Use Elasticsearch API token representing logged in user who created the alert to perform ES queries during alert execution.