Keep open Kibana cases visible each week
A small weekly review helps open investigations stay connected to their next step.
Trigger
Recurring schedule
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Action
Get Cases
Tool to retrieve a list of cases in kibana. use when you need to find or list existing security or operational cases, potentially filtering by various attributes like status, assignee, or severity.
Why this helps
Open cases can fade from view when there is no regular reminder to revisit them.
- Bring open investigations back into view on a cadence.
- Support deliberate follow-up planning.
- Reduce reliance on personal reminders to revisit cases.
Setup
Build it in a few focused steps.
- 1Connect Telegram and Kibana to Notis once through the portal.
- 2Create a weekly scheduled automation in the portal or tell Notis to retrieve open Kibana cases.
- 3Use one plain-language instruction to specify the case summary that helps with follow-up.
- 4Choose the weekly schedule, select a channel for run reports, and test with one case review.
Questions about this workflow
Can I focus the review on a particular assignee?
Describe the focus in the prompt so Notis can use it when retrieving cases.
Will the automation change case status?
No. It retrieves cases for your review.
When this happens · Trigger
Do this · Action
Supported Triggers and Actions
Notis builds workflows that link Telegram to Kibana. A trigger fires from one place; an action lands in another.
Telegram triggers
Kibana actions
Recurring trigger
Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.
Delete Action
Tool to delete an action in kibana. use when you need to remove a specific action by its id, optionally within a specific space.
Webhook trigger
Notis starts this workflow when an external tool or custom backend sends an HTTP request.
Delete Alerting Rule
Tool to delete an alerting rule in kibana. use when you need to remove a specific alerting rule by its id.
New Message Received
Triggered when your bot receives a new message in a private chat, group, or supergroup. To receive every message in a group, Privacy Mode must be disabled for the bot in BotFather.
Delete Connector
Tool to delete a connector in kibana. use when you need to remove an existing connector.
New Channel Post
Triggered when a new post is published to a channel where your bot is an administrator.
Delete Fleet Output
Tool to delete a specific output configuration in kibana fleet. use when you need to remove an existing output by its id.
Callback Query Received
Triggered when a user taps an inline keyboard button attached to one of your bot's messages.
Delete Fleet Proxy
Tool to delete a specific fleet proxy configuration by its id. use when you need to remove an existing proxy setup.
Message Edited
Triggered when a message in a chat your bot can see is edited by its sender.
Delete List
Deletes a list. use when you want to delete a list by its id.
New Chat Member
Triggered when a new member joins a group or supergroup the bot belongs to, including when the bot itself is added.
Delete Osquery Saved Query
Tool to delete a saved osquery query by its id. use when you need to remove a specific osquery saved query.
Delete Saved Object
Tool to delete a saved object in kibana. use when you need to remove a specific saved object like a visualization or dashboard.
Connect any two apps with Notis in the middle.
Telegram and Kibana, or any other combination from 1,000+ integrations.
When this happens · Trigger
Do this · Action
Save your first hour today.
7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Kibana.