Skip to content
Notis

Review Fleet agent policies on a schedule

Keep policy configuration visible with a small recurring review that is easy to follow.

Trigger

Recurring schedule

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

Action

Get Fleet Agent Policies

Fetches a list of agent policies in fleet. use when you need to retrieve agent policy configurations.

Why this helps

Policy details can become difficult to keep straight when configuration reviews happen infrequently.

  • Make policy reviews more consistent.
  • Keep configuration context easy to access.
  • Reduce interruptions for routine inventory checks.

Setup

Build it in a few focused steps.

  • 1Connect Telegram and Kibana to Notis once through the portal.
  • 2Create a recurring scheduled automation in the portal or ask Notis to retrieve Fleet agent policies regularly.
  • 3Describe the policy information you want in one plain-language instruction.
  • 4Choose the schedule, select a channel for run reports, and test with one policy inventory.

Questions about this workflow

Does it inspect the agents themselves?

This action retrieves Fleet agent policies. Choose a different Kibana action if you need a separate kind of information.

Will this edit policies?

No. It provides a policy inventory for review.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Telegram to Kibana. A trigger fires from one place; an action lands in another.

Telegram triggers

Kibana actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Delete Action

Tool to delete an action in kibana. use when you need to remove a specific action by its id, optionally within a specific space.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Delete Alerting Rule

Tool to delete an alerting rule in kibana. use when you need to remove a specific alerting rule by its id.

ActionInstant

New Message Received

Triggered when your bot receives a new message in a private chat, group, or supergroup. To receive every message in a group, Privacy Mode must be disabled for the bot in BotFather.

TriggerInstant

Delete Connector

Tool to delete a connector in kibana. use when you need to remove an existing connector.

ActionInstant

New Channel Post

Triggered when a new post is published to a channel where your bot is an administrator.

TriggerInstant

Delete Fleet Output

Tool to delete a specific output configuration in kibana fleet. use when you need to remove an existing output by its id.

ActionInstant

Callback Query Received

Triggered when a user taps an inline keyboard button attached to one of your bot's messages.

TriggerInstant

Delete Fleet Proxy

Tool to delete a specific fleet proxy configuration by its id. use when you need to remove an existing proxy setup.

ActionInstant

Message Edited

Triggered when a message in a chat your bot can see is edited by its sender.

TriggerInstant

Delete List

Deletes a list. use when you want to delete a list by its id.

ActionInstant

New Chat Member

Triggered when a new member joins a group or supergroup the bot belongs to, including when the bot itself is added.

TriggerInstant

Delete Osquery Saved Query

Tool to delete a saved osquery query by its id. use when you need to remove a specific osquery saved query.

ActionInstant

Delete Saved Object

Tool to delete a saved object in kibana. use when you need to remove a specific saved object like a visualization or dashboard.

ActionInstant

Connect any two apps with Notis in the middle.

Telegram and Kibana, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Kibana.