Check Kibana alerts in Telegram
Send a plain-language request in Telegram and get a focused look at Kibana alerts without losing your place.
Trigger
New Message Received
Triggered when your bot receives a new message in a private chat, group, or supergroup. To receive every message in a group, Privacy Mode must be disabled for the bot in BotFather.
Action
Find Kibana Alerts
Tool to find and/or aggregate detection alerts in kibana. use this to retrieve a list of alerts, optionally filtering them with a query and performing aggregations.
Why this helps
Switching into Kibana to check alerts can interrupt the work already in front of you.
- Review alerts from the chat where a concern surfaced.
- Get a concise answer to support quicker triage.
- Reduce context-switching during focused work.
Setup
Build it in a few focused steps.
- 1Connect Telegram and Kibana to Notis once through the portal.
- 2Create an automation in the portal or tell Notis you want Telegram requests to retrieve matching Kibana alerts.
- 3Use one plain-language instruction describing which alerts to find and how to summarize them.
- 4Choose the Telegram message trigger, select a channel for run reports, and test with one real alert request.
Questions about this workflow
Can I ask for alerts matching a particular concern?
Yes. Include the relevant terms or context in your Telegram message and describe in the automation prompt how Notis should use that request to find alerts.
Does this create or change alerts?
No. This workflow retrieves alerts for review; it does not modify Kibana alert records.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Telegram to Kibana. A trigger fires from one place; an action lands in another.
Telegram triggers
Kibana actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Delete Action
Tool to delete an action in kibana. use when you need to remove a specific action by its id, optionally within a specific space.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete Alerting Rule
Tool to delete an alerting rule in kibana. use when you need to remove a specific alerting rule by its id.
New Message Received
Triggered when your bot receives a new message in a private chat, group, or supergroup. To receive every message in a group, Privacy Mode must be disabled for the bot in BotFather.
Delete Connector
Tool to delete a connector in kibana. use when you need to remove an existing connector.
New Channel Post
Triggered when a new post is published to a channel where your bot is an administrator.
Delete Fleet Output
Tool to delete a specific output configuration in kibana fleet. use when you need to remove an existing output by its id.
Callback Query Received
Triggered when a user taps an inline keyboard button attached to one of your bot's messages.
Delete Fleet Proxy
Tool to delete a specific fleet proxy configuration by its id. use when you need to remove an existing proxy setup.
Message Edited
Triggered when a message in a chat your bot can see is edited by its sender.
Delete List
Deletes a list. use when you want to delete a list by its id.
New Chat Member
Triggered when a new member joins a group or supergroup the bot belongs to, including when the bot itself is added.
Delete Osquery Saved Query
Tool to delete a saved osquery query by its id. use when you need to remove a specific osquery saved query.
Delete Saved Object
Tool to delete a saved object in kibana. use when you need to remove a specific saved object like a visualization or dashboard.
Connect any two apps with Notis in the middle.
Telegram and Kibana, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Kibana.