Skip to content
Notis

Check attachment evidence without losing incident focus

When an incident points to a known attachment, Notis can retrieve its metadata for a quick evidence check.

Trigger

Webhook received

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

Action

Retrieve Event Attachment Metadata

Tool to retrieve metadata for an attachment on a specified event. use when you have asset uuid, event uuid, and attachment uuid and need details like size, hash, and scan status.

Why this helps

Verifying whether an evidence attachment is present and scanned takes attention away from response work.

  • Retrieve metadata for a known event attachment.
  • See details such as its hash and scan status.
  • Keep the response centered on the incident.

Setup

Build it in a few focused steps.

  • 1Connect Better Stack and Rkvst to Notis once through the portal.
  • 2Create an automation in the portal or ask Notis for it in plain language.
  • 3Prompt Notis to retrieve metadata for the specified Rkvst event attachment when an incident webhook includes its references.
  • 4Select an incoming webhook trigger and a channel for run reports.
  • 5Test with a real event and attachment reference, then confirm the metadata is for the expected item.

Questions about this workflow

What identifiers are needed?

The action requires the asset UUID, event UUID, and attachment UUID.

Does this download the attachment?

No. It retrieves attachment metadata, including details such as size, hash, and scan status.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Better stack to Rkvst. A trigger fires from one place; an action lands in another.

Better stack triggers

Rkvst actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Download Event Attachment

Tool to download an attachment from a specified event on an asset. use when you have asset uuid, event uuid, and attachment uuid, and want the raw binary content.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get App Registration

Tool to retrieve details for a given app registration id. use after obtaining the application's uuid to inspect its configuration and credentials.

ActionInstant

Get Asset

Tool to retrieve details for a given asset. use after you have its uuid; set `at time` to get historical state.

ActionInstant

Get Blob

Tool to retrieve details of a blob by id. use after confirming the blob id.

ActionInstant

Get Event

Tool to retrieve details of a specified event. use when you need full metadata, attributes, and associated trails of an existing event in datatrails.

ActionInstant

Get IAM Subject

Tool to retrieve iam subject details. use when you need to fetch details for a specific iam subject by its id.

ActionInstant

Get Member

Tool to retrieve details for a given member id. use after obtaining a valid member uuid.

ActionInstant

Get Public Asset

Tool to retrieve details for a public asset. use when you have a public asset uuid.

ActionInstant

Connect any two apps with Notis in the middle.

Better stack and Rkvst, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Rkvst.