# Kibana webhook for firewall blacklist update

**URL:** <https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815>\
**Category:** Elastic Security\
**Created:** [October 15, 2021, 9:32am UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815 "2021-10-15T09:32:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![algira37](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/algira37/32/88482_2.png) [@algira37](https://discuss.elastic.co/u/algira37)\
**Post date:** [October 15, 2021, 9:32am UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815/1 "2021-10-15T09:32:00Z")

</div>

Hello,  
I would like to use Kibana with the webhook feature to call my microservice to update my firewall blacklist.  
Unfortunately, I cant find that this feature is free or not, could you please help me?

---

<div class="post-metadata">

**Author:** ![n2x4](https://avatars.discourse-cdn.com/v4/letter/n/3e96dc/32.png) [@n2x4](https://discuss.elastic.co/u/n2x4)\
**Post date:** [October 17, 2021, 9:51pm UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815/2 "2021-10-17T21:51:32Z")

</div>

Third party connections like webhooks require a gold license or above. You'll see connectors in stack management with that license.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 17, 2021, 11:24pm UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815/3 "2021-10-17T23:24:43Z")

</div>

Subscription matrix here, as said Webhook connector is a commercial licensed feature, gold and above.

> **[Subscriptions | Elastic Stack Products & Support | Elastic](https://www.elastic.co/subscriptions)**
>
> See subscription levels, pricing, and tiered features for on-prem deployments of the Elastic Stack (Elasticsearch Kibana, Beats, and Logstash), Elastic Cloud, and Elastic Cloud Enterprise.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 18, 2021, 12:01am UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815/4 "2021-10-18T00:01:52Z")

</div>

As already said, the webhook Kibana Action is a paid feature, the only free actions are the Index Action, which will write to an specific index and the Log Action, which will log to the Kibana server Log.

To call your microservice using the free license you can use the Index Action as the action and build some tool that would query that specific index and trigger the webhook, you can also use logstash to do that with the `elasticsearch` input and the `http` output.

---

<div class="post-metadata">

**Author:** ![algira37](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/algira37/32/88482_2.png) [@algira37](https://discuss.elastic.co/u/algira37)\
**Post date:** [October 26, 2021, 4:14pm UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815/5 "2021-10-26T16:14:20Z")

</div>

Hi, thanks. Can you help me with this, please.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [October 26, 2021, 5:34pm UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815/6 "2021-10-26T17:34:10Z")

</div>

@algira37 What help are you looking for.

How to purchase a license?

You could also look at Elastic Cloud that feature will come as part of the subscription.

Otherwise you will need to build your own using some method like @leandrojmp suggested, when you will need to maintain etc... that will be much more complicated than using a license.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2021, 5:35pm UTC](https://discuss.elastic.co/t/kibana-webhook-for-firewall-blacklist-update/286815/7 "2021-11-23T17:35:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
