Appearance
Elastic Observability
Elastic / Kibana alert webhooks POST JSON to Exhale. Each tenant gets a unique HTTPS URL token. Exhale scrubs the payload, upserts a Pulse (
source=elastic), and runs triage when the alert state maps to active / firing / similar.
This is ingest (creates Pulses). For logs and Observability enrichment at triage time, see Elastic context.
See Sources for how Elastic fits with the other incoming webhooks.
On the hosted app, use the URL Connections copies. It starts with https://exhaleoncall.com/webhooks/. The customer host does not publish /v1/webhooks/....
Endpoint
After Connect in Connections → Sources → Observability & alerts → Elastic Observability:
Preferred (keeps tokens out of proxy access logs):
POST https://exhaleoncall.com/webhooks/elasticSend header X-Exhale-Webhook-Token: {token}.
Path form (also supported):
POST https://exhaleoncall.com/webhooks/elastic/{token}token— opaque URL segment; this token authenticates the delivery.- Response: 202 Accepted with
pulse_id,status,created, andmessage.
Unknown tokens return 404. Disabled or expired-trial tenants return 403.
Customer setup
- Sign in as admin → Connections → Sources → Elastic Observability.
- Click Connect Elastic and copy the webhook URL.
- In Kibana, add a Webhook connector / rule action and paste the
Exhale URL.
- Include an alert or rule id and a status field.
- Send test alert creates a synthetic pulse and marks the integration configured.
See Elastic's official guide: Webhook connector and action.
Rotate webhook token replaces the previous URL right away. Update Kibana after rotating.
Payload shape
| Field | Required | Notes |
|---|---|---|
| Alert / rule id | Yes | Stable id for dedupe (source=elastic) |
status / state | No | active, recovered, … |
title / rule name | No | Pulse title |
Lifecycle mapping
| Elastic / Kibana state | Pulse status |
|---|---|
| Active, open, firing, new | Received → triage |
| Recovered, resolved, closed, ok | Resolved |
Example
bash
TOKEN="your-url-token"
curl -i -X POST "https://exhaleoncall.com/webhooks/elastic/${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"alert_id":"a-1","status":"active","title":"High error rate"}'Related
See Errors & authentication for structured errors, 413 size limits, Redis delivery dedupe, and token rotation.