mcpbeat

elastic Skills

70 skills published by elastic across 1 repository. Together they weigh 902 890 tokens — that is what loading all of them at once would cost you in context.

70 skills 902 890 tokens total

Cloud Access Management
agent-skills

> projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.

18k tokens scripts
Cloud Create Project
agent-skills

> Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.

9k tokens scripts
Cloud Manage Project
agent-skills

> credentials, resume, and load saved credentials. Connects to existing projects by resolving endpoints and acquiring scoped Elasticsearch API keys. Use when performing day-2 operations on serverless projects, connecting to an existing project, loading or resetting project credentials, or looking up project details.

10k tokens scripts
Cloud Network Security
agent-skills

> IP filters and AWS PrivateLink VPC filters. Use when restricting network access or configuring private connectivity.

8k tokens scripts
Cloud Setup
agent-skills

> Configures Elastic Cloud authentication and environment defaults. Use when setting up EC_API_KEY, configuring Cloud API access, or when another cloud skill requires credentials.

1k tokens
Elasticsearch Audit
agent-skills

> Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.

6k tokens
Elasticsearch Authn
agent-skills

> Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms. Use when connecting with credentials, choosing a realm, or managing API keys. Assumes the target realms are already configured.

6k tokens
Elasticsearch Authz
agent-skills

> security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.

10k tokens
Elasticsearch Esql
agent-skills

> Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.

70k tokens scripts
Elasticsearch File Ingest
agent-skills

> Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms. Use when loading files or batch importing data — not for reindexing, general ingest pipeline design, or bulk API patterns.

9k tokens scripts
Elasticsearch Onboarding
agent-skills

> Help developers new to Elasticsearch get from zero to a working search experience. Guide them through understanding their intent, mapping their data, and building a search experience with best practices baked in. Use this when the user shows intent to build search-related functionality, asks about Elasticsearch-related concepts for their use case, or expresses the need for help getting started with Elasticsearch.

34k tokens
Elasticsearch Security Troubleshooting
agent-skills

> expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.

8k tokens
Kibana Agent Builder
agent-skills

> Create and manage Agent Builder agents and custom tools in Kibana. Use when asked to create, update, delete, test, or inspect agents or tools in Agent Builder.

15k tokens scripts
Kibana Alerting Rules
agent-skills

> Create and manage Kibana alerting rules via REST API or Terraform. Use when creating, updating, or managing rule lifecycle (enable, disable, mute, snooze) or rules-as-code workflows.

4k tokens
Kibana Anomaly Detection
agent-skills

Elastic ML anomaly detection skill — investigation/RCA, score explanation, job operations (create, datafeed, start/stop, results), and troubleshooting (missing docs, memory limits, datafeed health, lifecycle). Operates against Kibana Agent Builder MCP tools (`ad_*`) on `.ml-anomalies-*`, `.ml-config`, `.ml-notifications-*`, `.ml-annotations-*`. Use when answering "what broke?"/"which entity?"/RCA, "why is score high/low?"/renormalization, "datafeed stopped"/"memory limit", or any request to set up or configure an ML anomaly detection job.

73k tokens scripts
Kibana Audit
agent-skills

> Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.

5k tokens
Kibana Connectors
agent-skills

> Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Use when configuring third-party integrations or managing connectors as code.

10k tokens
Kibana Dashboards
agent-skills

> Create and manage Kibana Dashboards and visualizations. Use when you need to define dashboards and visualizations declaratively, version control them, or automate their deployment.

25k tokens scripts
Kibana Streams
agent-skills

> List, inspect, enable, disable, and resync Kibana Streams via the REST API. Use when the user needs stream details, ingest/query settings, queries, significant events, or attachments.

3k tokens
Kibana Vega
agent-skills

> Create Vega and Vega-Lite visualizations with ES|QL data sources in Kibana. Use when building custom charts, dashboards, or programmatic panel layouts beyond standard Lens charts.

27k tokens scripts
Observability Edot Dotnet Instrument
agent-skills

> Instrument a .NET application with the Elastic Distribution of OpenTelemetry (EDOT) .NET SDK for automatic tracing, metrics, and logs. Use when adding observability to a .NET service that has no existing APM agent.

467 tokens
Observability Edot Dotnet Migrate
agent-skills

> Migrate a .NET application from the classic Elastic APM .NET agent to the EDOT .NET SDK. Use when switching from Elastic.Apm.* packages to Elastic.OpenTelemetry.

532 tokens
Observability Edot Java Instrument
agent-skills

> Instrument a Java application with the Elastic Distribution of OpenTelemetry (EDOT) Java agent for automatic tracing, metrics, and logs. Use when adding observability to a Java service that has no existing APM agent.

457 tokens
Observability Edot Java Migrate
agent-skills

> Migrate a Java application from the classic Elastic APM Java agent to the EDOT Java agent. Use when switching from elastic-apm-agent.jar to elastic-otel-javaagent.jar.

523 tokens
Observability Edot Python Instrument
agent-skills

> Instrument a Python application with the Elastic Distribution of OpenTelemetry (EDOT) Python agent for automatic tracing, metrics, and logs. Use when adding observability to a Python service that has no existing APM agent.

506 tokens
Observability Edot Python Migrate
agent-skills

> Migrate a Python application from the classic Elastic APM Python agent to the EDOT Python agent. Use when switching from elastic-apm to elastic-opentelemetry.

531 tokens
Observability K8s Investigation
agent-skills

> Investigate Kubernetes workload, node, and control-plane issues using OTel telemetry (EDOT). Use when diagnosing pod failures (CrashLoopBackOff, OOMKilled, Error), node pressure, resource exhaustion, image pull failures, admission rejections, autoscaling anomalies, or correlating K8s state with application signals. OTel ingest path only — the legacy ECS Kubernetes integration shape is out of scope.

8k tokens
Observability LLM Obs
agent-skills

> orchestration. Use when the user asks about LLM monitoring, GenAI observability, or AI cost/quality.

4k tokens
Observability Logs Search
agent-skills

> Search and filter Observability logs using ES|QL. Use when investigating log spikes, errors, or anomalies; getting volume and trends; or drilling into services or containers during incidents.

5k tokens
Observability Manage Slos
agent-skills

> Create and manage SLOs in Elastic Observability using the Kibana API. Use when defining SLIs, setting error budgets, or managing SLO lifecycle.

1k tokens
Observability Service Health
agent-skills

> Assess APM service health using SLOs, alerts, ML, throughput, latency, error rate, and dependencies. Use when checking service status, performance, or when the user asks about service health.

10k tokens scripts
Security Alert Triage
agent-skills

> Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.

12k tokens scripts
Security Case Management
agent-skills

> Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.

8k tokens scripts
Security Detection Rule Management
agent-skills

> Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use for false positives, exceptions, new coverage, noisy rules, or rule management via Kibana API.

21k tokens scripts
Security Generate Security Sample Data
agent-skills

> Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, or setting up a POC.

29k tokens scripts
Cloud Access Management
agent-skills

> projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.

18k tokens scripts
Cloud Create Project
agent-skills

> Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.

9k tokens scripts
Cloud Manage Project
agent-skills

> credentials, resume, and load saved credentials. Connects to existing projects by resolving endpoints and acquiring scoped Elasticsearch API keys. Use when performing day-2 operations on serverless projects, connecting to an existing project, loading or resetting project credentials, or looking up project details.

10k tokens scripts
Cloud Network Security
agent-skills

> IP filters and AWS PrivateLink VPC filters. Use when restricting network access or configuring private connectivity.

8k tokens scripts
Cloud Setup
agent-skills

> Configures Elastic Cloud authentication and environment defaults. Use when setting up EC_API_KEY, configuring Cloud API access, or when another cloud skill requires credentials.

1k tokens
Elasticsearch Audit
agent-skills

> Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.

6k tokens
Elasticsearch Authn
agent-skills

> Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms. Use when connecting with credentials, choosing a realm, or managing API keys. Assumes the target realms are already configured.

6k tokens
Elasticsearch Authz
agent-skills

> security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.

10k tokens
Elasticsearch Esql
agent-skills

> Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.

70k tokens scripts
Elasticsearch File Ingest
agent-skills

> Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms. Use when loading files or batch importing data — not for reindexing, general ingest pipeline design, or bulk API patterns.

9k tokens scripts
Elasticsearch Onboarding
agent-skills

> Help developers new to Elasticsearch get from zero to a working search experience. Guide them through understanding their intent, mapping their data, and building a search experience with best practices baked in. Use this when the user shows intent to build search-related functionality, asks about Elasticsearch-related concepts for their use case, or expresses the need for help getting started with Elasticsearch.

34k tokens
Elasticsearch Security Troubleshooting
agent-skills

> expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.

8k tokens
Kibana Agent Builder
agent-skills

> Create and manage Agent Builder agents and custom tools in Kibana. Use when asked to create, update, delete, test, or inspect agents or tools in Agent Builder.

15k tokens scripts
Kibana Alerting Rules
agent-skills

> Create and manage Kibana alerting rules via REST API or Terraform. Use when creating, updating, or managing rule lifecycle (enable, disable, mute, snooze) or rules-as-code workflows.

4k tokens
Kibana Anomaly Detection
agent-skills

Elastic ML anomaly detection skill — investigation/RCA, score explanation, job operations (create, datafeed, start/stop, results), and troubleshooting (missing docs, memory limits, datafeed health, lifecycle). Operates against Kibana Agent Builder MCP tools (`ad_*`) on `.ml-anomalies-*`, `.ml-config`, `.ml-notifications-*`, `.ml-annotations-*`. Use when answering "what broke?"/"which entity?"/RCA, "why is score high/low?"/renormalization, "datafeed stopped"/"memory limit", or any request to set up or configure an ML anomaly detection job.

73k tokens scripts
Kibana Audit
agent-skills

> Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.

5k tokens
Kibana Connectors
agent-skills

> Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Use when configuring third-party integrations or managing connectors as code.

10k tokens
Kibana Dashboards
agent-skills

> Create and manage Kibana Dashboards and visualizations. Use when you need to define dashboards and visualizations declaratively, version control them, or automate their deployment.

25k tokens scripts
Kibana Vega
agent-skills

> Create Vega and Vega-Lite visualizations with ES|QL data sources in Kibana. Use when building custom charts, dashboards, or programmatic panel layouts beyond standard Lens charts.

27k tokens scripts
Kibana Streams
agent-skills

> List, inspect, enable, disable, and resync Kibana Streams via the REST API. Use when the user needs stream details, ingest/query settings, queries, significant events, or attachments.

3k tokens
Observability Edot Dotnet Instrument
agent-skills

> Instrument a .NET application with the Elastic Distribution of OpenTelemetry (EDOT) .NET SDK for automatic tracing, metrics, and logs. Use when adding observability to a .NET service that has no existing APM agent.

467 tokens
Observability Edot Dotnet Migrate
agent-skills

> Migrate a .NET application from the classic Elastic APM .NET agent to the EDOT .NET SDK. Use when switching from Elastic.Apm.* packages to Elastic.OpenTelemetry.

532 tokens
Observability Edot Java Instrument
agent-skills

> Instrument a Java application with the Elastic Distribution of OpenTelemetry (EDOT) Java agent for automatic tracing, metrics, and logs. Use when adding observability to a Java service that has no existing APM agent.

457 tokens
Observability Edot Java Migrate
agent-skills

> Migrate a Java application from the classic Elastic APM Java agent to the EDOT Java agent. Use when switching from elastic-apm-agent.jar to elastic-otel-javaagent.jar.

523 tokens
Observability Edot Python Instrument
agent-skills

> Instrument a Python application with the Elastic Distribution of OpenTelemetry (EDOT) Python agent for automatic tracing, metrics, and logs. Use when adding observability to a Python service that has no existing APM agent.

506 tokens
Observability Edot Python Migrate
agent-skills

> Migrate a Python application from the classic Elastic APM Python agent to the EDOT Python agent. Use when switching from elastic-apm to elastic-opentelemetry.

531 tokens
Observability K8s Investigation
agent-skills

> Investigate Kubernetes workload, node, and control-plane issues using OTel telemetry (EDOT). Use when diagnosing pod failures (CrashLoopBackOff, OOMKilled, Error), node pressure, resource exhaustion, image pull failures, admission rejections, autoscaling anomalies, or correlating K8s state with application signals. OTel ingest path only — the legacy ECS Kubernetes integration shape is out of scope.

8k tokens
Observability LLM Obs
agent-skills

> orchestration. Use when the user asks about LLM monitoring, GenAI observability, or AI cost/quality.

4k tokens
Observability Logs Search
agent-skills

> Search and filter Observability logs using ES|QL. Use when investigating log spikes, errors, or anomalies; getting volume and trends; or drilling into services or containers during incidents.

5k tokens
Observability Manage Slos
agent-skills

> Create and manage SLOs in Elastic Observability using the Kibana API. Use when defining SLIs, setting error budgets, or managing SLO lifecycle.

1k tokens
Observability Service Health
agent-skills

> Assess APM service health using SLOs, alerts, ML, throughput, latency, error rate, and dependencies. Use when checking service status, performance, or when the user asks about service health.

10k tokens scripts
Security Alert Triage
agent-skills

> Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.

12k tokens scripts
Security Case Management
agent-skills

> Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.

8k tokens scripts
Security Detection Rule Management
agent-skills

> Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use for false positives, exceptions, new coverage, noisy rules, or rule management via Kibana API.

21k tokens scripts
Security Generate Security Sample Data
agent-skills

> Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, or setting up a POC.

29k tokens scripts