Give incident comments a trackable Kibana case
When someone adds a significant update to an incident discussion, create a Kibana case to make follow-up visible.
Trigger
Comment Created
Triggers when a new comment is created in Notion. Optional `page_id` filter scopes to comments on a specific page. When omitted, fires for any new comment in the workspace the integration has access to. Requires the 'Read comments' capability on the Notion integration. If a connection was authorized before that capability was enabled, the user must re-authorize the connection for comment events to flow.
Action
Create Case
Tool to create a new case in kibana. use when you need to open and track issues, incidents, or investigations. you can assign users, set severity levels, add tags, and configure external connectors for integration with itsm systems.
Why this helps
Important incident details can be buried in comment threads instead of moving into a tracked response.
- Makes comment-based escalations easier to track.
- Reduces the need to repeatedly scan discussion threads.
- Creates a clear investigation starting point in Kibana.
Setup
Build it in a few focused steps.
- 1Connect Notion and Kibana to Notis once through the portal.
- 2Create an automation in the portal, or ask Notis to open a Kibana case for a significant comment on an incident page.
- 3Describe in one plain-language instruction which incident comments should create a case.
- 4Choose Comment Created and a run-report channel, then test with a real incident comment.
Questions about this workflow
Will every workspace comment create a case?
The Comment Created trigger can be scoped to a page. Describe which comments are actionable in the instruction to avoid irrelevant cases.
What access does Notion need for comments?
The Notion integration requires the Read comments capability. A connection authorized before it was enabled may need reauthorization.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Notion to Kibana. A trigger fires from one place; an action lands in another.
Notion triggers
Kibana actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Delete Action
Tool to delete an action in kibana. use when you need to remove a specific action by its id, optionally within a specific space.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete Alerting Rule
Tool to delete an alerting rule in kibana. use when you need to remove a specific alerting rule by its id.
All Page Events
Triggers when any Notion page is created or updated across the workspace.
Delete Connector
Tool to delete a connector in kibana. use when you need to remove an existing connector.
Comment Created
Triggers when a new comment is created in Notion. Optional `page_id` filter scopes to comments on a specific page. When omitted, fires for any new comment in the workspace the integration has access to. Requires the 'Read comments' capability on the Notion integration. If a connection was authorized before that capability was enabled, the user must re-authorize the connection for comment events to flow.
Delete Fleet Output
Tool to delete a specific output configuration in kibana fleet. use when you need to remove an existing output by its id.
New Comment
Triggers when a new comment is added to a specified Notion block or page.
Delete Fleet Proxy
Tool to delete a specific fleet proxy configuration by its id. use when you need to remove an existing proxy setup.
Database Created
Triggers when a new Notion database (the container) is created. A database is the post-2025-09-03 container that holds one or more data sources. This trigger fires for the container's creation event (`database.created`), distinct from `NOTION_DATASOURCE_CREATED` which fires when a new data source is added to an existing database. Most customers calling Notion's `POST /v1/databases` (the legacy API) or creating a database via the Notion UI will see this event. Adding a new data source to an existing database fires `data_source.created` instead — use `NOTION_DATASOURCE_CREATED` for that. Notion's payload puts `entity.type: "block"` (the container is a `child_database` block in the content tree) and `entity.id` is the database id.
Delete List
Deletes a list. use when you want to delete a list by its id.
Data Source Created
Triggers when a new Notion data source is created. Fires workspace-wide. The payload's `data.parent` carries the data source's tree parent (typically the teamspace) for downstream filtering. A single template-based database creation can fire multiple `data_source.created` events at once — one per data source the template instantiates.
Delete Osquery Saved Query
Tool to delete a saved osquery query by its id. use when you need to remove a specific osquery saved query.
Data Source Schema Updated
Triggers when a Notion data source's schema is updated. Fires on column add / remove / rename. Payload includes `data.updated_properties: [{id, name, action}]` so consumers can discriminate the kind of change downstream. Optional `data_source_id` filter scopes to schema changes on a single data source. When omitted, fires for any schema change in the workspace the integration has access to. Note: adding a column also fires `page.properties_updated` once per existing row in the data source. Customers wanting a single structural-change signal should use this trigger.
Delete Saved Object
Tool to delete a saved object in kibana. use when you need to remove a specific saved object like a visualization or dashboard.
Connect any two apps with Notis in the middle.
Notion and Kibana, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Kibana.