Built by Metorial, the integration platform for agentic AI.
Search and list Kibana cases for incident tracking. Cases can be associated with alerts, have comments and attachments, and can be synced with external case management systems.
List all connectors configured in Kibana. Connectors integrate with external services like email, Slack, PagerDuty, webhook, Jira, ServiceNow, Microsoft Teams, and more.
List all security roles configured in Kibana. Roles define Elasticsearch and Kibana feature privileges.
Export Kibana saved objects in NDJSON format for backup or migration between environments. Specify either object types to export all objects of those types, or provide specific object IDs to export selectively.
List all data views (index patterns) configured in Kibana. Data views define which Elasticsearch indices Kibana queries.
Create, get, update, or delete a Fleet agent policy. Agent policies define agent behavior, integrations, and monitoring configuration.
Test or execute a Kibana connector with specific parameters. Useful for testing connector configuration or sending one-off notifications.
Get the current status of the Kibana instance, including overall health, version, and plugin status.
Add a comment or alert attachment to an existing Kibana case.
Get Fleet enrollment API keys used to enroll new Elastic Agents.
Create, get, update, or delete a Kibana case. Cases are used for incident tracking and can be associated with alerts and synced with external case management systems.
Create, get, update, or delete a Kibana data view (index pattern). Data views define which Elasticsearch indices Kibana queries. Supports configuring runtime fields, time fields, field formats, and source filters.
Create, get, update, or delete a Kibana connector. Connectors integrate with external services for rule-triggered notifications. Supported types include email, Slack, PagerDuty, webhook, Jira, ServiceNow, Microsoft Teams, Opsgenie, and more.
Get, create, update, or delete a Kibana saved object. Supports dashboards, visualizations, maps, data views, Canvas workpads, and other saved object types. Provide the action to perform along with the object type and ID.
List all Kibana spaces. Spaces organize dashboards and other saved objects into meaningful categories.
Create, get, update, or delete a Kibana Service Level Objective (SLO). Supports KQL, metric custom, and histogram indicator types with occurrences or timeslices budgeting methods.
Search and list Kibana alerting rules. Rules monitor conditions and trigger actions when thresholds are met. Supports filtering by search terms and KQL filters.
List Fleet agent policies in Kibana. Agent policies define what data agents collect and which integrations they run.
List Elastic Agents managed by Fleet. Shows agent status, policy assignment, version, and host information.
Create, get, update, or delete a Kibana security role. Roles define Elasticsearch cluster/index privileges and Kibana feature privileges per space.
Search and list Kibana saved objects such as dashboards, visualizations, maps, data views, Canvas workpads, and other saved objects. Use this to find specific objects by type and search term, or to browse all objects of a given type.
Create, get, update, or delete a Kibana space. Spaces enable organizing dashboards and other saved objects into meaningful categories. Rules and connectors are isolated to the space in which they were created.
Create, get, update, delete, enable, disable, or mute/unmute a Kibana alerting rule. Rules monitor conditions and trigger actions via connectors when thresholds are met. Supports Elasticsearch query, index threshold, metric threshold, log threshold, and more.
Search and list Kibana Service Level Objectives (SLOs). SLOs define reliability targets for services and can use various indicator types.
List Fleet package policies in Kibana. Package policies attach Elastic integrations, such as Nginx or System, to Fleet agent policies.
Get, set, or unset the default Kibana data view for the current space. The default data view is used when no specific data view is selected.
List Kibana alerting rule types available to the authenticated user. Use this before creating rules to discover ruleTypeId values, action groups, required license level, and authorized consumers.
List Kibana connector types available for rules and cases, including license and feature availability. Use this before creating connectors to discover connectorTypeId values and supported features.
Schedule or delete a Kibana alerting rule snooze schedule. Snooze schedules temporarily suppress rule notifications during maintenance windows or planned downtime.
Get, create, update, or delete a Fleet package policy. Package policies attach Elastic integration packages to Fleet agent policies. Provide packagePolicy as the raw Kibana package policy request body for create and update.