# How to trigger a webhook with KQL?

**URL:** <https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717>\
**Category:** Kibana\
**Created:** [February 18, 2021, 2:37pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717 "2021-02-18T14:37:59Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [February 18, 2021, 2:37pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/1 "2021-02-18T14:37:59Z")

</div>

Dear all =)

I would like to create an alert that triggers a webhook each time `host:10.10.10.10` is found in the log stream `example_test`.

When I click on " Stack Management" and then "Create Alert" I get presented with the options

- Index Threshold
- Inventory
- Log threshold
- Metric threshold
- Uptime monitor status
- Uptime TLS

and each looks like SQL statements and not KQL.

**Question**

Can anyone tell me how I can have a KQL statement evaluated each minute, and if it finds a hit, then trigger a webhook?

Hugs,  
Sandra =)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 18, 2021, 3:35pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/2 "2021-02-18T15:35:59Z")

</div>

Hi @Sandra_Schlichting Welcome to the community.

Interestingly there is no simple alert based on a KQL query (yet) ... I believe that is coming in a future release, an alert based on the Full DSL is coming soon, I suspect KQL will come after that.

First you will need to create a webhook connector and test it, you can do that through the create connector setup.

Today I would use the Log Threshold alert.

First there is a little un-intuitive process to use the Log Threshold Alert. The log index needs to be added to the Logs UI. That make that index (or index pattern) available for the Logs View and Alerting functionality (I asked for that dependency to be removed)

 ![Screen Shot 2021-02-18 at 7.24.37 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/8/981be36f40c875fd6734e14d956d60074a8becf3.png)

Then I would create the threshold like this of course using your field(s)

 ![Screen Shot 2021-02-18 at 7.33.58 AM](https://us1.discourse-cdn.com/elastic/original/3X/9/2/9292a258a80b84b4f79b4ae6ae3092c71c933f6a.png)

Then create your action based on the webhook...

Lets us know how is goes, is there more than that that you want to do?

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [February 18, 2021, 10:08pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/3 "2021-02-18T22:08:41Z")

</div>

Dear Stephen =)

That is a very interesting workaround. Thanks a lot!

Ideally would I like to create all of this over the Kibana REST API. Would that be possible?

Hugs,  
Sandra =)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 18, 2021, 10:25pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/4 "2021-02-18T22:25:14Z")

</div>

The alerting API is in progress / iterating but the plan is to make all the Alerting Capabilities available via and API (a highly requested feature) . Stay Tuned!

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [February 18, 2021, 11:29pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/5 "2021-02-18T23:29:15Z")

</div>

I can imagine =)

So does that mean, that the above isn't currently supported over the API?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 18, 2021, 11:36pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/6 "2021-02-18T23:36:43Z")

</div>

Correct : The API it is in the processes of getting documented / refined, so it is not released / supported today.

---

<div class="post-metadata">

**Author:** ![Sandra\_Schlichting](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandra_schlichting/32/84122_2.png) [@Sandra\_Schlichting](https://discuss.elastic.co/u/Sandra_Schlichting)\
**Post date:** [February 24, 2021, 3:02pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/7 "2021-02-24T15:02:23Z")

</div>

Do you know if there exist a feature request ticket for KQL in Kibana Watchers, I can subscribe to?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 24, 2021, 4:29pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/8 "2021-02-24T16:29:55Z")

</div>

Hi @Sandra_Schlichting

Lets clarify Terminology a bit

[Watcher](https://www.elastic.co/guide/en/elasticsearch/reference/current/xpack-alerting.html) is the legacy / code only alerting and notification framework (which I think you are not referring to... perhaps you are)

[Kibana Alerting](https://www.elastic.co/guide/en/kibana/current/alerting-getting-started.html) is the new framework which I think we are discussing, and yes there is a feature request / issue... you can find it [here](https://github.com/elastic/kibana/issues/91860). (I had it opened as a result of our conversation) of course there are many items in the backlog so I can not speak to its priority or schedule. I do know that the [DSL search for Kibana Alerting](https://github.com/elastic/kibana/issues/61313) is a pretty high priority.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2021, 4:30pm UTC](https://discuss.elastic.co/t/how-to-trigger-a-webhook-with-kql/264717/9 "2021-03-24T16:30:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
