I pulled the tasks.db SQLite DB and looked through that. While the directory structure appears to be a UUID from the database, I didn’t see the alert_methods listed in the database.
You can find global alert methods from /usr/[local]/share/openvas/openvasmd/global_alert_methods. As you have noticed, some alert methods are hard-coded.
The best way to create your own alert methods is to start from the source code of gvmd.
Clone one of the existing that appears closest to what you want.
However, this is not a user feature. You will not find user-documentation on how to add a new alert method. You rather have to search through the source code about what to consider. It might also help if you search for some commits where alerts were added.
If you are not a developer, this is a considerable challenge.
As an alternative you can run GMP scripts to pull data from GVM and send/process it the way you
need. In fact, this is pretty convenient. You need your own scheduling though.
There are also a number of alerts that simply place a report XML into some storage, for example via SCP.
You then would handle all that arrives in the drop zone. Several SIEM can use such a scheme to import data.
This is exactly how I have done the OpenVAS-Splunk interface. Report is copied by SCP alert to localhost into target directory where Splunk picks it up. I’m aware that I could do Splunk integration with “Send to host” alert as well, however, I found this approach works better for me.