Interestingly there is no simple alert based on a KQL query (yet) ... I believe that is coming in a future release, an alert based on the Full DSL is coming soon, I suspect KQL will come after that.
First you will need to create a webhook connector and test it, you can do that through the create connector setup.
Today I would use the Log Threshold alert.
First there is a little un-intuitive process to use the Log Threshold Alert. The log index needs to be added to the Logs UI. That make that index (or index pattern) available for the Logs View and Alerting functionality (I asked for that dependency to be removed)
The alerting API is in progress / iterating but the plan is to make all the Alerting Capabilities available via and API (a highly requested feature) . Stay Tuned!
Watcher is the legacy / code only alerting and notification framework (which I think you are not referring to... perhaps you are)
Kibana Alerting is the new framework which I think we are discussing, and yes there is a feature request / issue... you can find it here. (I had it opened as a result of our conversation) of course there are many items in the backlog so I can not speak to its priority or schedule. I do know that the DSL search for Kibana Alerting is a pretty high priority.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.