Elastabot brings selected Elasticsearch and ElastAlert operations into Slack. A user can search stored records, ask about cluster health, or acknowledge an alert from the conversation where an incident is being discussed. That can reduce switching between tools during investigation. The bot also gives chat users access to potentially sensitive data and alert controls, so its permissions matter. Its dependency on Slack's classic app model limits new adoption.
Deployment and operating notes
The upstream Elastabot README identifies a Slack bot for Elasticsearch searches, health queries and ElastAlert acknowledgements. It explicitly requires a classic Slack bot and warns against converting it to granular permissions. Slack has paused deprecation of existing classic apps, but new classic apps cannot be created. That distinction makes the old creation instructions unsuitable for new adoption without claiming that every existing installation has stopped working.
For a surviving installation, identify the Slack app type, token scopes, search permissions and Elasticsearch write access used to silence alerts. Do not solve an authentication failure by broadening tokens or exposing the search cluster. A replacement should use a supported Slack app model and enforce which users may query sensitive data or acknowledge an alert. Test denied commands, channel membership, audit records and the actual silence behavior in a staging workspace. Preserve existing alert state and keep direct alert-management access during cutover. No current compatible Elastabot release or drop-in Slack migration was established here; an accessible repository alone does not resolve that integration dependency.
Historical upstream link check · 2026-10-09
The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
A Slack bot companion to Elasticsearch and ElastAlert. Current support includes searching for data, checking the cluster health, acknowledging (and silencing) alerts, and also triggering triage events, which are currently initiated via an smtp email.
The emails by default will contain the alert details, but arbitrary triage requests can also be created. The triage email is best used with a ticketing system that is monitoring for such emails, such as Jira.
Search
Slack users can search the Elasticsearch cluster for arbitrary search criteria, using the Lucene syntax. This can be useful for maintaining a history of searches, but needs to be used with caution. Certain Slack communities with public access should not enable this feature if the Elasticsearch cluster contains sensitive data.
Acknowledge Elastalerts
When told to ack an alert generated by Elastalert, Elastabot will look for the alert and silence it by creating a silence document in the appropriate Elasticsearch index.
Additionally, if the ack command includes a question mark ,?, then the alert will be sent through the triage process. The question mark symbolizes that there are unanswered questions related to the alert and therefore the alert needs to be triaged.
NOTE: Alert names provided in the command argument are searched as-is, with the only character replacement occurring on the space character, which is escaped prior to sending to Elasticsearch.
Sources & further reading
Spotted something that needs another look?
Help improve this page →