# Elastic / Kibana

EvoHub receives Kibana alerts through a **Webhook connector** used by your alerting rules. Each rule gets two actions with the same body: one when the alert is active, one when it recovers. The recovered action resolves the EvoHub alert.

## Set it up

:::steps
### Create the integration
In EvoHub, go to **On-Call → Integrations → + Add Integration**, choose **Elastic / Kibana**, pick an **Escalation Policy** and click **Create Integration**. Copy the **Webhook URL**.
### Create the connector
In Kibana, go to **Stack Management → Connectors → Create connector → Webhook**. Set **Method** to `POST`, **URL** to your webhook URL and add the header `Content-Type: application/json`.
### Add two actions to each rule
Edit the rule and add the connector under **Actions** twice: once with **Run when** set to the rule's active (firing) group, once with **Run when** *Recovered*. Set the action frequency to **On status changes** for each alert, not a summary of alerts. Use the body below for both.
:::

```json
{"rule_id":"{{rule.id}}","rule_name":"{{rule.name}}","rule_url":"{{rule.url}}","alert_id":"{{alert.id}}","action_group":"{{alert.actionGroup}}","reason":"{{context.reason}}","severity":"{{context.rule.severity}}","tags":"{{rule.tags}}"}
```

The connector's **Test** tab sends the body with the variables unfilled. EvoHub answers with success and opens no alert.

## What EvoHub reads

| EvoHub alert | Taken from |
| --- | --- |
| Title | `rule_name`, followed by `alert_id` in brackets (the host or group the alert is for). |
| Description | `reason`. |
| Severity | `severity` when the rule has one (security detection rules); otherwise **high**. |
| Labels | `rule_id`, `alert_id`, `action_group`, `tags`, and `url` (the rule's link). |

## Resolve and deduplication

- An alert is identified by the rule and `alert_id`, so each host or group of a rule is its own EvoHub alert, and repeats while it is open are recorded as **Retriggered**.
- The **Recovered** action sends `action_group` `recovered`, which resolves the matching alert.

## Related

- [Integrations overview](https://docs-dev.evohub.io/integrations-overview.md)
- [Sumo Logic](https://docs-dev.evohub.io/sumo-logic.md)
