Analytics

Kibana, worked by an AI employee

Not another app for your team to learn, and not a set of rules for you to build. You hire an AI employee, you give it access to your Kibana account, and you ask it for things in Slack or Teams the way you would ask anyone else on the team. There is nothing to map and nothing to maintain.

  • Analytics
  • Connects with a key
  • 49 ready-made tools
  • Asked in Slack or Teams
At work

An illustration of how the conversation reads, not a transcript from a client account.

What Kibana is

Kibana is a visualization and analytics platform for Elasticsearch, offering dashboards, data exploration, and monitoring capabilities for gaining insights from data

You paste in a key from your own Kibana account. It is kept encrypted, and you can withdraw it from inside Kibana whenever you like.

How a run works

One message in, the work done in Kibana.

  1. 01

    You ask

    You message your AI employee in the chat your team already has open, in one sentence, in your own words.

  2. 02

    It works out the step

    It decides what the job needs in Kibana. You do not pick anything from a menu or wire anything together.

  3. 03

    It does the work

    Signed in to your own Kibana account, inside the access you granted it, doing the thing you asked for.

  4. 04

    It reports back

    It tells you what it did, in the same thread. If it could not do something, it says so rather than guessing.

49 tools it already has

What it can do in Kibana

These are the ready-made tools your AI employee already has in Kibana. It is not limited to them, but it never has to be taught these.

  • Check Fleet PermissionsTool to check the permissions for the fleet api. use when you need to verify if the current user has the necessary privileges for fleet operations.
  • Create Alerting RuleTool to create a new alerting rule in kibana. use when you need to define a new condition that, when met, triggers an alert and potentially executes predefined actions.
  • Create CaseTool to create a new case in kibana. use when you need to open and track issues, incidents, or investigations. you can assign users, set severity levels, add tags, and configure ex
  • Create DashboardTool to create a new dashboard in kibana. use when you need to create a dashboard to visualize data. dashboards can contain visualizations, saved searches, and other embeddable obj
  • Create Data ViewTool to create a new data view (index pattern) in kibana. use when you need to define which elasticsearch indices to query and analyze in kibana. data views determine which fields
  • Create Kibana ConnectorTool to create a new connector in kibana. use when you need to integrate kibana with an external service.
  • Create or Update Saved ObjectTool to create or update a saved object in kibana. use when you need to programmatically manage kibana dashboards, visualizations, index patterns, etc.
  • Delete ActionTool to delete an action in kibana. use when you need to remove a specific action by its id, optionally within a specific space.
  • Delete Alerting RuleTool to delete an alerting rule in kibana. use when you need to remove a specific alerting rule by its id.
  • Delete ConnectorTool to delete a connector in kibana. use when you need to remove an existing connector.
  • Delete Fleet OutputTool to delete a specific output configuration in kibana fleet. use when you need to remove an existing output by its id.
  • Delete Fleet ProxyTool to delete a specific fleet proxy configuration by its id. use when you need to remove an existing proxy setup.
  • Delete ListDeletes a list. use when you want to delete a list by its id.
  • Delete Osquery Saved QueryTool to delete a saved osquery query by its id. use when you need to remove a specific osquery saved query.
  • Delete Saved ObjectTool to delete a saved object in kibana. use when you need to remove a specific saved object like a visualization or dashboard.
  • Find Detection Engine RulesRetrieves a list of detection engine rules based on specified criteria. use this tool to find detection rules.
  • Find Kibana AlertsTool to find and/or aggregate detection alerts in kibana. use this to retrieve a list of alerts, optionally filtering them with a query and performing aggregations.
  • Get Action TypesTool to fetch the list of available action types (e.g., '.slack', '.email', '.webhook') in kibana. use this to discover the 'actiontypeid' needed when creating a new action.
  • Get Alert TypesTool to retrieve available alert types in kibana. use when you need to get a list of all possible alert types and their metadata.
  • Get Alerting RulesTool to retrieve a list of alerting rules in kibana. use when you need to get a paginated set of rules based on specified conditions.
  • Get All ConnectorsTool to retrieve a list of all connectors in kibana. use this tool when you need to get information about available connectors.
  • Get CasesTool to retrieve a list of cases in kibana. use when you need to find or list existing security or operational cases, potentially filtering by various attributes like status, assig
  • Get Data ViewsTool to retrieve a list of data views available in kibana. use when you need to get a list of available data views, optionally filtering by a name pattern.
  • Get Endpoint List ItemsTool to retrieve all items from an endpoint exception list. use when you need to get a list of endpoint exceptions, for example, to check existing exceptions before adding a new on
  • Get Entity Store EnginesRetrieves the list of engines from the entity store.
  • Get Entity Store StatusTool to retrieve the status of the entity store in kibana. use this to check if the entity store is operational.
  • Get EPM Package StatisticsTool to retrieve statistics for a specific package in the elastic package manager. use when you need to get epm package statistics.
  • Get Fleet Agent PoliciesFetches a list of agent policies in fleet. use when you need to retrieve agent policy configurations.
  • Get Fleet Agents Available VersionsTool to retrieve the available versions for fleet agents. use when you need to get a list of all available elastic agent versions.
  • Get Fleet Agents Setup StatusTool to check if the fleet agents are set up. use when you need to verify the fleet agent setup status.
  • Get Fleet Data StreamsRetrieves the list of data streams in fleet.
  • Get Fleet Enrollment API KeyTool to retrieve details of a specific enrollment api key by its id. use when you have the id of an enrollment api key and need its details.
  • Get Fleet Enrollment API KeysTool to fetch a list of enrollment api keys. use when you need to retrieve existing enrollment tokens for kibana fleet.
  • Get Fleet EPM CategoriesTool to fetch the list of categories in the elastic package manager. use when you need to retrieve available package categories.
  • Get Fleet EPM Data StreamsTool to retrieve the list of data streams in the elastic package manager. use when you need to get a list of available data streams, optionally filtering by type, dataset, or categ
  • Get Fleet EPM Package DetailsTool to fetch details of a specific package and version in the elastic package manager (epm). use when you need to get information about a particular epm package, such as its title
  • Get Fleet EPM Package FileTool to retrieve a specific file from a package in the elastic package manager. use when you need to inspect the contents of a package file.
  • Get Fleet EPM PackagesTool to fetch the list of available packages in the elastic package manager. use when you need to find available integrations or their details.
  • Get Fleet EPM Packages (Limited)Tool to fetch a limited list of packages from the elastic package manager. use when you need to retrieve a list of available epm packages with minimal details.
  • Get Fleet Package PoliciesTool to retrieve a list of all package policies (agent & epm), providing their ids and associated details. use when you need to get an overview of existing package policies.
  • Get Fleet Server HostTool to fetch details of a specific fleet server host by its item id. use when you need to get information about a particular fleet server host.
  • Get Fleet Server HostsTool to retrieve the list of fleet server hosts. use when you need to get information about the available fleet server hosts.
  • Get Index Management IndicesTool to fetch information about indices managed by kibana's index management feature. it queries the underlying elasticsearch / cat/indices api to retrieve index details. use when
  • Get Installed EPM PackagesTool to retrieve the list of installed packages in the elastic package manager. use this when you need to check which packages are currently installed in fleet.
  • Get Kibana StatusTool to get the current status of kibana. use when you need to check if kibana is healthy, monitor its state, or get information about the kibana instance including version, uuid,
  • Get Node MetricsTool to retrieve statistics for nodes in an elasticsearch cluster, often visualized in kibana. use when you need to monitor node health, performance, or resource usage. this action
  • Get Reporting JobsTool to retrieve a list of reporting jobs in kibana. use when you need to see pending or completed reports. this uses an internal api endpoint, which might be subject to change wit
  • Get Saved ObjectsTool to retrieve a list of saved objects in kibana based on specified criteria. use when you need to find dashboards, visualizations, index patterns, or other saved entities.
  • List Entity Store EntitiesTool to list entity records in the entity store with support for paging, sorting, and filtering. use when you need to retrieve a list of entities such as users, hosts, or services.
Access, and who is in charge of it

You stay the boss of your Kibana account.

Nothing connects until you approve it. You grant access one app at a time, you can take it back the same way, and everything your AI employee does in there is written down where you can see it.

How we handle your data
  • It signs in to your own Kibana account. You are not moving anything into ours.
  • You grant access one app at a time, and you can take it back the same way.
  • Everything it does in Kibana is written down, with what it did and when.
  • Anything you tell it to check with you first, it checks with you first.
Other apps in the same corner of the business

It works in Kibana and the rest of your software in the same job

A real job rarely stays in one place. Reading a message in one app, checking a record in another and writing the result in a third is one request to your AI employee, not three.

Questions people ask about Kibana

Can an AI employee really work inside Kibana?
Yes. It signs in to your own Kibana account and works in it the way a new hire would, from the chat your team already has open. Nobody installs anything, and nobody learns a new screen.
Do I have to move anything out of Kibana?
No. Nothing moves and nothing is replaced. Your records stay in Kibana, your team carries on in the same screens they used yesterday, and your AI employee works alongside them in there.
How does it get into my Kibana account?
You paste in a key from your own Kibana account. It is kept encrypted, and you can withdraw it from inside Kibana whenever you like. You approve it before anything connects, and you can take the access back the same way you gave it.
What can it actually do in Kibana?
It has 49 ready-made tools in Kibana today, among them Check Fleet Permissions, Create Alerting Rule and Create Case. The full list is on this page. It is not limited to those, but it never has to be taught them.
Can it use Kibana and the rest of my software in the same job?
Yes, and that is usually the point. Reading a message in one app, checking a record in Kibana and writing the result somewhere else is one request to your AI employee, not three separate ones you stitch together.
Who decides what it is allowed to do in Kibana?
You do. You grant access one app at a time and can withdraw it at any time, anything you ask it to check with you first it checks with you first, and everything it does in Kibana is written down with what it did and when.