Skip to content
Notis

Find related Kibana alerts for a Notion escalation

When an escalation is marked for review, pull relevant Kibana alerts into view to help you take the next step with context.

Trigger

Page Properties Updated

Triggers when properties of a Notion page are updated. Customer optionally scopes with at most one of: - data_source_id: any row in this data source - page_id: this specific page - parent_page_id: any page whose immediate parent is this page With none set, fires for any property change in the workspace the integration has access to. Adding a column to a data source fires this trigger once per existing row. Customers can branch on `data.updated_properties` (array of property IDs) to filter downstream.

Action

Find Kibana Alerts

Tool to find and/or aggregate detection alerts in kibana. use this to retrieve a list of alerts, optionally filtering them with a query and performing aggregations.

Why this helps

Security-related follow-up can feel fragmented when the escalation and detection evidence live in different tools.

  • Surfaces relevant detection alerts after an escalation update.
  • Helps connect the documented concern with available evidence.
  • Reduces manual searching during triage.

Setup

Build it in a few focused steps.

  • 1Connect Notion and Kibana to Notis once through the portal.
  • 2Create an automation in the portal, or ask Notis to find relevant Kibana alerts when a Notion security escalation is updated.
  • 3Describe in one plain-language instruction which escalation changes matter and what context should guide the alert search.
  • 4Choose Page Properties Updated and a run-report channel, then test with one real escalation update.

Questions about this workflow

Does the automation create an alert?

No. Find Kibana Alerts retrieves detection alerts for review.

Can it avoid running on unrelated property changes?

Describe the escalation change that matters in the instruction and scope the trigger to the relevant page or data source when possible.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Notion to Kibana. A trigger fires from one place; an action lands in another.

Notion triggers

Kibana actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Delete Action

Tool to delete an action in kibana. use when you need to remove a specific action by its id, optionally within a specific space.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Delete Alerting Rule

Tool to delete an alerting rule in kibana. use when you need to remove a specific alerting rule by its id.

ActionInstant

All Page Events

Triggers when any Notion page is created or updated across the workspace.

TriggerPolling

Delete Connector

Tool to delete a connector in kibana. use when you need to remove an existing connector.

ActionInstant

Comment Created

Triggers when a new comment is created in Notion. Optional `page_id` filter scopes to comments on a specific page. When omitted, fires for any new comment in the workspace the integration has access to. Requires the 'Read comments' capability on the Notion integration. If a connection was authorized before that capability was enabled, the user must re-authorize the connection for comment events to flow.

TriggerInstant

Delete Fleet Output

Tool to delete a specific output configuration in kibana fleet. use when you need to remove an existing output by its id.

ActionInstant

New Comment

Triggers when a new comment is added to a specified Notion block or page.

TriggerPolling

Delete Fleet Proxy

Tool to delete a specific fleet proxy configuration by its id. use when you need to remove an existing proxy setup.

ActionInstant

Database Created

Triggers when a new Notion database (the container) is created. A database is the post-2025-09-03 container that holds one or more data sources. This trigger fires for the container's creation event (`database.created`), distinct from `NOTION_DATASOURCE_CREATED` which fires when a new data source is added to an existing database. Most customers calling Notion's `POST /v1/databases` (the legacy API) or creating a database via the Notion UI will see this event. Adding a new data source to an existing database fires `data_source.created` instead — use `NOTION_DATASOURCE_CREATED` for that. Notion's payload puts `entity.type: "block"` (the container is a `child_database` block in the content tree) and `entity.id` is the database id.

TriggerInstant

Delete List

Deletes a list. use when you want to delete a list by its id.

ActionInstant

Data Source Created

Triggers when a new Notion data source is created. Fires workspace-wide. The payload's `data.parent` carries the data source's tree parent (typically the teamspace) for downstream filtering. A single template-based database creation can fire multiple `data_source.created` events at once — one per data source the template instantiates.

TriggerInstant

Delete Osquery Saved Query

Tool to delete a saved osquery query by its id. use when you need to remove a specific osquery saved query.

ActionInstant

Data Source Schema Updated

Triggers when a Notion data source's schema is updated. Fires on column add / remove / rename. Payload includes `data.updated_properties: [{id, name, action}]` so consumers can discriminate the kind of change downstream. Optional `data_source_id` filter scopes to schema changes on a single data source. When omitted, fires for any schema change in the workspace the integration has access to. Note: adding a column also fires `page.properties_updated` once per existing row in the data source. Customers wanting a single structural-change signal should use this trigger.

TriggerInstant

Delete Saved Object

Tool to delete a saved object in kibana. use when you need to remove a specific saved object like a visualization or dashboard.

ActionInstant

Connect any two apps with Notis in the middle.

Notion and Kibana, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Kibana.