{"_id":"@alerthq/provider-elastic","_rev":"2-a8c5366424722b7050b20b8997989823","name":"@alerthq/provider-elastic","dist-tags":{"latest":"0.0.1"},"versions":{"0.0.1":{"name":"@alerthq/provider-elastic","version":"0.0.1","keywords":["alerthq","provider","elastic","elasticsearch","kibana","watcher","alerts","monitoring"],"license":"MIT","_id":"@alerthq/provider-elastic@0.0.1","maintainers":[{"name":"rsafaya","email":"rsafaya@edrv.io"}],"homepage":"https://github.com/ai-software-agency/alerthq#readme","bugs":{"url":"https://github.com/ai-software-agency/alerthq/issues"},"dist":{"shasum":"961720137db6b48b6078ae665fcba70b6747d9ee","tarball":"https://registry.npmjs.org/@alerthq/provider-elastic/-/provider-elastic-0.0.1.tgz","fileCount":5,"integrity":"sha512-6+8VzFPZVgMxl+KgQasnIHt2Ghho+g2oKfNIstxoWYahNhmoO9iOYx6GPmQTU9O2KgdRzx7UVaPc4NiGB9GGLA==","signatures":[{"sig":"MEYCIQDYp1uVxtG8EmTazGj6XDILVZW9vTL0KPYAUzNv9gd65QIhAORvIJ4Clmlfcr/SXC0+e9gXwcQV04pwE34gD7G6WtNn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":19809},"main":"./dist/index.js","type":"module","_from":"file:alerthq-provider-elastic-0.0.1.tgz","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js","default":"./dist/index.js"}},"scripts":{"lint":"eslint src/","test":"vitest run --passWithNoTests","build":"tsup src/index.ts --format esm --dts","typecheck":"tsc --noEmit"},"_npmUser":{"name":"rsafaya","email":"rsafaya@edrv.io"},"_resolved":"/private/var/folders/y_/sbbsfnm54k310t77b7c43cdm0000gn/T/e7e1955c4e831c178b673e65c5ccc5bd/alerthq-provider-elastic-0.0.1.tgz","_integrity":"sha512-6+8VzFPZVgMxl+KgQasnIHt2Ghho+g2oKfNIstxoWYahNhmoO9iOYx6GPmQTU9O2KgdRzx7UVaPc4NiGB9GGLA==","repository":{"url":"git+https://github.com/ai-software-agency/alerthq.git","type":"git","directory":"packages/provider-elastic"},"_npmVersion":"11.7.0","description":"Elastic Watcher + Kibana Rules alert provider for alerthq","directories":{},"_nodeVersion":"25.4.0","dependencies":{"zod":"^3.24.0","@elastic/elasticsearch":"^8.16.0"},"_hasShrinkwrap":false,"peerDependencies":{"@alerthq/core":"0.0.1"},"_npmOperationalInternal":{"tmp":"tmp/provider-elastic_0.0.1_1775722590927_0.0830648683266555","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-04-09T08:16:30.801Z","modified":"2026-04-09T09:10:24.477Z","0.0.1":"2026-04-09T08:16:31.067Z"},"bugs":{"url":"https://github.com/ai-software-agency/alerthq/issues"},"license":"MIT","homepage":"https://github.com/ai-software-agency/alerthq#readme","keywords":["alerthq","provider","elastic","elasticsearch","kibana","watcher","alerts","monitoring"],"repository":{"url":"git+https://github.com/ai-software-agency/alerthq.git","type":"git","directory":"packages/provider-elastic"},"description":"Elastic Watcher + Kibana Rules alert provider for alerthq","maintainers":[{"email":"dpipalia@edrv.io","name":"dhruvin-edrv"},{"email":"rsafaya@edrv.io","name":"rsafaya"}],"readme":"# @alerthq/provider-elastic\n\nElastic Watcher + Kibana Rules alert provider for [alerthq](https://github.com/edrv/alerthq).\n\n## Supported Alert Types\n\n| Alert Type | API Source | Notes |\n|------------|-----------|-------|\n| Elasticsearch Watchers | `POST /_watcher/_query/watches` via `@elastic/elasticsearch` | All watcher types (compare, script, array_compare, always, never) |\n| Kibana Alerting Rules | `GET /api/alerting/rules/_find` via Kibana REST API | All rule types (metrics, logs, uptime, APM, etc.) |\n\nKibana rules are only fetched when `kibanaUrl` is configured.\n\n## Authentication\n\nTwo authentication models are supported:\n\n- **Basic auth** — username and password\n- **API key** — a base64-encoded API key\n\nThe same credentials are used for both Elasticsearch and Kibana (if configured).\n\n## Configuration\n\nAdd to your `alerthq.yaml`:\n\n```yaml\nproviders:\n  elastic:\n    enabled: true\n    url: https://my-cluster.es.example.com:9200\n    kibanaUrl: https://my-cluster.kb.example.com:5601  # optional\n    auth:\n      type: basic\n      username: elastic\n      password: changeme\n    # Or use API key auth:\n    # auth:\n    #   type: apiKey\n    #   apiKey: base64encodedkey\n```\n\n| Field | Type | Required | Default | Description |\n|-------|------|----------|---------|-------------|\n| `url` | `string` | Yes | — | Elasticsearch cluster URL |\n| `kibanaUrl` | `string` | No | — | Kibana URL (enables Kibana rule fetching) |\n| `auth.type` | `'basic' \\| 'apiKey'` | Yes | — | Authentication type |\n| `auth.username` | `string` | If basic | — | Elasticsearch username |\n| `auth.password` | `string` | If basic | — | Elasticsearch password |\n| `auth.apiKey` | `string` | If apiKey | — | Base64-encoded API key |\n| `watcherPageSize` | `number` | No | `100` | Page size for watcher queries |\n| `kibanaPageSize` | `number` | No | `100` | Page size for Kibana rule queries |\n\n## Required Permissions\n\n**Elasticsearch:** The user/API key needs the `manage_watcher` or `monitor_watcher` cluster privilege to query watches.\n\n**Kibana:** The user/API key needs the `read` privilege for the Alerting feature in the relevant Kibana space(s).\n\n## Field Mapping\n\n### Watchers\n\n| AlertDefinition Field | Source |\n|-----------------------|--------|\n| `id` | `generateAlertId('elastic-watcher', _id)` |\n| `source` | `'elastic-watcher'` |\n| `sourceId` | `_id` (watch ID) |\n| `name` | `_id` (watches have no separate name field) |\n| `description` | Empty string |\n| `enabled` | `status.state.active` |\n| `severity` | `'unknown'` (watchers have no native severity) |\n| `conditionSummary` | Built from `condition` block (compare, script, always, etc.) |\n| `notificationTargets` | Extracted from `actions` (email, webhook, slack, pagerduty, logging, index) |\n| `tags` | Empty (watchers have no native tags) |\n| `lastModifiedAt` | `null` (not available from watcher API) |\n\n### Kibana Rules\n\n| AlertDefinition Field | Source |\n|-----------------------|--------|\n| `id` | `generateAlertId('elastic-kibana', id)` |\n| `source` | `'elastic-kibana'` |\n| `sourceId` | `id` (Kibana rule UUID) |\n| `name` | `name` |\n| `enabled` | `enabled` |\n| `severity` | `'unknown'` (Kibana rules have no unified severity field) |\n| `conditionSummary` | Built from `rule_type_id` + `params` (criteria, threshold, index) |\n| `notificationTargets` | Extracted from `actions` by `actionTypeId` (email, slack, pagerduty, webhook, server-log) |\n| `tags` | Kibana tags converted to `{ tagName: 'true' }` record |\n| `lastModifiedAt` | `updatedAt` |\n\n## Limitations\n\n- Watcher severity is always `'unknown'` — Elasticsearch watchers have no native severity concept.\n- Watcher names use the `_id` field since watchers have no dedicated name.\n- Watcher `lastModifiedAt` is not available from the query API.\n- Kibana rules require a separate `kibanaUrl` and do not use the Elasticsearch SDK.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}