Skip to content

Elastic Observability ​

Elastic / Kibana alert webhooks POST JSON to Exhale. Each tenant gets a unique HTTPS URL token. Exhale scrubs the payload, upserts a Pulse (source=elastic), and runs triage when the alert state maps to active / firing / similar.

This is ingest (creates Pulses). For logs and Observability enrichment at triage time, see Elastic context.

See Sources for how Elastic fits with the other incoming webhooks.

On the hosted app, use the URL Connections copies. It starts with https://exhaleoncall.com/webhooks/. The customer host does not publish /v1/webhooks/....


Endpoint ​

After Connect in Connections → Sources → Observability & alerts → Elastic Observability:

Preferred (keeps tokens out of proxy access logs):

POST https://exhaleoncall.com/webhooks/elastic

Send header X-Exhale-Webhook-Token: {token}.

Path form (also supported):

POST https://exhaleoncall.com/webhooks/elastic/{token}
  • token — opaque URL segment; this token authenticates the delivery.
  • Response: 202 Accepted with pulse_id, status, created, and message.

Unknown tokens return 404. Disabled or expired-trial tenants return 403.


Customer setup ​

  1. Sign in as admin → Connections → Sources → Elastic Observability.
  2. Click Connect Elastic and copy the webhook URL.
  3. In Kibana, add a Webhook connector / rule action and paste the Exhale URL.
  4. Include an alert or rule id and a status field.
  5. Send test alert creates a synthetic pulse and marks the integration configured.

See Elastic's official guide: Webhook connector and action.

Rotate webhook token replaces the previous URL right away. Update Kibana after rotating.


Payload shape ​

FieldRequiredNotes
Alert / rule idYesStable id for dedupe (source=elastic)
status / stateNoactive, recovered, …
title / rule nameNoPulse title

Lifecycle mapping ​

Elastic / Kibana statePulse status
Active, open, firing, newReceived → triage
Recovered, resolved, closed, okResolved

Example ​

bash
TOKEN="your-url-token"
curl -i -X POST "https://exhaleoncall.com/webhooks/elastic/${TOKEN}" \
  -H "Content-Type: application/json" \
  -d '{"alert_id":"a-1","status":"active","title":"High error rate"}'

See Errors & authentication for structured errors, 413 size limits, Redis delivery dedupe, and token rotation.

Exhale by Kolstrom Systems LLC