# How to create a webhook

**URL:** <https://discuss.elastic.co/t/how-to-create-a-webhook/379698>\
**Category:** Elastic Security\
**Created:** [July 2, 2025, 7:32am UTC](https://discuss.elastic.co/t/how-to-create-a-webhook/379698 "2025-07-02T07:32:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![KaWa](https://avatars.discourse-cdn.com/v4/letter/k/eb8c5e/32.png) [@KaWa](https://discuss.elastic.co/u/KaWa)\
**Post date:** [July 2, 2025, 7:32am UTC](https://discuss.elastic.co/t/how-to-create-a-webhook/379698/1 "2025-07-02T07:32:52Z")

</div>

Dear community,

TL;DR:  
**goal** : create tickets for SIEM alarms in ticket system  
**path** : use webhook with token (generated by ticket system)  
**problem** : how to setup a connector

* * *

I'd like to create a ticket for every SIEM alarm in our ticket system. The ticket system uses a token for authentication.

In the chapter "Webhook action" ([Webhook action | Elastic Docs](https://www.elastic.co/docs/explore-analyze/alerts-cases/watcher/actions-webhook)) there is no option for delivering a token to via the request. Do I have to put it in the "params", or does this fit to the auth section (where only 'basic auth' is supported)?

Best regards,  
Kai

#elastic-stack:webhook  
#webhook  
#connector  
#elastic-stack:connector

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 2, 2025, 1:16pm UTC](https://discuss.elastic.co/t/how-to-create-a-webhook/379698/2 "2025-07-02T13:16:50Z")

</div>

Hi @KaWa

Usually Authentication Tokens are added as a custom headers... perhaps I am missing something?

Can you should a sample what a `curl POST` request would look like?

 ![Screenshot 2025-07-02 at 6.14.20 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/0/006c97be65be5e108e55df7e2d3f2488ebd0e21e.png)

---

<div class="post-metadata">

**Author:** ![KaWa](https://avatars.discourse-cdn.com/v4/letter/k/eb8c5e/32.png) [@KaWa](https://discuss.elastic.co/u/KaWa)\
**Post date:** [July 4, 2025, 7:06am UTC](https://discuss.elastic.co/t/how-to-create-a-webhook/379698/3 "2025-07-04T07:06:33Z")

</div>

Dear community,

We got it working, thanks to our internal IT!

For all the people reading this, there are some points you have to keep in mind:

1. In the kibana.yml there are options that touch the communication between Kibana and other systems. We had to consider these parameters (found [here](https://www.elastic.co/docs/reference/kibana/configuration-reference/alerting-settings)

- xpack.actions.proxyBypassHosts
- xpack.actions.allowedHosts

1. How to use a token in a HTTP-header:  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/6/26dd55b267dd97b13fd57a21efceb2b30089edc4.png)  
(xxxyyyzzz is your token)
2. If you use HTTPS, perhaps you need to make your CA available (see "Add certificate authority" in the picture).
3. What does your ticket-system expect? Perhaps you need to make it aware, that Kibana sends json and use the "Content-Type"-header.

I hope this helps others with the same problem.

Best regards  
Kai

---

<div class="post-metadata">

**Author:** ![KaWa](https://avatars.discourse-cdn.com/v4/letter/k/eb8c5e/32.png) [@KaWa](https://discuss.elastic.co/u/KaWa)\
**Post date:** [July 4, 2025, 7:08am UTC](https://discuss.elastic.co/t/how-to-create-a-webhook/379698/4 "2025-07-04T07:08:08Z")

</div>

Thanks, @stephenb for your comment. We tried `curl POST` and this led us to the solution.
