EvoHub Docs Sign in

Integrations

Elastic / Kibana

Use with AI
View as MarkdownThis page as plain text, for pasting into an AI tool Open in ClaudeAsk Claude questions about this page Open in ChatGPTAsk ChatGPT questions about this page
Connect to Cursor / VS Code / ClaudeSearch and read these docs from your AI tool (MCP server)

MCP server URL

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai and Claude Desktop): Settings → Connectors → Add custom connector, and paste the URL above.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

EvoHub receives Kibana alerts through a Webhook connector used by your alerting rules. Each rule gets two actions with the same body: one when the alert is active, one when it recovers. The recovered action resolves the EvoHub alert.

Set it up

Create the integration

In EvoHub, go to On-Call → Integrations → + Add Integration, choose Elastic / Kibana, pick an Escalation Policy and click Create Integration. Copy the Webhook URL.

Create the connector

In Kibana, go to Stack Management → Connectors → Create connector → Webhook. Set Method to POST, URL to your webhook URL and add the header Content-Type: application/json.

Add two actions to each rule

Edit the rule and add the connector under Actions twice: once with Run when set to the rule's active (firing) group, once with Run when Recovered. Set the action frequency to On status changes for each alert, not a summary of alerts. Use the body below for both.

{"rule_id":"{{rule.id}}","rule_name":"{{rule.name}}","rule_url":"{{rule.url}}","alert_id":"{{alert.id}}","action_group":"{{alert.actionGroup}}","reason":"{{context.reason}}","severity":"{{context.rule.severity}}","tags":"{{rule.tags}}"}

The connector's Test tab sends the body with the variables unfilled. EvoHub answers with success and opens no alert.

What EvoHub reads

EvoHub alert Taken from
Title rule_name, followed by alert_id in brackets (the host or group the alert is for).
Description reason.
Severity severity when the rule has one (security detection rules); otherwise high.
Labels rule_id, alert_id, action_group, tags, and url (the rule's link).

Resolve and deduplication

  • An alert is identified by the rule and alert_id, so each host or group of a rule is its own EvoHub alert, and repeats while it is open are recorded as Retriggered.
  • The Recovered action sends action_group recovered, which resolves the matching alert.

Last updated