Agent skill

Elasticsearch Audit

by aspectrr in aspectrr/deer

Enable, configure, and query Elasticsearch security audit logs.

MITAuto-check passedSecurity

Install Elasticsearch Audit

skills CLI
$ npx skills add aspectrr/deer --skill elasticsearch-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aspectrr/deer elasticsearch-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/elasticsearch-audit .claude/skills/elasticsearch-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch-audit
GitHub stars
405
Token cost
~1.7k tokens
SKILL.md length
401 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Enable, configure, and query Elasticsearch security audit logs.

  • The task involves audit logging setup
  • SKILL.md covers Jobs to Be Done, Prerequisites, Enable Audit Logging and Audit Output, plus 5 more sections
  • Calls curl
  • Event filtering

What it does

Elasticsearch Audit is an agent skill from aspectrr/deer. Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Search implementation, Security review and Security operations. It works with Elasticsearch. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.

When your agent uses it

  • The task involves audit logging setup
  • Event filtering
  • Investigating security incidents like failed logins

Example prompts

  • “/elasticsearch-audit”

What it can do on your machine

Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Elasticsearch Audit loads about 1.7k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 401 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 401 words, ~1,738 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch-audit/SKILL.md (or your agent's skills folder).
name
elasticsearch-audit
description
Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.
metadata.author
elastic
metadata.version
0.1.0
metadata.source
elastic/agent-skills//skills/elasticsearch/elasticsearch-audit

Elasticsearch Audit Logging

Enable and configure security audit logging for Elasticsearch via the cluster settings API. Audit logs record security events such as authentication attempts, access grants and denials, role changes, and API key operations.

For detailed API endpoints and event types, see references/api-reference.md.

Jobs to Be Done

  • Enable or disable security audit logging on a cluster
  • Select which security events to record (authentication, access, config changes)
  • Create filter policies to reduce audit log noise
  • Query audit logs for failed authentication attempts
  • Investigate unauthorized access or privilege escalation incidents
  • Set up compliance-focused audit configuration
  • Detect brute-force login patterns from audit data
  • Configure audit output to an index for programmatic querying

Prerequisites

ItemDescription
Elasticsearch URLCluster endpoint (e.g. https://localhost:9200 or a Cloud deployment URL)
AuthenticationValid credentials (see the elasticsearch-authn skill)
Cluster privilegesmanage cluster privilege to update cluster settings
LicenseAudit logging requires a gold, platinum, enterprise, or trial license

Enable Audit Logging

bash
curl -X PUT "${ELASTICSEARCH_URL}/_cluster/settings" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "persistent": {
      "xpack.security.audit.enabled": true
    }
  }'

Audit Output

OutputSetting valueDescription
logfilelogfileWritten to <ES_HOME>/logs/<cluster>_audit.json. Default.
indexindexWritten to .security-audit-* indices. Queryable via the API.
bash
curl -X PUT "${ELASTICSEARCH_URL}/_cluster/settings" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "persistent": {
      "xpack.security.audit.enabled": true,
      "xpack.security.audit.outputs": ["index", "logfile"]
    }
  }'

Select Events to Record

Include specific events only
bash
curl -X PUT "${ELASTICSEARCH_URL}/_cluster/settings" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "persistent": {
      "xpack.security.audit.logfile.events.include": [
        "authentication_failed",
        "access_denied",
        "access_granted",
        "anonymous_access_denied",
        "tampered_request",
        "run_as_denied",
        "connection_denied"
      ]
    }
  }'
Event types reference
EventFires when
authentication_failedCredentials were rejected
authentication_successUser authenticated successfully
access_grantedAn authorized action was performed
access_deniedAn action was denied due to insufficient privileges
anonymous_access_deniedAn unauthenticated request was rejected
tampered_requestA request was detected as tampered with
connection_grantedA node joined the cluster (transport layer)
connection_deniedA node connection was rejected
security_config_changeA security setting was changed (role, user, API key, etc.)
Show full SKILL.md (149 more words)Show less

Filter Policies

Filter policies suppress specific audit events by user, realm, role, or index.

bash
curl -X PUT "${ELASTICSEARCH_URL}/_cluster/settings" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "persistent": {
      "xpack.security.audit.logfile.events.ignore_filters": {
        "system_users": {
          "users": ["_xpack_security", "_xpack", "elastic/fleet-server"],
          "realms": ["_service_account"]
        }
      }
    }
  }'

Query Audit Events

Search for failed authentication attempts
bash
curl -X POST "${ELASTICSEARCH_URL}/.security-audit-*/_search" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "query": {
      "bool": {
        "filter": [
          { "term": { "event.action": "authentication_failed" } },
          { "range": { "@timestamp": { "gte": "now-24h" } } }
        ]
      }
    },
    "sort": [{ "@timestamp": { "order": "desc" } }],
    "size": 50
  }'
Search for access denied events
bash
curl -X POST "${ELASTICSEARCH_URL}/.security-audit-*/_search" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "query": {
      "bool": {
        "filter": [
          { "term": { "event.action": "access_denied" } },
          { "range": { "@timestamp": { "gte": "now-7d" } } }
        ]
      }
    },
    "sort": [{ "@timestamp": { "order": "desc" } }],
    "size": 20
  }'

Deployment Compatibility

CapabilitySelf-managedECHServerless
ES audit via cluster settingsYesYesNot available
ES logfile outputYesVia Cloud UINot available
ES index outputYesYesNot available
Filter policies via cluster settingsYesYesNot available

Guidelines

Prefer index output for programmatic access

Enable the index output to make audit events queryable. The logfile output is better for shipping to external SIEM tools via Filebeat but cannot be queried through the Elasticsearch API.

Start restrictive, then widen

Begin with failure events only (authentication_failed, access_denied, security_config_change). Add success events only when needed — they generate high volume.

Monitor audit index size

Set up an ILM policy to roll over and delete old .security-audit-* indices. A 30-90 day retention is typical.

© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in deer-cli/internal/skill/defaults/elasticsearch-audit of aspectrr/deer.

Open the folder on GitHubat commit e4f9845

Compare with similar skills

Elasticsearch Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch Audit this skillaspectrr/deer405—~1.7kAutomated safety check: PassMIT
Building Threat Feed Aggregation With Mispmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Detecting Debug Endpointsjeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Ecs Operation Reviewaws/tools-for-devops-agent102—~4.8kAutomated safety check: PassApache-2.0
Detecting Insider Threat With Uebamukul975/Anthropic-Cybersecurity-Skills34k—~738Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0

Similar skills

  • Building Threat Feed Aggregation With Misp

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting Debug Endpoints

    jeremylongshore/tons-of-skills-marketplace

    Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…

    2.8k GitHub stars~2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Ecs Operation Review

    aws/tools-for-devops-agent

    Official

    Performs a comprehensive Amazon ECS operations review across the 6 review pillars (Resiliency & HA, Observability, Security, Operations, Performance, Additional Analysis) using read-only AWS APIs…

    102 GitHub stars~4.8k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Detecting Insider Threat With Ueba

    mukul975/Anthropic-Cybersecurity-Skills

    Implement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and alert on insider threat…

    34k GitHub stars~738 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 2 days ago
    SecurityAuto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    SecurityAuto-check: notes

More from aspectrr/deer

All 14 skills in this repo
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Auto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Kafka

    aspectrr/deer

    Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.

    405 GitHub stars~946 tokensUpdated 5 mo ago
    Auto-check passed
  • Create and manage Kibana alerting rules via REST API or Terraform.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed

Works with

Questions about Elasticsearch Audit

What does Elasticsearch Audit do?

Enable, configure, and query Elasticsearch security audit logs. Elasticsearch Audit is an agent skill from aspectrr/deer. Enable, configure, and query Elasticsearch security audit logs.

When should I use Elasticsearch Audit?

Elasticsearch Audit fits situations like: the task involves audit logging setup; event filtering; investigating security incidents like failed logins.

How do I install Elasticsearch Audit in Claude Code?

Run `npx skills add aspectrr/deer --skill elasticsearch-audit -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/elasticsearch-audit in aspectrr/deer) into .claude/skills/elasticsearch-audit in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch Audit in Codex?

Run `npx skills add aspectrr/deer --skill elasticsearch-audit -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/elasticsearch-audit in aspectrr/deer) into .agents/skills/elasticsearch-audit in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill elasticsearch-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-audit, .gemini/skills/elasticsearch-audit, .github/skills/elasticsearch-audit and .opencode/skills/elasticsearch-audit in your project.

What does Elasticsearch Audit need to run?

Going by SKILL.md and its folder, Elasticsearch Audit needs the command-line tools its instructions call (curl).

Does Elasticsearch Audit access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Elasticsearch Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch Audit use?

Elasticsearch Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch Audit use?

About 1.7k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Elasticsearch Audit?

Skills that share tags, products or a category with Elasticsearch Audit: Building Threat Feed Aggregation With Misp (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Debug Endpoints (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Ecs Operation Review (aws/tools-for-devops-agent, 102 stars) and Detecting Insider Threat With Ueba (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch Audit?

aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.

Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.