 27, 2026, 2:03am UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/1 "2026-03-27T02:03:00Z")

</div>

Using the API we can get the index of the alert that it is being used

curl   
--request GET '[https://localhost:5601/api/alerting/rules/\_find](https://localhost:5601/api/alerting/rules/_find)' \

If I want to use a query which default dataview or default index for all alert rule should i be looking at?

I was trying to find from the official Elasticsearch documentation for Elastic Stack Monitoring Integration but to no avail.

We are reindexing our index. So we are not sure if that will impact any of our alerts.

Kindly advice

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [March 27, 2026, 6:21am UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/2 "2026-03-27T06:21:19Z")

</div>

Hello @Whoami1980

I am not sure what is the exact query. The below index i see has information about alert status for all spaces :

`.kibana_alerting_cases_*`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/2/9287754ebdaa259fdfecef775700ac2dccd9d1a2.png)

Thanks!!

---

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [March 27, 2026, 7:22am UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/3 "2026-03-27T07:22:17Z")

</div>

the ".kibana\_alerting\_cases\_\*" return values but not the data view below.

btw is your screenshot . analytics \>\> discover \>\> dataview.

cause i try to put ".kibana\_alerting\_cases\_\*" but cant find in the gui

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/f/9f97a825ce07ae0c30e544f7f0f985a9368337bc.png)

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [March 27, 2026, 7:36am UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/4 "2026-03-27T07:36:15Z")

</div>

Hello @Whoami1980

You need to create a dataview with the index pattern if you want to use a dataview.

Thanks!!

---

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [March 27, 2026, 7:40am UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/5 "2026-03-27T07:40:25Z")

</div>

@Tortoise

Maybe i have not been clear. the reason we are using the query is because

we want to query what dataview or default index is currently configured for all our alert rule

hope that clarifies

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 27, 2026, 12:44pm UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/6 "2026-03-27T12:44:07Z")

</div>

> [@Whoami1980](#):
>
> we want to query what dataview or default index is currently configured for all our alert rule

You should use the API to get this information.

The rules will be saved internally in Kibana as saved objects, it is no something that you can simple make a query to an index, there is no documentation on how and where they are stored as it is expected that the detection rules API to be used in this case.

If you want you can query the `.internal.alerts-security*` indices, this is where the alerts that triggered will be stored, you have some information about the rules that triggered the alert.

---

<div class="post-metadata">

**Author:** ![Whoami1980](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/whoami1980/32/147545_2.png) [@Whoami1980](https://discuss.elastic.co/u/Whoami1980)\
**Post date:** [March 30, 2026, 9:02am UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/7 "2026-03-30T09:02:24Z")

</div>

@leandrojmp

I tried to run the API get for alerts in devtools but to no avail

```auto
GET /api/alerting/_health
{
  "error": "no handler found for uri [/api/alerting/_health?pretty=true] and method [GET]"
}

GET /alerting/_health
{
  "error": "Incorrect HTTP method for uri [/alerting/_health?pretty=true] and method [GET], allowed: [POST]",
  "status": 405
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 30, 2026, 1:30pm UTC](https://discuss.elastic.co/t/looking-for-alert-rule-dataview-and-index/385650/8 "2026-03-30T13:30:39Z")

</div>

This is a Kibana API, if you run in Dev Tools you need to use `GET kbn:/api/endpoint`
