Agent skill

Kibana Connectors

by aspectrr in aspectrr/deer

Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.

MITAuto-check passedBackend & APIs

Install Kibana Connectors

skills CLI
$ npx skills add aspectrr/deer --skill kibana-connectors -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aspectrr/deer kibana-connectors --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aspectrr/deer.git skills-src && mkdir -p .claude/skills && cp -r skills-src/deer-cli/internal/skill/defaults/kibana-connectors .claude/skills/kibana-connectors && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kibana-connectors
GitHub stars
405
Token cost
~2k tokens
SKILL.md length
448 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.

  • Works in 7 steps: Use preconfigured connectors for… → Test connectors before attaching to… → Check referenced_by_count before deleting. → …
  • Configuring third-party integrations
  • SKILL.md covers Core Concepts, Authentication, API Reference and Creating a Connector, plus 7 more sections
  • Calls curl; reaches hooks.slack.com and events.pagerduty.com

What it does

Kibana Connectors is an agent skill from aspectrr/deer. Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Use when configuring third-party integrations or managing connectors as code.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Webhooks, Monitoring and alerting and Infrastructure as code. It works with Elasticsearch, PagerDuty, Slack and Terraform. The repository describes itself as: 🦌 The AI Elasticsearch Engineer. The licence is MIT.

When your agent uses it

  • Configuring third-party integrations
  • Managing connectors as code

Example prompts

  • “/kibana-connectors”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Use preconfigured connectors for production on-prem. They eliminate secret sprawl.
  2. Test connectors before attaching to rules. Use the _execute endpoint.
  3. Check referenced_by_count before deleting.
  4. One connector per service, not per rule. Create a single Slack connector and reference it from multiple rules.
  5. Use Spaces for multi-tenant isolation.
  6. Always configure a recovery action alongside the active action.
  7. Use deduplication keys for on-call connectors. Set dedupKey to {{rule.id}}-{{alert.id}}.

What it can do on your machine

Read from SKILL.md and the folder at commit e4f9845. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • hooks.slack.com
    • events.pagerduty.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kibana Connectors loads about 2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 448 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aspectrr/deer at commit e4f9845, republished under its MIT licence (© aspectrr). 448 words, ~2,018 tokens.

Download SKILL.mdSave it as .claude/skills/kibana-connectors/SKILL.md (or your agent's skills folder).
name
kibana-connectors
description
Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Use when configuring third-party integrations or managing connectors as code.
metadata.author
elastic
metadata.version
0.1.1
metadata.source
elastic/agent-skills//skills/kibana/kibana-connectors

Kibana Connectors

Core Concepts

Connectors store connection information for Elastic services and third-party systems. Alerting rules use connectors to route actions (notifications) when rule conditions are met. Connectors are managed per Kibana Space.

Connector Categories
CategoryConnector Types
LLM ProvidersOpenAI, Google Gemini, Amazon Bedrock, Elastic Managed LLMs, AI Connector, MCP (Preview, 9.3+)
Incident ManagementPagerDuty, Opsgenie, ServiceNow (ITSM, SecOps, ITOM), Jira, Jira Service Management (9.2+), IBM Resilient, Swimlane, Torq, Tines, D3 Security, XSOAR (9.1+), TheHive
Endpoint SecurityCrowdStrike, SentinelOne, Microsoft Defender for Endpoint
MessagingSlack (API / Webhook), Microsoft Teams, Email
Logging & ObservabilityServer log, Index, Observability AI Assistant
WebhookWebhook, Webhook - Case Management, xMatters
ElasticCases

Authentication

All connector API calls require API key auth or Basic auth. Every mutating request must include the kbn-xsrf header.

http
kbn-xsrf: true

API Reference

Base path: <kibana_url>/api/actions (or /s/<space_id>/api/actions for non-default spaces).

OperationMethodEndpoint
Create connectorPOST/api/actions/connector/{id}
Update connectorPUT/api/actions/connector/{id}
Get connectorGET/api/actions/connector/{id}
Delete connectorDELETE/api/actions/connector/{id}
Get all connectorsGET/api/actions/connectors
Get connector typesGET/api/actions/connector_types
Run connectorPOST/api/actions/connector/{id}/_execute

Creating a Connector

Example: Create a Slack Connector (Webhook)
bash
curl -X POST "https://my-kibana:5601/api/actions/connector/my-slack-connector" \
  -H "kbn-xsrf: true" \
  -H "Content-Type: application/json" \
  -H "Authorization: ApiKey <your-api-key>" \
  -d '{
    "name": "Production Slack Alerts",
    "connector_type_id": ".slack",
    "config": {},
    "secrets": {
      "webhookUrl": "https://hooks.slack.com/services/T00/B00/XXXX"
    }
  }'
Example: Create a PagerDuty Connector
bash
curl -X POST "https://my-kibana:5601/api/actions/connector/my-pagerduty" \
  -H "kbn-xsrf: true" \
  -H "Content-Type: application/json" \
  -H "Authorization: ApiKey <your-api-key>" \
  -d '{
    "name": "PagerDuty Incidents",
    "connector_type_id": ".pagerduty",
    "config": {
      "apiUrl": "https://events.pagerduty.com/v2/enqueue"
    },
    "secrets": {
      "routingKey": "your-pagerduty-integration-key"
    }
  }'

Listing Connectors

bash
curl -X GET "https://my-kibana:5601/api/actions/connectors" \
  -H "Authorization: ApiKey <your-api-key>"

The response includes referenced_by_count showing how many rules use each connector. Always check this before deleting.

Running a Connector (Test)

bash
curl -X POST "https://my-kibana:5601/api/actions/connector/my-slack-connector/_execute" \
  -H "kbn-xsrf: true" \
  -H "Content-Type: application/json" \
  -H "Authorization: ApiKey <your-api-key>" \
  -d '{
    "params": {
      "message": "Test alert from API"
    }
  }'

Terraform Provider

hcl
resource "elasticstack_kibana_action_connector" "slack" {
  name              = "Production Slack Alerts"
  connector_type_id = ".slack"

  config = jsonencode({})

  secrets = jsonencode({
    webhookUrl = "https://hooks.slack.com/services/T00/B00/XXXX"
  })
}

Common Connector Type IDs

Type IDNameLicense
.emailEmailGold
.slackSlack (Webhook)Gold
.slack_apiSlack (API)Gold
.pagerdutyPagerDutyGold
.jiraJiraGold
.servicenowServiceNow ITSMPlatinum
.webhookWebhookGold
.indexIndexBasic
.server-logServer logBasic
.opsgenieOpsgenieGold
.teamsMicrosoft TeamsGold
.gen-aiOpenAIEnterprise
.bedrockAmazon BedrockEnterprise
.geminiGoogle GeminiEnterprise
.casesCasesPlatinum
Show full SKILL.md (180 more words)Show less

Best Practices

  1. Use preconfigured connectors for production on-prem. They eliminate secret sprawl.
  2. Test connectors before attaching to rules. Use the _execute endpoint.
  3. Check referenced_by_count before deleting.
  4. One connector per service, not per rule. Create a single Slack connector and reference it from multiple rules.
  5. Use Spaces for multi-tenant isolation.
  6. Always configure a recovery action alongside the active action.
  7. Use deduplication keys for on-call connectors. Set dedupKey to {{rule.id}}-{{alert.id}}.

Common Pitfalls

  1. Missing kbn-xsrf header. Returns 400.
  2. Wrong connector_type_id. Must include leading dot (e.g., .slack).
  3. Empty secrets object required. Even for connectors without secrets, pass "secrets": {}.
  4. Connector type is immutable. Delete and recreate to change it.
  5. Secrets lost on export/import. Must re-enter secrets manually after import.

Guidelines

  • Include kbn-xsrf: true on every POST, PUT, and DELETE.
  • connector_type_id is immutable — delete and recreate to change connector type.
  • Always pass "secrets": {} even for connectors with no secrets.
  • Check referenced_by_count before deleting.
  • Connectors are space-scoped; prefix paths with /s/<space_id>/api/actions/ for non-default Kibana Spaces.
  • Test every new connector with _execute before attaching to rules.

© aspectrr, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in deer-cli/internal/skill/defaults/kibana-connectors of aspectrr/deer.

Open the folder on GitHubat commit e4f9845

Compare with similar skills

Kibana Connectors next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kibana Connectors compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kibana Connectors this skillaspectrr/deer405—~2kAutomated safety check: PassMIT
Supercheck Monitoring Alertssupercheck-io/supercheck215—~855Automated safety check: PassAGPL-3.0
Tool ConnectorZhixiangLuo/10xProductivity479—~925Automated safety check: PassMIT
Google Cloud Storage Bucket Architectgoogle/skills21k—~2.6kAutomated safety check: PassApache-2.0
Oncall Irmgrafana/skills282—~1.4kAutomated safety check: PassApache-2.0
Sentry Alert TunerLeoYeAI/openclaw-master-skills2.2k—~7.3kAutomated safety check: PassMIT

Similar skills

  • Supercheck Monitoring Alerts

    supercheck-io/supercheck

    Work on Supercheck HTTP, ping, or DNS monitors, regional scheduling and aggregation, alert state/history, incidents, or email, Slack, PagerDuty, and webhook notifications.

    215 GitHub stars~855 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Tool Connector

    ZhixiangLuo/10xProductivity

    Connect any tool you use at work to your agent — including internal company tools, custom-built systems, deployment portals, incident trackers, internal knowledge bases, HR systems, and commercial…

    479 GitHub stars~925 tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Creates Cloud Storage on Google Cloud (also known colloquially as GCS) buckets.

    21k GitHub stars~2.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Oncall Irm

    grafana/skills

    Official

    Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates…

    282 GitHub stars~1.4k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Sentry Alert Tuner

    LeoYeAI/openclaw-master-skills

    Reduce Sentry alert fatigue by surgically tuning issue grouping, fingerprint rules, severity mapping, sample rates, before-send filters, sourcemap pipelines, and release-health gates.

    2.2k GitHub stars~7.3k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Workspace API

    friday-platform/friday-studio

    Create, list, update, delete, and clean up workspaces via the daemon HTTP API at $FRIDAYDURL.

    104 GitHub stars~9.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes

More from aspectrr/deer

All 14 skills in this repo
  • Elasticsearch Audit

    aspectrr/deer

    Enable, configure, and query Elasticsearch security audit logs.

    405 GitHub stars~1.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Auto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Auto-check passed
  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Auto-check passed
  • Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues.

    405 GitHub stars~4.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Kafka

    aspectrr/deer

    Kafka topic management, consumer group monitoring, message production/consumption, and cluster health diagnostics.

    405 GitHub stars~946 tokensUpdated 5 mo ago
    Auto-check passed

Questions about Kibana Connectors

What does Kibana Connectors do?

Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Kibana Connectors is an agent skill from aspectrr/deer. Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.

When should I use Kibana Connectors?

Kibana Connectors fits situations like: configuring third-party integrations; managing connectors as code.

How do I install Kibana Connectors in Claude Code?

Run `npx skills add aspectrr/deer --skill kibana-connectors -a claude-code`. Or copy the skill folder (deer-cli/internal/skill/defaults/kibana-connectors in aspectrr/deer) into .claude/skills/kibana-connectors in your project. Claude Code loads it when a task matches its description.

How do I install Kibana Connectors in Codex?

Run `npx skills add aspectrr/deer --skill kibana-connectors -a codex`. Or copy the skill folder (deer-cli/internal/skill/defaults/kibana-connectors in aspectrr/deer) into .agents/skills/kibana-connectors in your project. Codex loads it when a task matches its description.

Can I use Kibana Connectors in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aspectrr/deer --skill kibana-connectors -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-connectors, .gemini/skills/kibana-connectors, .github/skills/kibana-connectors and .opencode/skills/kibana-connectors in your project.

What does Kibana Connectors need to run?

Going by SKILL.md and its folder, Kibana Connectors needs the command-line tools its instructions call (curl).

Does Kibana Connectors access the network?

SKILL.md names 2 domains. In commands or code: hooks.slack.com and events.pagerduty.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Kibana Connectors safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kibana Connectors use?

Kibana Connectors is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kibana Connectors use?

About 2k tokens (SKILL.md is roughly 8.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kibana Connectors?

Skills that share tags, products or a category with Kibana Connectors: Supercheck Monitoring Alerts (supercheck-io/supercheck, 215 stars), Tool Connector (ZhixiangLuo/10xProductivity, 479 stars), Google Cloud Storage Bucket Architect (google/skills, 21k stars) and Oncall Irm (grafana/skills, 282 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kibana Connectors?

aspectrr (a GitHub user) maintains it in aspectrr/deer, which has 405 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on April 21, 2026.

Source: aspectrr/deer on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.