47 available actions

What your AI agent can do in Kibana

Kibana is a visualization and analytics platform for Elasticsearch, offering dashboards, data exploration, and monitoring capabilities for gaining insights from data This page lists every available action. Your agent only receives the actions and permissions required for the role you approve.

Common starting points

  • Find Kibana AlertsTool to find and/or aggregate detection alerts in Kibana.
  • Find Detection Engine RulesRetrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options.
  • Create Alerting RuleTool to create a new alerting rule in Kibana.
  • Create CaseTool to create a new case in Kibana.
  • Delete Alerting RuleTool to delete an alerting rule in Kibana.
  • Delete ConnectorTool to delete a connector in Kibana.

Browse all 47 actions by capability

Open a capability to see every supported action and its description.

Find & reviewLook up and review existing recordsView 34 actionsHide actions
  • Find Kibana AlertsTool to find and/or aggregate detection alerts in Kibana.
  • Get Action TypesRetrieves all available connector types (actions) in Kibana.
  • Get Alerting RulesTool to retrieve a list of alerting rules in Kibana.
  • Get Rule TypesRetrieves available rule types (alert types) in Kibana.
  • Get CasesTool to retrieve a list of cases in Kibana.
  • Get All ConnectorsTool to retrieve a list of all connectors in Kibana.
  • Get Data ViewsRetrieves all data views (formerly known as index patterns) available in Kibana.
  • Find Detection Engine RulesRetrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options.
  • Get Endpoint List ItemsRetrieves Elastic Endpoint exception list items with filtering, pagination, and sorting capabilities.
  • Get Entity Store EnginesRetrieves all entity store engines configured in Kibana.
  • List Entity Store EntitiesTool to list entity records in the entity store with support for paging, sorting, and filtering.
  • Get Entity Store StatusRetrieves the current status of the Kibana Entity Store and its configured engines.
  • Get Fleet Agent PoliciesRetrieves a paginated list of Fleet agent policies with filtering, sorting, and optional detailed information.
  • Get Fleet Agents Available VersionsTool to retrieve the available versions for Fleet agents.
  • Get Fleet Agents Setup StatusCheck Fleet setup readiness and identify missing requirements.
  • Check Fleet PermissionsTool to check the permissions for the Fleet API.
  • Get Fleet Enrollment API KeyTool to retrieve details of a specific enrollment API key by its ID.
  • Get Fleet Enrollment API KeysTool to fetch a list of enrollment API keys.
  • Get Fleet EPM CategoriesGet all available package categories in the Elastic Package Manager (EPM) with package counts.
  • Get Fleet EPM Data StreamsTool to retrieve the list of data streams in the Elastic Package Manager.
  • Get Fleet EPM Package DetailsRetrieves comprehensive details for a specific Fleet integration package version from the Elastic Package Manager (EPM).
  • Get Fleet EPM Package FileRetrieves a specific file from an Elastic Package Manager (EPM) package.
  • Get Fleet EPM PackagesTool to fetch the list of available packages in the Elastic Package Manager.
  • Get Installed EPM PackagesTool to retrieve the list of installed packages in the Elastic Package Manager.
  • Get Fleet EPM Packages (Limited)Retrieves a limited list of package names from the Elastic Package Manager (EPM) registry.
  • Get EPM Package StatisticsRetrieves usage statistics for a specific Fleet package in Kibana, including the number of package policies and agent policies using the package.
  • Get Fleet Package PoliciesRetrieves a list of Fleet package policies (integration policies) in Kibana.
  • Get Fleet Server HostTool to fetch details of a specific Fleet server host by its item ID.
  • Get Fleet Server HostsTool to retrieve the list of Fleet Server hosts.
  • Get Index Management IndicesTool to fetch information about indices managed by Kibana's Index Management feature.
  • Get Node MetricsTool to retrieve statistics for nodes in an Elasticsearch cluster, often visualized in Kibana.
  • Get Reporting JobsTool to retrieve a list of reporting jobs in Kibana.
  • Get Saved ObjectsTool to retrieve a list of saved objects in Kibana based on specified criteria.
  • Get Kibana StatusTool to get the current status of Kibana.
Create & communicateCreate records or send supported messagesView 6 actionsHide actions
  • Create Alerting RuleTool to create a new alerting rule in Kibana.
  • Create CaseTool to create a new case in Kibana.
  • Create Kibana ConnectorTool to create a new connector in Kibana.
  • Create DashboardTool to create a new dashboard in Kibana.
  • Create Data ViewTool to create a new data view (index pattern) in Kibana.
  • Create or Update Saved ObjectTool to create or update a saved object in Kibana.
Remove & cancelRemove records or cancel supported workView 7 actionsHide actions
  • Delete Alerting RuleTool to delete an alerting rule in Kibana.
  • Delete ConnectorTool to delete a connector in Kibana.
  • Delete Fleet OutputTool to delete a specific output configuration in Kibana Fleet.
  • Delete Fleet ProxyDeletes a Fleet proxy configuration by its unique identifier.
  • Delete ListDeletes a list.
  • Delete Osquery Saved QueryDelete a saved Osquery query by its saved object ID.
  • Delete Saved ObjectTool to delete a saved object in Kibana.

Connection record

A connection you can control.

Sign-in
Customer-managed key
Setup
Use a key you create and control. It is stored securely and limited to the work agreed for the role.
Boundaries
Only the approved role and actions.
Off switch
Revoke the connection from your account.

FAQ

Before you connect Kibana

How does the agent connect to Kibana?
With a key you create and control. It is stored securely, permissions are limited to what the agent needs, and you can revoke it at any time.
What can the agent actually do in Kibana?
The page above lists the 47 actions currently available through the Kibana connection. The role determines which of those actions the agent may use, and write access is only enabled when the workflow needs it.
Is Kibana included in my plan?
Connections are priced per tool on top of the base plan. Some are included and some are premium. See pricing for how connection charges work.
How long until Kibana is ready?
Timing depends on the sign-in method, permissions and workflow being connected. We confirm the scope and setup plan before enabling the connection.

Bring the workflow together

Ready to put Kibana to work?

Start with the responsibility you want off your plate. We’ll map the connection and the boundaries around it.

All product names, logos, and brands are property of their respective owners and are used for identification only. ZeroToClaw is not affiliated with or endorsed by Kibana.