Skip to content
Notis

Bring a referenced evidence attachment into review

Pass a known Rkvst attachment reference with an incident signal so the raw file can be retrieved for review.

Trigger

Webhook received

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

Action

Download Event Attachment

Tool to download an attachment from a specified event on an asset. use when you have asset uuid, event uuid, and attachment uuid, and want the raw binary content.

Why this helps

A useful attachment can be difficult to find again while an incident needs your attention.

  • Retrieve a specified attachment from its Rkvst event.
  • Reduce repeated searching for incident evidence.
  • Help reviewers inspect the right source material.

Setup

Build it in a few focused steps.

  • 1Connect Better Stack and Rkvst to Notis once through the portal.
  • 2Create an automation in the portal or ask Notis to create it conversationally.
  • 3Write one prompt asking Notis to retrieve a specified event attachment when the webhook provides all required UUIDs.
  • 4Choose an incoming webhook trigger and a channel for run reports.
  • 5Test with a real reference and verify the returned attachment is the expected one.

Questions about this workflow

What does the webhook need to include?

The asset UUID, event UUID, and attachment UUID are required for this action.

Can it find an attachment from an incident description alone?

No. The action retrieves a specified attachment and requires its identifiers.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Better stack to Rkvst. A trigger fires from one place; an action lands in another.

Better stack triggers

Rkvst actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Download Event Attachment

Tool to download an attachment from a specified event on an asset. use when you have asset uuid, event uuid, and attachment uuid, and want the raw binary content.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Get App Registration

Tool to retrieve details for a given app registration id. use after obtaining the application's uuid to inspect its configuration and credentials.

ActionInstant

Get Asset

Tool to retrieve details for a given asset. use after you have its uuid; set `at time` to get historical state.

ActionInstant

Get Blob

Tool to retrieve details of a blob by id. use after confirming the blob id.

ActionInstant

Get Event

Tool to retrieve details of a specified event. use when you need full metadata, attributes, and associated trails of an existing event in datatrails.

ActionInstant

Get IAM Subject

Tool to retrieve iam subject details. use when you need to fetch details for a specific iam subject by its id.

ActionInstant

Get Member

Tool to retrieve details for a given member id. use after obtaining a valid member uuid.

ActionInstant

Get Public Asset

Tool to retrieve details for a public asset. use when you have a public asset uuid.

ActionInstant

Connect any two apps with Notis in the middle.

Better stack and Rkvst, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Rkvst.