- Kibana Guide: other versions:
- What is Kibana?
- What’s new in 7.15
- Kibana concepts
- Quick start
- Set up
- Install Kibana
- Configure Kibana
- Alerting and action settings
- APM settings
- Banners settings
- Development tools settings
- Graph settings
- Fleet settings
- i18n settings
- Logging settings
- Logs settings
- Metrics settings
- Machine learning settings
- Monitoring settings
- Reporting settings
- Secure settings
- Search sessions settings
- Security settings
- Spaces settings
- Task Manager settings
- Telemetry settings
- URL drilldown settings
- Start and stop Kibana
- Access Kibana
- Securing access to Kibana
- Add data
- Upgrade Kibana
- Configure security
- Configure reporting
- Configure monitoring
- Production considerations
- Discover
- Dashboard and visualizations
- Canvas
- Maps
- Build a map to compare metrics by country or region
- Track, visualize, and alert on assets in real time
- Map custom regions with reverse geocoding
- Heat map layer
- Tile layer
- Vector layer
- Plot big data
- Search geographic data
- Configure map settings
- Connect to Elastic Maps Service
- Import geospatial data
- Troubleshoot
- Reporting and sharing
- Machine learning
- Graph
- Alerting
- Observability
- APM
- Security
- Dev Tools
- Fleet
- Osquery
- Stack Monitoring
- Stack Management
- REST API
- Get features API
- Kibana spaces APIs
- Kibana role management APIs
- User session management APIs
- Saved objects APIs
- Index patterns APIs
- Alerting APIs
- Action and connector APIs
- Import and export dashboard APIs
- Logstash configuration management APIs
- Shorten URL
- Get Task Manager health
- Upgrade assistant APIs
- Kibana plugins
- Accessibility
- Release notes
- Developer guide
Index connector and action
editIndex connector and action
editThe index connector will index a document into Elasticsearch. See also the create index API.
Connector configuration
editIndex connectors have the following configuration properties.
- Name
- The name of the connector. The name is used to identify a connector in the management UI connector listing, or in the connector list when configuring an action.
- Index
- The Elasticsearch index to be written to.
- Refresh
- Setting for the refresh policy for the write request.
- Execution time field
- This field will be automatically set to the time the alert condition was detected.
Preconfigured connector type
editmy-index: name: preconfigured-index-connector-type actionTypeId: .index config: index: .kibana refresh: true executionTimeField: somedate
Config defines information for the connector type.
-
index
- A string that corresponds to Index.
-
refresh
-
A boolean that corresponds to Refresh. Defaults to
false
. -
executionTimeField
- A string that corresponds to Execution time field.
Define connector in Stack Management
editDefine Index connector properties.

Test Index action parameters.

Action configuration
editIndex actions have the following properties.
- Document
- The document to index in JSON format.
Example
editExample of the index document for Index Threshold rule:
{ "rule_id": "{{ruleId}}", "rule_name": "{{ruleName}}", "alert_id": "{{alertId}}", "context_message": "{{context.message}}" }
Example of creating a test index using the API.
PUT test { "settings" : { "number_of_shards" : 1 }, "mappings" : { "properties" : { "rule_id" : { "type" : "text" }, "rule_name" : { "type" : "text" }, "alert_id" : { "type" : "text" }, "context_message": { "type" : "text" } } } }
Alert history Elasticsearch index connector
edit[preview] This functionality is in technical preview and may be changed or removed in a future release. Elastic will work to fix any issues, but features in technical preview are not subject to the support SLA of official GA features. Kibana offers a preconfigured index connector to facilitate indexing active alert data into Elasticsearch.
This functionality is experimental and may be changed or removed completely in a future release.
To use this connector, set the xpack.actions.preconfiguredAlertHistoryEsIndex
configuration to true
.
xpack.actions.preconfiguredAlertHistoryEsIndex: true
When creating a new rule, add an Index action and select the Alert history Elasticsearch index (preconfigured)
connector.

Documents are indexed using a preconfigured schema that captures the action variables available for the rule. By default, these documents are indexed into the kibana-alert-history-default
index, but you can specify a different index. Index names must start with kibana-alert-history-
to take advantage of the preconfigured alert history index template.
To write documents to the preconfigured index, you must have all
or write
privileges to the kibana-alert-history-*
indices. Refer to Kibana role management for more information.
The kibana-alert-history-*
indices are not configured to use ILM so they must be maintained manually. If the index size grows large,
consider using the delete by query API to clean up older documents in the index.
On this page