Turn outage monitoring requests into Kibana alert rules
Capture a request for a signal while it is fresh and make it actionable in Kibana.
Trigger
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Action
Create Alerting Rule
Tool to create a new alerting rule in kibana. use when you need to define a new condition that, when met, triggers an alert and potentially executes predefined actions.
Why this helps
Monitoring requests are easy to lose among ongoing Slack discussions and follow-up tasks.
- Record explicit monitoring requests as Kibana rules.
- Reduce the handoff from discussion to configuration.
- Keep the originating request available for review.
Setup
Build it in a few focused steps.
- 1Connect Slack and Kibana to Notis once in the portal.
- 2Create an automation in the portal or ask Notis conversationally.
- 3In one plain-language instruction, ask Notis to create a Kibana alerting rule only for Slack messages that explicitly request outage monitoring.
- 4Select the Slack channel-message trigger, choose a channel for run reports, and test with one real monitoring request.
Questions about this workflow
Will casual mentions of an outage create a rule?
Tell Notis in the instruction to act only on explicit requests to set up outage monitoring.
Can I review the rule after it is created?
Yes. Find it in Kibana’s alerting rules and review the automation run report in your selected channel.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Slack to Kibana. A trigger fires from one place; an action lands in another.
Slack triggers
Kibana actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Delete Action
Tool to delete an action in kibana. use when you need to remove a specific action by its id, optionally within a specific space.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete Alerting Rule
Tool to delete an alerting rule in kibana. use when you need to remove a specific alerting rule by its id.
New Channel Created Trigger
Triggered when a new channel is created in Slack.
Delete Connector
Tool to delete a connector in kibana. use when you need to remove an existing connector.
Channel Message Received
Triggered when a message is posted in a Slack channel (public, private, or multi-party IM). Does NOT match direct messages.
Delete Fleet Output
Tool to delete a specific output configuration in kibana fleet. use when you need to remove an existing output by its id.
Direct Message Received
Triggered when a new direct message (DM) is sent to a user in Slack. Catches all DMs across all DM channels.
Delete Fleet Proxy
Tool to delete a specific fleet proxy configuration by its id. use when you need to remove an existing proxy setup.
Message Reaction Added
Triggered when a reaction is added to a message in Slack. Supports optional filtering by channel and emoji name.
Delete List
Deletes a list. use when you want to delete a list by its id.
Message Reaction Removed
Triggered when a reaction is removed from a message in Slack. Supports optional filtering by channel and emoji name.
Delete Osquery Saved Query
Tool to delete a saved osquery query by its id. use when you need to remove a specific osquery saved query.
Reaction Added Trigger
DEPRECATED: use `SLACK_MESSAGE_REACTION_ADDED` instead. Triggered when a reaction is added to a message in Slack.
Delete Saved Object
Tool to delete a saved object in kibana. use when you need to remove a specific saved object like a visualization or dashboard.
Connect any two apps with Notis in the middle.
Slack and Kibana, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Kibana.