You can create an action policy to manage how alert notifications are sent. You can configure an action policy to dynamically send alert notifications to specified users, user groups, or on-duty groups. You can also configure an action policy to escalate an alert that remains unconfirmed or unresolved for a long period of time.


  1. Log on to the Log Service console.
  2. Go to the Action Policy tab.
    1. In the Projects section, click the project that you want to view.
    2. In the left-side navigation pane, click Alerts.
    3. On the Alert Center page, choose Alert Management > Action Policy.
  3. On the Action Policy tab, click Create.
  4. In the Add Action Policy dialog box, set the ID and Name parameters.
  5. Add a primary action policy.
    1. On the Primary Action Policy tab, click the Condition icon.
    2. Specify a condition to trigger an alert.
      Parameter Description
      • All: The specified action policy is executed only if all alerts in a merge set meet the specified condition.
      • Any: The specified action policy is executed if one or more of the alerts in a merge set meet the specified condition.
      Conditional expressions Alerts that meet a conditional expression are processed based on the specified action policy. You can specify an object, an operator, and an object value for the conditional expression. For example, you can set the object to an Alibaba Cloud account and set the object value to 174****2745.
      You can add multiple conditions in standard mode or advanced mode.
      • Standard Mode: If you specify multiple conditions, the conditions are associated by using the AND operator.
      • Advanced Mode: If you specify multiple conditions, you can use the AND operator or the OR operator to associate the conditions. You can also group multiple conditions into one group by using parentheses.
    3. Configure an action group.
      Set the parameters displayed in the Log Service console to configure notification methods. For more information, see Notification methods.
      Note If you set the Notification Method parameter to EventBridge or Function Compute, you must authorize Log Service as prompted. This operation is required only once. During the authorization process, a service-linked role named AliyunServiceRoleForSLSAlert is automatically created. Then, Log Service can assume the service-linked role to access the resources of Alibaba Cloud services such as EventBridge and Function Compute.
    4. Click the End icon next to the Condition or Action Group dialog box to end the configuration.
      If you want to add more conditions and action groups, click the Condition icon.
  6. Optional:Configure a secondary action policy.
    You can configure a secondary action policy to handle an alert that remains unresolved for a long period of time. You can turn on Enabled on the Secondary Action Policy tab and set the parameters. For more information, see Step 5.
  7. Click OK.

What to do next

  • Delete a node

    Right-click the node that you want to delete and select Delete Node.

    Delete a node
  • Add a node
    Note If you have added the End node, you must delete the End node before you can add nodes such as Condition and Action Group.
    • Click the Condition icon to add a Condition node.
    • Click the Action Policy icon to add an Action Group node.
    • Click the End icon to add an End node.
    Action Policy