Search Guard Integration
With the ilert Search Guard integration, you can create alerts in ilert based on Search Guard alerts.
Last updated
With the ilert Search Guard integration, you can create alerts in ilert based on Search Guard alerts.
Last updated
(c) 2011 - 2024 ilert GmbH
Go to Alert sources --> Alert sources and click on Create new alert source
Search for Search Guard in the search field, click on the Search Guard tile and click on Next.
Give your alert source a name, optionally assign teams and click Next.
Select an escalation policy by creating a new one or assigning an existing one.
Select you Alert grouping preference and click Continue setup. You may click Do not group alerts for now and change it later.
The next page show additional settings such as customer alert templates or notification prioritiy. Click on Finish setup for now.
On the final page, an API key and / or webhook URL will be generated that you will need later in this guide.
Go to Search Guard to open the main menu and choose Search Guard -> Signals
On the next page click on the New button to create a new watch
On the next view name the watch e.g. My Watch scroll down and configure the watch to your liking.
Scroll down to Actions and add the Webhook action
Name the action e.g. iLert, paste the Webhook URL that you generated in ilert, change headers as required and paste the following json as body template
Click on Create to save the watch.
Finished! Your Elastic Search Guard alerts will now create alerts in ilert.
Will alerts in ilert be resolved automatically?
No, unfortunately Search Guard watch(es) will not fire resolve events for alerts.
Can I connect Search Guard with multiple alert sources from ilert?
Yes, simply create more watches in Search Guard.