Agent skill

Elasticsearch Security Troubleshooting

by aspectrr in aspectrr/deer

Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

MITAuto-check passedBackend & APIs

Install Elasticsearch Security Troubleshooting

skills CLI
$ npx skills add aspectrr/deer --skill elasticsearch-security-troubleshooting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aspectrr/deer elasticsearch-security-troubleshooting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/elasticsearch-security-troubleshooting .claude/skills/elasticsearch-security-troubleshooting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch-security-troubleshooting
GitHub stars
405
Token cost
~4.9k tokens
SKILL.md length
1,683 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

  • The user reports a security error
  • SKILL.md covers Jobs to Be Done, Prerequisites, Diagnostic Workflow and Diagnostic Toolkit, plus 7 more sections
  • Calls curl and openssl
  • Tasks that involve Search implementation

What it does

Elasticsearch Security Troubleshooting is an agent skill from aspectrr/deer. Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.

Its SKILL.md is about 4.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Search implementation. It works with Elasticsearch. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.

When your agent uses it

  • The user reports a security error
  • Tasks that involve Search implementation

Example prompts

  • “/elasticsearch-security-troubleshooting”

What it can do on your machine

Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • openssl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Elasticsearch Security Troubleshooting loads about 4.9k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 1,683 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 1,683 words, ~4,908 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch-security-troubleshooting/SKILL.md (or your agent's skills folder).
name
elasticsearch-security-troubleshooting
description
Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.
metadata.author
elastic
metadata.version
0.1.0
metadata.source
elastic/agent-skills//skills/elasticsearch/elasticsearch-security-troubleshooting

Elasticsearch Security Troubleshooting

Diagnose and resolve common Elasticsearch security issues. This skill provides a structured triage workflow for authentication failures, authorization errors, TLS problems, API key issues, role mapping mismatches, Kibana login failures, and license-expiry lockouts.

For authentication methods and API key management, see the elasticsearch-authn skill. For roles, users, and role mappings, see the elasticsearch-authz skill. For license management, see the elasticsearch-license skill.

For diagnostic API endpoints, see references/api-reference.md.

Deployment note: Diagnostic API availability differs between self-managed, ECH, and Serverless. See Deployment Compatibility for details.

Jobs to Be Done

  • Diagnose HTTP 401 authentication failures
  • Diagnose HTTP 403 permission denied errors
  • Troubleshoot TLS/SSL handshake or certificate errors
  • Investigate expired or invalid API keys
  • Debug role mappings that do not grant expected roles
  • Fix Kibana login failures, redirect loops, or CORS errors
  • Recover from a license-expiry lockout
  • Determine why a user lacks access to a specific index

Prerequisites

ItemDescription
Elasticsearch URLCluster endpoint (e.g. https://localhost:9200 or a Cloud deployment URL)
AuthenticationAny valid credentials — even minimal — to reach the cluster
Cluster privilegesmonitor for read-only diagnostics; manage_security for fixes

Prompt the user for any missing values. If the user cannot authenticate at all, start with TLS and Certificate Errors or License Expiry Recovery.

Diagnostic Workflow

Route the symptom to the correct section:

SymptomSection
HTTP 401, authentication_exceptionAuthentication Failures
HTTP 403, security_exception, access deniedAuthorization Failures
SSL/TLS handshake error, certificate rejectedTLS and Certificate Errors
API key rejected, expired, or ineffectiveAPI Key Issues
Role mapping not granting expected rolesRole Mapping Issues
Kibana login broken, redirect loop, CORS errorKibana Authentication Issues
All users locked out, paid features disabledLicense Expiry Recovery

Each section follows a Gather - Diagnose - Resolve pattern.

Diagnostic Toolkit

Use these APIs at the start of any security investigation:

bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_security/_authenticate"

Confirms identity, realm, and roles. If this fails with 401, the problem is authentication.

bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_xpack"

Confirms whether security is enabled (features.security.enabled). If security is disabled, all security APIs return errors.

bash
curl -X POST "${ELASTICSEARCH_URL}/_security/user/_has_privileges" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "index": [
      { "names": ["'"${INDEX_PATTERN}"'"], "privileges": ["read"] }
    ]
  }'

Tests whether the authenticated user holds specific privileges without requiring manage_security.

bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_license"

Check license type and status. An expired paid license disables paid realms and features.

Authentication Failures (401)

A 401 response means Elasticsearch could not verify the caller's identity.

Gather
bash
curl -v <auth_flags> "${ELASTICSEARCH_URL}/_security/_authenticate" 2>&1

The -v flag shows headers and the response body. Look for:

  • WWW-Authenticate header — indicates which auth schemes the cluster accepts.
  • authentication_exception in the response body — the reason field describes what failed.
Diagnose
SymptomLikely cause
unable to authenticate userWrong username or password
unable to authenticate with provided credentialsCredentials do not match any realm in the chain
user is not enabledThe native user account is disabled
token is expiredAPI key or bearer token has expired
No WWW-Authenticate headerSecurity may be disabled; check GET /_xpack

If the user authenticates via an external realm (LDAP, AD, SAML, OIDC), the realm chain order matters. Elasticsearch tries realms in configured order and stops at the first match. If a higher-priority realm rejects the credentials before the intended realm is reached, authentication fails.

Resolve
CauseAction
Wrong credentialsVerify username/password or API key value. See elasticsearch-authn.
Disabled userPUT /_security/user/{name}/_enable. See elasticsearch-authz.
Expired API keyCreate a new API key. See API Key Issues.
Realm chain orderCheck elasticsearch.yml realm order (self-managed only).
Security disabledEnable xpack.security.enabled: true in elasticsearch.yml and restart.
Paid realm after expiryLicense expired — see License Expiry Recovery.

Authorization Failures (403)

A 403 response means the user is authenticated but lacks the required privileges.

Gather

Test the specific privileges the operation requires:

bash
curl -X POST "${ELASTICSEARCH_URL}/_security/user/_has_privileges" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "index": [
      { "names": ["logs-*"], "privileges": ["read", "view_index_metadata"] }
    ],
    "cluster": ["monitor"]
  }'

The response contains a has_all_requested boolean and per-resource breakdowns.

Also check the user's effective roles:

bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_security/_authenticate"

Inspect the roles array and authentication_realm to confirm the user is who you expect.

Diagnose
SymptomLikely cause
has_all_requested: false for an indexRole is missing the required index privilege
has_all_requested: false for a clusterRole is missing the required cluster privilege
User has fewer roles than expectedRoles array was replaced (not merged) on last update
API key returns 403 on previously allowedAPI key privileges are a snapshot — role changes after
operationcreation do not propagate to existing keys
Resolve
CauseAction
Missing index privilegeAdd the privilege to the role or create a new role. See elasticsearch-authz.
Missing cluster privilegeAdd the cluster privilege. See elasticsearch-authz.
Roles replaced on updateFetch current roles first, then update with the full array. See elasticsearch-authz.
Stale API key privilegesCreate a new API key with updated role_descriptors. See elasticsearch-authn.

TLS and Certificate Errors

TLS errors prevent the client from establishing a connection at all.

Gather
bash
curl -v --cacert "${CA_CERT}" "https://${ELASTICSEARCH_HOST}:9200/" 2>&1 | head -30

Look for:

  • SSL certificate problem: unable to get local issuer certificate — CA not trusted.
  • SSL certificate problem: certificate has expired — certificate past its validity date.
  • SSL: no alternative certificate subject name matches target host name — hostname mismatch.

For deeper inspection (self-managed only):

bash
openssl s_client -connect "${ELASTICSEARCH_HOST}:9200" -showcerts </dev/null 2>&1

This displays the full certificate chain, expiry dates, and subject alternative names.

Diagnose
Error messageLikely cause
unable to get local issuer certificateMissing or wrong CA certificate
certificate has expiredServer or CA certificate past expiry
no alternative certificate subject name matchesCertificate SAN does not include the hostname
self-signed certificateSelf-signed cert not in the trust store
SSLHandshakeException (Java client)Truststore missing the CA or wrong password
Resolve
CauseAction
Wrong CA certPass the correct CA with --cacert or add it to the system trust store.
Expired certificateRegenerate certificates with elasticsearch-certutil (self-managed).
Hostname mismatchRegenerate the certificate with the correct SAN entries.
Self-signed certDistribute the CA cert to all clients or use a publicly trusted CA.
Quick workaroundUse curl -k / --insecure to skip verification. Not for production.

On ECH, TLS is managed by Elastic — certificate errors usually indicate the client is not using the correct Cloud endpoint URL. On Serverless, TLS is fully managed and transparent.

API Key Issues

Gather

Retrieve the key's metadata:

bash
curl "${ELASTICSEARCH_URL}/_security/api_key?name=${KEY_NAME}" <auth_flags>

Check expiration, invalidated, and role_descriptors in the response.

Diagnose
SymptomLikely cause
401 when using the keyKey expired or invalidated
403 on operations that should be allowedKey was created with insufficient role_descriptors
Derived key has no accessAPI key created another API key — derived keys have no privilege
Key works for some indices but not othersrole_descriptors scope is too narrow
Show full SKILL.md (661 more words)Show less
Resolve
CauseAction
Expired keyCreate a new key with appropriate expiration. See elasticsearch-authn.
Invalidated keyCreate a new key. Invalidated keys cannot be reinstated.
Wrong scopeCreate a new key with correct role_descriptors. See elasticsearch-authn.
Derived key problemUse POST /_security/api_key/grant with user credentials instead. See elasticsearch-authn.

Role Mapping Issues

Role mappings grant roles to users from external realms. When they fail silently, users authenticate but get no roles.

Gather
bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_security/_authenticate"

Note the username, authentication_realm.name, and roles array.

bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_security/role_mapping"

List all mappings and inspect their rules and enabled fields.

Diagnose
SymptomLikely cause
User has empty roles arrayNo mapping matches the user's attributes
User gets wrong rolesA different mapping matched first or the rule is too broad
Mapping exists but does not applyenabled is false
Mustache template produces wrong role nameTemplate syntax error or unexpected attribute value

Compare the user's authentication_realm.name and groups (from _authenticate) against each mapping's rules to find the mismatch.

Resolve
CauseAction
No matching ruleUpdate the mapping rules to match the user's realm and attributes.
Mapping disabledSet "enabled": true on the mapping.
Template errorTest the Mustache template with known attribute values. See elasticsearch-authz.
Rule too broadAdd all / except conditions to narrow the match. See elasticsearch-authz.

Kibana Authentication Issues

Missing kbn-xsrf header

All mutating Kibana API requests require the kbn-xsrf header:

bash
curl -X PUT "${KIBANA_URL}/api/security/role/my-role" \
  <auth_flags> \
  -H "kbn-xsrf: true" \
  -H "Content-Type: application/json" \
  -d '{ ... }'

Without it, Kibana returns 400 Bad Request with "Request must contain a kbn-xsrf header".

SAML/OIDC redirect loop

Common causes:

  • Incorrect xpack.security.authc.realms.saml.*.sp.acs or idp.metadata.path in elasticsearch.yml.
  • Clock skew between the IdP and Elasticsearch nodes (SAML assertions have a validity window).
  • Kibana server.publicBaseUrl does not match the SAML ACS URL.

Verify the SAML realm configuration:

bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_security/_authenticate"

If this returns a valid user via a non-SAML realm, the SAML realm itself is not being reached. Check realm chain order.

Kibana cannot reach Elasticsearch

Kibana logs Unable to retrieve version information from Elasticsearch nodes. Verify the elasticsearch.hosts setting in kibana.yml points to a reachable endpoint and the credentials (elasticsearch.username / elasticsearch.password or elasticsearch.serviceAccountToken) are valid.

License Expiry Recovery

When a paid license expires, the cluster enters a security-closed state: paid realms (SAML, LDAP, AD, PKI) stop working and users authenticating through them are locked out. Native and file realms remain functional.

Quick triage
bash
curl <auth_flags> "${ELASTICSEARCH_URL}/_license"

If license.status is "expired", proceed with recovery.

Recovery steps

Follow the detailed recovery workflow in the elasticsearch-license skill. The critical first step depends on deployment type:

DeploymentFirst step
Self-managedLog in with a file-based user (elasticsearch-users CLI) or native user.
ECHContact Elastic support or renew via the Cloud console.
ServerlessNot applicable — licensing is fully managed by Elastic.

Deployment Compatibility

Diagnostic tool and API availability differs across deployment types.

Tool / APISelf-managedECHServerless
_security/_authenticateYesYesYes
_security/user/_has_privilegesYesYesYes
_xpackYesYesLimited
_licenseYesYes (read)Not available
_security/api_key (GET)YesYesYes
_security/role_mappingYesYesYes
elasticsearch-users CLIYesNot availableNot available
openssl s_client on nodesYesNot availableNot available
Elasticsearch logsYesVia Cloud UIVia Cloud UI

Guidelines

Always start with _authenticate

Run GET /_security/_authenticate as the first diagnostic step. It reveals the user's identity, realm, roles, and authentication type in a single call. Most issues become apparent from this response alone.

Check the license early

Before investigating realm or privilege issues, verify the license is active with GET /_license. An expired paid license disables realms and features, producing symptoms that mimic misconfiguration.

Use _has_privileges before manual inspection

Instead of reading role definitions and mentally computing effective access, use POST /_security/user/_has_privileges to test specific privileges directly. This is faster and accounts for role composition, DLS, and FLS.

Avoid superuser credentials

Never use the built-in elastic superuser for day-to-day troubleshooting. Create a dedicated admin user or API key with manage_security privileges. Reserve the elastic user for initial setup and emergency recovery only.

Do not bypass TLS in production

Using curl -k or --insecure skips certificate verification and masks real TLS issues. Use it only for initial diagnosis, then fix the underlying certificate problem.

© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in deer-cli/internal/skill/defaults/elasticsearch-security-troubleshooting of aspectrr/deer.

Open the folder on GitHubat commit e4f9845

Compare with similar skills

Elasticsearch Security Troubleshooting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch Security Troubleshooting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch Security Troubleshooting this skillaspectrr/deer405—~4.9kAutomated safety check: PassMIT
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Foundatio Repositoriesexceptionless/Exceptionless2.5k—~1.9kAutomated safety check: PassApache-2.0
Elasticsearch File IngestKilo-Org/kilo-marketplace190—~2.8kAutomated safety check: PassApache-2.0
Elasticsearcholasunkanmi-SE/codebuddy141—~425Automated safety check: PassMIT
Elasticsearch Index Designelastic/agent-skills592—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Elasticsearch

    olasunkanmi-SE/codebuddy

    Interact with Elasticsearch clusters via the API. An agent skill from olasunkanmi-SE/codebuddy.

    141 GitHub stars~425 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Elasticsearch Index Design

    elastic/agent-skills

    Official

    Design and review Elasticsearch index mappings for stated access patterns: correct field types, text+keyword multi-fields, docvalues tuning, mapping-explosion avoidance, and explicit shard settings.

    592 GitHub stars~3.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Vss Setup Video Analytics API

    NVIDIA-AI-Blueprints/video-search-and-summarization

    A skill your agent uses to deploy the vss-video-analytics-api REST service standalone with its Elasticsearch ingest-pipeline, selectable Kafka/Redis stream type, and Kafka-topic readiness gates when…

    1.9k GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check: notes

More from aspectrr/deer

All 14 skills in this repo
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Auto-check passed
  • Kafka

    aspectrr/deer

    Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.

    405 GitHub stars~946 tokensUpdated 5 mo ago
    Auto-check passed
  • Create and manage Kibana alerting rules via REST API or Terraform.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed

Works with

Categories

Questions about Elasticsearch Security Troubleshooting

What does Elasticsearch Security Troubleshooting do?

Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Elasticsearch Security Troubleshooting is an agent skill from aspectrr/deer. Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

When should I use Elasticsearch Security Troubleshooting?

Elasticsearch Security Troubleshooting fits situations like: the user reports a security error; tasks that involve Search implementation.

How do I install Elasticsearch Security Troubleshooting in Claude Code?

Run `npx skills add aspectrr/deer --skill elasticsearch-security-troubleshooting -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/elasticsearch-security-troubleshooting in aspectrr/deer) into .claude/skills/elasticsearch-security-troubleshooting in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch Security Troubleshooting in Codex?

Run `npx skills add aspectrr/deer --skill elasticsearch-security-troubleshooting -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/elasticsearch-security-troubleshooting in aspectrr/deer) into .agents/skills/elasticsearch-security-troubleshooting in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch Security Troubleshooting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill elasticsearch-security-troubleshooting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-security-troubleshooting, .gemini/skills/elasticsearch-security-troubleshooting, .github/skills/elasticsearch-security-troubleshooting and .opencode/skills/elasticsearch-security-troubleshooting in your project.

What does Elasticsearch Security Troubleshooting need to run?

Going by SKILL.md and its folder, Elasticsearch Security Troubleshooting needs the command-line tools its instructions call (curl and openssl).

Does Elasticsearch Security Troubleshooting access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Elasticsearch Security Troubleshooting safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch Security Troubleshooting use?

Elasticsearch Security Troubleshooting is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch Security Troubleshooting use?

About 4.9k tokens (SKILL.md is roughly 20k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Elasticsearch Security Troubleshooting?

Skills that share tags, products or a category with Elasticsearch Security Troubleshooting: Product Full-Text Search (lobehub/lobehub, 83k stars), Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars) and Elasticsearch (olasunkanmi-SE/codebuddy, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch Security Troubleshooting?

aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.

Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.