Agent skill

Kibana Audit

by aspectrr in aspectrr/deer

Enable and configure Kibana audit logging for saved object access, logins, and space operations.

MITAuto-check passedBackend & APIs

Install Kibana Audit

skills CLI
$ npx skills add aspectrr/deer --skill kibana-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aspectrr/deer kibana-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/kibana-audit .claude/skills/kibana-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kibana-audit
GitHub stars
405
Token cost
~848 tokens
SKILL.md length
185 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Enable and configure Kibana audit logging for saved object access, logins, and space operations.

  • Setting up Kibana audit
  • SKILL.md covers Enable Kibana Audit Logging, Event Types, Filter Policies and Correlate with ES Audit Logs, plus 3 more sections
  • Calls curl
  • Filtering events

What it does

Kibana Audit is an agent skill from aspectrr/deer. Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.

Its SKILL.md is about 850 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Search implementation. It works with Elasticsearch. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.

When your agent uses it

  • Setting up Kibana audit
  • Filtering events
  • Correlating Kibana and ES audit logs

Example prompts

  • “/kibana-audit”

What it can do on your machine

Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kibana Audit loads about 848 tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 185 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~848

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 185 words, ~848 tokens.

Download SKILL.mdSave it as .claude/skills/kibana-audit/SKILL.md (or your agent's skills folder).
name
kibana-audit
description
Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.
metadata.author
elastic
metadata.version
0.1.0
metadata.source
elastic/agent-skills//skills/kibana/kibana-audit

Kibana Audit Logging

Enable and configure audit logging for Kibana via kibana.yml. Covers application-layer security events: saved object CRUD, login/logout, session expiry, and space operations.

Enable Kibana Audit Logging

yaml
xpack.security.audit.enabled: true
xpack.security.audit.appender:
  type: rolling-file
  fileName: /path/to/kibana/data/audit.log
  policy:
    type: time-interval
    interval: 24h
  strategy:
    type: numeric
    max: 10

A Kibana restart is required after changes.

Event Types

Event actionDescription
saved_object_createA saved object was created
saved_object_getA saved object was read
saved_object_updateA saved object was updated
saved_object_deleteA saved object was deleted
saved_object_findA saved object search was performed
loginA user logged in (success or failure)
logoutA user logged out
session_cleanupAn expired session was cleaned up
space_create/update/deleteSpace operations

Filter Policies

yaml
xpack.security.audit.ignore_filters:
  - actions: [saved_object_find]
    categories: [database]

Correlate with ES Audit Logs

Both Kibana and ES record the same trace.id (via X-Opaque-Id header). This is the primary correlation key.

Search ES audit by trace ID
bash
curl -X POST "${ELASTICSEARCH_URL}/.security-audit-*/_search" \
  <auth_flags> \
  -H "Content-Type: application/json" \
  -d '{
    "query": {
      "bool": {
        "filter": [
          { "term": { "trace.id": "'"${TRACE_ID}"'" } },
          { "range": { "@timestamp": { "gte": "now-24h" } } }
        ]
      }
    },
    "sort": [{ "@timestamp": { "order": "asc" } }]
  }'

Ship Kibana Audit to Elasticsearch

yaml
filebeat.inputs:
  - type: log
    paths: ["/path/to/kibana/data/audit.log"]
    json.keys_under_root: true

output.elasticsearch:
  hosts: ["https://localhost:9200"]
  index: "kibana-audit-%{+yyyy.MM.dd}"

Deployment Compatibility

CapabilitySelf-managedECHServerless
Kibana auditYesVia Cloud UINot available
Correlate via trace.idYesYesNot available

Guidelines

  • Always enable alongside Elasticsearch audit for full coverage.
  • Use trace.id for correlation between Kibana and ES events.
  • Filter noisy saved_object_find events to reduce volume.
  • Ship logs to Elasticsearch via Filebeat for unified querying.

© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in deer-cli/internal/skill/defaults/kibana-audit of aspectrr/deer.

Open the folder on GitHubat commit e4f9845

Compare with similar skills

Kibana Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kibana Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kibana Audit this skillaspectrr/deer405—~848Automated safety check: PassMIT
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Foundatio Repositoriesexceptionless/Exceptionless2.5k—~1.9kAutomated safety check: PassApache-2.0
Elasticsearch File IngestKilo-Org/kilo-marketplace190—~2.8kAutomated safety check: PassApache-2.0
Elasticsearcholasunkanmi-SE/codebuddy141—~425Automated safety check: PassMIT
Elasticsearch Index Designelastic/agent-skills592—~3.1kAutomated safety check: PassApache-2.0

Similar skills

  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Elasticsearch

    olasunkanmi-SE/codebuddy

    Interact with Elasticsearch clusters via the API. An agent skill from olasunkanmi-SE/codebuddy.

    141 GitHub stars~425 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Elasticsearch Index Design

    elastic/agent-skills

    Official

    Design and review Elasticsearch index mappings for stated access patterns: correct field types, text+keyword multi-fields, docvalues tuning, mapping-explosion avoidance, and explicit shard settings.

    592 GitHub stars~3.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Vss Setup Video Analytics API

    NVIDIA-AI-Blueprints/video-search-and-summarization

    A skill your agent uses to deploy the vss-video-analytics-api REST service standalone with its Elasticsearch ingest-pipeline, selectable Kafka/Redis stream type, and Kafka-topic readiness gates when…

    1.9k GitHub stars~2.6k tokensUpdated today
    Backend & APIsAuto-check: notes

More from aspectrr/deer

All 14 skills in this repo
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Auto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Kafka

    aspectrr/deer

    Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.

    405 GitHub stars~946 tokensUpdated 5 mo ago
    Auto-check passed

Works with

Categories

Questions about Kibana Audit

What does Kibana Audit do?

Enable and configure Kibana audit logging for saved object access, logins, and space operations. Kibana Audit is an agent skill from aspectrr/deer. Enable and configure Kibana audit logging for saved object access, logins, and space operations.

When should I use Kibana Audit?

Kibana Audit fits situations like: setting up Kibana audit; filtering events; correlating Kibana and ES audit logs.

How do I install Kibana Audit in Claude Code?

Run `npx skills add aspectrr/deer --skill kibana-audit -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/kibana-audit in aspectrr/deer) into .claude/skills/kibana-audit in your project. Claude Code loads it when a task matches its description.

How do I install Kibana Audit in Codex?

Run `npx skills add aspectrr/deer --skill kibana-audit -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/kibana-audit in aspectrr/deer) into .agents/skills/kibana-audit in your project. Codex loads it when a task matches its description.

Can I use Kibana Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill kibana-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-audit, .gemini/skills/kibana-audit, .github/skills/kibana-audit and .opencode/skills/kibana-audit in your project.

What does Kibana Audit need to run?

Going by SKILL.md and its folder, Kibana Audit needs the command-line tools its instructions call (curl).

Does Kibana Audit access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Kibana Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kibana Audit use?

Kibana Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kibana Audit use?

About 848 tokens (SKILL.md is roughly 3.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kibana Audit?

Skills that share tags, products or a category with Kibana Audit: Product Full-Text Search (lobehub/lobehub, 83k stars), Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars) and Elasticsearch (olasunkanmi-SE/codebuddy, 141 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kibana Audit?

aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.

Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.