Integrations
Elastic / Kibana
EvoHub receives Kibana alerts through a Webhook connector used by your alerting rules. Each rule gets two actions with the same body: one when the alert is active, one when it recovers. The recovered action resolves the EvoHub alert.
Set it up
Create the integration
In EvoHub, go to On-Call → Integrations → + Add Integration, choose Elastic / Kibana, pick an Escalation Policy and click Create Integration. Copy the Webhook URL.
{"rule_id":"{{rule.id}}","rule_name":"{{rule.name}}","rule_url":"{{rule.url}}","alert_id":"{{alert.id}}","action_group":"{{alert.actionGroup}}","reason":"{{context.reason}}","severity":"{{context.rule.severity}}","tags":"{{rule.tags}}"}
The connector's Test tab sends the body with the variables unfilled. EvoHub answers with success and opens no alert.
What EvoHub reads
| EvoHub alert | Taken from |
|---|---|
| Title | rule_name, followed by alert_id in brackets (the host or group the alert is for). |
| Description | reason. |
| Severity | severity when the rule has one (security detection rules); otherwise high. |
| Labels | rule_id, alert_id, action_group, tags, and url (the rule's link). |
Resolve and deduplication
- An alert is identified by the rule and
alert_id, so each host or group of a rule is its own EvoHub alert, and repeats while it is open are recorded as Retriggered. - The Recovered action sends
action_grouprecovered, which resolves the matching alert.
Related
Was this page helpful?
