Hello,
We forward Elastic Security detection alerts to an external system through a Webhook connector configured as a rule action. That works well for new alerts. However, the receiving side also requires every subsequent status change of an alert to be transmitted, for example when an analyst sets it to acknowledged or closed, together with the timestamp of the change.
As far as we can tell, rule actions only fire on rule executions that generate alerts. Changing kibana.alert.workflow_status afterwards does not trigger the rule's actions again, and the Kibana event log shows no further connector execution after the status change.
What is the recommended way to achieve this? Options we are considering:
- Elastic Workflows, if there is a trigger for detection alert status changes (we found triggers for cases, but not for detection alerts)
- Periodically querying the alerts index for changes to
kibana.alert.workflow_statusand forwarding them from an external process, but this doesn't seem ideal
Is there a native mechanism we are missing? We're on Kibana 9.5.4, Elastic Cloud Enterprise.
If there is no such mechanism, would it be a doable feature request?
Use case:
Some regulated environments require a provider to forward security alerts to a central external SIEM, and to transmit every status update of each alert, so that the receiving party can verify that alerts are assessed and closed within defined deadlines. Forwarding the initial alert works through a Webhook connector as a rule action today. There is, however, no native way to forward the later status changes an analyst makes in Kibana, so the external system never learns when an alert was acknowledged or closed.
Kind regards,
Willem D'Haese