Demo

Description

This download enhances the Kibana alerting experience. Kibana alerting is an easy to use evolution of the alerting capabilities within the Elastic Stack. All relevant configuations can be easily managed through the Kibana Frontend. However to get an overview about the existing alerts and the status the user have to visit stack management. That makes it hard to get the status and history of alerts into dashboards.

This enhancement is loading the current state of each Kibana alert into a separate index using a watcher script. A second watcher script is saving the current state of each alert into another index to preserve the history of each alert. The download also includes two dashboards. The Alert overview dashboard is showing each Kibana alert and the current status. A Kibana alert could be configured manually, automatically by using Stack Monitoring or the use of Elastic Security Detection rules. The overview dashboard is configured to offer a drilldown into the Alert history dashboard called Alert overview. To trigger the drill down you need to filter on the alert you would like to observe more in depth.

What is Kibana alerting?

Kibana alerting allows you to define rules to detect complex conditions within different Kibana apps and trigger actions when those conditions are met. Alerting is integrated with ObservabilitySecurityMaps and Machine Learning, can be centrally managed from the Management UI, and provides a set of built-in connectors and rules (known as stack rules) for you to use.

Combining the visibility in all those kind of alerts into one single dashboard that can get extended with every other kind of information is extremly valuable for every use case.

Tested versions 7.1, 7.9, 7.10, 7.11, 7.12, 7.13
ECS compliant No

You must log in to submit a review.

Related downloads

Watch to detect large shards

This watch is getting data from the Elasticsearch shards API directly and checking for large shards.

Kibana alerting enhancement

This bundle enhances the Kibana alerting experience. Storing all relevant information in indices and visualize the data in dashboards.

Watch for changes in IOWaits

A watch which alerts if the time spent by a hosts CPU in IOWait, has increased by more than than N% in the last Y mins.

Uptime watch using Heartbeat data

This watch checks the availability of your Heartbeat observed services. It will trigger an alert whenever at least one of your services is down.

Watcher job to integrate ChatGPT in Elasticsearch

Watcher job to integrate ChatGPT API from OpenAI in Elasticsearch. Helpful to find solutions for error messages very quick.

These downloads could be also interesting for you

Timetable canvas

This canvas examples shows timetable data from trains. Its build based on the real world information panel in german trian stations. Its refreshing based on current time.

RUM extension dashboard

This dashboard provide deeper insight into the real user monitoring data collected by Elastic RUM.

Threat detection Kibana dashboard

Kibana dashboard example visualizing the results of the Elastic SIEM detection engine

Filebeat Suricata Canvas dashboard

A Kibana Canvas dashboard example that visualizes suricata logs collected with Filebeat.

Filebeat Log analysis canvas example

This is a simple canvas dashboard example that analyzes logs created by Filebeat.

Detection engine alerts overview dashboard

Average rating:

Kibana Canvas dashboard that shows an aggregated view on the results of the detection engine in Elastic Security.