Kibana
Elasticsearch visualization platform for alerting rules, connectors, Fleet outputs, saved queries, lists, and dashboard configuration.
Helps observability teams that manage alerting rules and connectors, configure Fleet outputs and proxies, and remove obsolete saved queries.
Use Kibana with Snow
Snow is a personal AI assistant that builds real apps for you, and they can put Kibana to work.
What Snow can do with Kibana
These are the Kibana operations Snow and the apps you build with it can run. Sign in to choose which ones Snow may run without asking.
Reads34
Look at your data without changing it.
- Check Fleet Permissions
Tool to check the permissions for the Fleet API. Use when you need to verify if the current user has the necessary privileges for Fleet operations.
- Find Detection Engine Rules
Retrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options. Use this action to: - List all detection rules in your Kibana security solution - Search for specific rules using KQL filters (by name, tags, severity, enabled status, etc.) - Sort rules by various criteria (name, risk score, creation date, etc.) - Paginate through large rule sets - Select specific fields to return for efficient data retrieval The detection engine rules are used for identifying security threats and generating alerts.
- Find Kibana Alerts
Tool to find and/or aggregate detection alerts in Kibana. Use this to retrieve a list of alerts, optionally filtering them with a query and performing aggregations.
- Get Action Types
Retrieves all available connector types (actions) in Kibana. Connector types (also called action types) are integrations like Slack, Email, Webhook, ServiceNow, etc. that can be used with alerting rules, cases, and workflows. Use this to discover which connector types are available and their requirements (license, features) before creating a new connector instance. Returns detailed information about each connector type including: - ID (e.g., '.slack', '.email', '.webhook') - Display name and enabled status - License requirements (basic, gold, platinum, enterprise) - Supported features (alerting, cases, workflows, etc.) - Configuration and deprecation status
- Get Alerting Rules
Tool to retrieve a list of alerting rules in Kibana. Use when you need to get a paginated set of rules based on specified conditions.
- Get All Connectors
Tool to retrieve a list of all connectors in Kibana. Use this tool when you need to get information about available connectors.
- Get Cases
Tool to retrieve a list of cases in Kibana. Use when you need to find or list existing security or operational cases, potentially filtering by various attributes like status, assignee, or severity.
- Get Data Views
Retrieves all data views (formerly known as index patterns) available in Kibana. Data views define which Elasticsearch indices you want to explore and are used throughout Kibana for features like Discover, Visualize, and Dashboard. This action returns a list of all configured data views with their IDs, names, and index patterns. Use this to discover available data sources before querying specific data views for detailed field information.
- Get Endpoint List Items
Retrieves Elastic Endpoint exception list items with filtering, pagination, and sorting capabilities. Use this action to: - List all endpoint exceptions in the security solution - Filter exceptions by specific field values (e.g., host.name:test-host) - Sort and paginate through exception items - Verify existing exceptions before creating new ones The endpoint exception list contains security exceptions applied to Elastic Endpoint agents.
- Get Entity Store Engines
Retrieves all entity store engines configured in Kibana. Entity store engines aggregate and manage entity data for different entity types (user, host, service). This action returns detailed configuration and status information for all engines, including their current status (installing, started, stopped, error), index patterns, processing parameters, and any error details if applicable. Use this to monitor entity store engines, check their operational status, and review their configuration settings.
Creates2
Add something new to your account.
- Create Case
Tool to create a new case in Kibana. Use when you need to open and track issues, incidents, or investigations. You can assign users, set severity levels, add tags, and configure external connectors for integration with ITSM systems.
- Create Kibana Connector
Tool to create a new connector in Kibana. Use when you need to integrate Kibana with an external service.
Updates4
Change something that is already there.
- Create Alerting Rule
Tool to create a new alerting rule in Kibana. Use when you need to define a new condition that, when met, triggers an alert and potentially executes predefined actions.
- Create Dashboard
Tool to create a new dashboard in Kibana. Use when you need to create a dashboard to visualize data. Dashboards can contain visualizations, saved searches, and other embeddable objects. Note: When using serverless Kibana, you must provide a dashboard_id. The action will automatically fallback to the import API for serverless environments.
- Create Data View
Tool to create a new data view (index pattern) in Kibana. Use when you need to define which Elasticsearch indices to query and analyze in Kibana. Data views determine which fields are available in Discover, Visualize, and other Kibana apps.
- Create or Update Saved Object
Tool to create or update a saved object in Kibana. Use when you need to programmatically manage Kibana dashboards, visualizations, index patterns, etc.
Deletes7
Remove something. This often cannot be undone.
- Delete Alerting Rule
Tool to delete an alerting rule in Kibana. Use when you need to remove a specific alerting rule by its ID.
- Delete Connector
Tool to delete a connector in Kibana. Use when you need to remove an existing connector.
- Delete Fleet Output
Tool to delete a specific output configuration in Kibana Fleet. Use when you need to remove an existing output by its ID.
- Delete Fleet Proxy
Deletes a Fleet proxy configuration by its unique identifier. Fleet proxies enable agents to communicate through proxy servers. Use this action to remove proxy configurations that are no longer needed. The proxy must not be in use by any agent policies or outputs before deletion. Requires 'fleet-settings-all' privileges in Kibana.
- Delete List
Deletes a list. Use when you want to delete a list by its ID.
- Delete Osquery Saved Query
Delete a saved Osquery query by its saved object ID. Use this to remove a specific Osquery saved query from Kibana. IMPORTANT: This action requires the 'saved_object_id' (UUID format), not the custom 'id' field. You can obtain the saved_object_id by listing queries first or from the response when creating a query.
- Delete Saved Object
Tool to delete a saved object in Kibana. Use when you need to remove a specific saved object like a visualization or dashboard.
Related integrations
Ready to put Kibana to work?
Sign up free, build an app by chatting, and connect Kibana in minutes. No credit card required.