Amazon Opensearch Service
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
Create and manage Elastic ML anomaly detection jobs via the API.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection .claude/skills/elasticsearch-anomaly-detection && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "elasticsearch-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection into .claude/skills/elasticsearch-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detectionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection .agents/skills/elasticsearch-anomaly-detection && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "elasticsearch-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection into .agents/skills/elasticsearch-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection .cursor/skills/elasticsearch-anomaly-detection && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "elasticsearch-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection into .cursor/skills/elasticsearch-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/elasticsearch/elasticsearch-anomaly-detection--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection .gemini/skills/elasticsearch-anomaly-detection && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "elasticsearch-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection into .gemini/skills/elasticsearch-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detectionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection .github/skills/elasticsearch-anomaly-detection && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection into .github/skills/elasticsearch-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection .opencode/skills/elasticsearch-anomaly-detection && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-anomaly-detection into .opencode/skills/elasticsearch-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-anomaly-detection", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
elasticsearch-anomaly-detectionCreate and manage Elastic ML anomaly detection jobs via the API.
Elasticsearch Anomaly Detection is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Elastic ML anomaly detection jobs via the API. Use when setting up jobs on an index or data stream, configuring jobs and datafeeds, or opening, starting, or stopping them.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/anomaly-detection-reference.md`). Compatibility notes: Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manageml privilege to create and…
It sits in Data & Analytics, covering Anomaly detection and Search implementation. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are json).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manage_ml privilege to create and manage jobs.
From compatibility in the SKILL.md frontmatter.
Elasticsearch Anomaly Detection loads about 2.4k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 876 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 876 words, ~2,387 tokens.
.claude/skills/elasticsearch-anomaly-detection/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Create, open, and start ML anomaly detection jobs on time-series data. Choose the right count-family detector direction, configure bucket span and time field, wire the datafeed to the correct index, and confirm running state from stats — not from assumptions.
<!-- begin-partial: preamble -->
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
<!-- end-partial: preamble -->
Prerequisite: ML anomaly detection requires a Platinum-equivalent license on self-managed clusters. Serverless projects include ML. The caller needs
manage_mlto create and manage jobs.Related skill: For interpreting anomaly scores, influencers, and model behavior after a job is running, use
elasticsearch-anomaly-detection-explainer— not this skill.
Discover the target index and time field. List candidate indices with GET /_cat/indices (pass a pattern when
the user names one). Fetch field types for the chosen index with GET /{index}/_mapping. The decision: confirm the
index exists, identify the time field (often @timestamp), and verify document volume is sufficient for baseline
learning. Never guess index or field names — they vary across deployments.
Choose detector function and direction. Match the user's intent to a count-family detector in
analysis_config.detectors:
high_count (or count, which flags both directions but is
acceptable when the user cares about spikes). Do not use low_count — it will miss spikes.low_count. Do not use high_count — it will miss drops
and silence.mean, high_mean, low_mean) with
field_name set — only when the user asks about a numeric metric, not raw event volume.The decision: pick one primary detector whose direction matches the anomaly type. For volume spike/drop questions on document counts, stay in the count family — mean detectors are unsuited to "how many events" questions.
Set immutable job shape before creation. These fields cannot change after PUT /_ml/anomaly_detectors/{job_id}:
analysis_config.bucket_span — use the interval the user specifies (e.g. 15m for 15-minute buckets). Match the
granularity of anomalies they care about; too short is noisy, too long is slow to detect.data_description.time_field — the time field from the mapping (commonly @timestamp).analysis_config.detectors — the function and direction from step 2.Example job body for a volume-spike detector:
{
"analysis_config": {
"bucket_span": "15m",
"detectors": [{ "function": "high_count" }]
},
"data_description": { "time_field": "@timestamp" }
}Example for an outage / drop detector:
{
"analysis_config": {
"bucket_span": "15m",
"detectors": [{ "function": "low_count" }]
},
"data_description": { "time_field": "@timestamp" }
}Create the job. Call PUT /_ml/anomaly_detectors/{job_id} with the job id the user requested (or a descriptive
id you propose). The job starts in closed state — creating it does not start analysis.
Create the datafeed. Call PUT /_ml/datafeeds/datafeed-{job_id} immediately after job creation. Set job_id to
the same id, indices to the target index (exact name or pattern from step 1), and a query that selects the relevant
documents (typically match_all). The datafeed id convention is datafeed-{job_id}.
{
"job_id": "{job_id}",
"indices": ["{index}"],
"query": { "match_all": {} }
}Open the job, then start the datafeed — in that order. This sequence is mandatory; do not skip or reorder:
POST /_ml/anomaly_detectors/{job_id}/_open — transitions the job to opened.POST /_ml/datafeeds/datafeed-{job_id}/_start — transitions the datafeed to started.Opening before the datafeed exists fails. Starting the datafeed before opening the job fails. Do not report success after only creating resources — the job is not running until both are active.
Confirm running state from stats. Verify the outcome with:
GET /_ml/anomaly_detectors/{job_id}/_stats — expect state: "opened".GET /_ml/datafeeds/datafeed-{job_id}/_stats — expect state: "started".Optionally call GET /_ml/anomaly_detectors/{job_id} to confirm configuration (detectors, bucket_span,
time_field, datafeed indices). Report both stats states explicitly — "created" is not the same as "opened" and
"started".
When stopping or deleting a job, reverse the startup order:
POST /_ml/datafeeds/datafeed-{job_id}/_stop — stop the datafeed first.POST /_ml/anomaly_detectors/{job_id}/_close — then close the job.Stop the datafeed before closing the job. Close the job before resetting or deleting it.
bucket_span, detectors, time_field) require delete-and-recreate if wrong — validate mapping
and intent before the first PUT.indices at the exact index or pattern they named — not a
nearby guess.by_field_name, over_field_name, partition_field_name) and advanced tuning live in
references/anomaly-detection-reference.md.For API paths, request/response fields, score semantics, and field interactions, read references/anomaly-detection-reference.md.
| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET /_cat/indices | elastic es cat indices --index '<pattern>' |
GET /{index}/_mapping | elastic es indices get-mapping --index '<index>' |
PUT /_ml/anomaly_detectors/{job_id} | elastic es ml put-job --job-id '<job_id>' --analysis-config '<json>' --data-description '<json>' |
PUT /_ml/datafeeds/datafeed-{job_id} | elastic es ml put-datafeed --datafeed-id 'datafeed-<job_id>' --job-id '<job_id>' --indices '<index>' --query '<json>' |
POST /_ml/anomaly_detectors/{job_id}/_open | elastic es ml open-job --job-id '<job_id>' |
POST /_ml/datafeeds/datafeed-{job_id}/_start | elastic es ml start-datafeed --datafeed-id 'datafeed-<job_id>' |
GET /_ml/anomaly_detectors/{job_id} | elastic es ml get-jobs --job-id '<job_id>' |
GET /_ml/anomaly_detectors/{job_id}/_stats | elastic es ml get-job-stats --job-id '<job_id>' |
GET /_ml/datafeeds/datafeed-{job_id}/_stats | elastic es ml get-datafeed-stats --datafeed-id 'datafeed-<job_id>' |
POST /_ml/datafeeds/datafeed-{job_id}/_stop | elastic es ml stop-datafeed --datafeed-id 'datafeed-<job_id>' |
POST /_ml/anomaly_detectors/{job_id}/_close | elastic es ml close-job --job-id '<job_id>' |
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/elasticsearch/elasticsearch-anomaly-detection of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Elasticsearch Anomaly Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Elasticsearch Anomaly Detection this skillelastic/agent-skills | 592 | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Amazon Opensearch Serviceaws/agent-toolkit-for-aws | 2.8k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch File IngestKilo-Org/kilo-marketplace | 190 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| TimesFM Forecastinggoogle-research/timesfm | 34k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Anomalib Adding A Modelopen-edge-platform/anomalib | 6.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Product Full-Text Searchlobehub/lobehub | 83k | — | ~4.1k | Automated safety check: Pass | Custom licence |
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
Kilo-Org/kilo-marketplace
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
google-research/timesfm
Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.
open-edge-platform/anomalib
Adds a new anomaly-detection model to anomalib under src/anomalib/models/.
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
open-edge-platform/anomalib
Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Create and manage Elastic ML anomaly detection jobs via the API. Elasticsearch Anomaly Detection is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Elastic ML anomaly detection jobs via the API.
Elasticsearch Anomaly Detection fits situations like: setting up jobs on an index; configuring jobs and datafeeds.
Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection in elastic/agent-skills) into .claude/skills/elasticsearch-anomaly-detection in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection in elastic/agent-skills) into .agents/skills/elasticsearch-anomaly-detection in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-anomaly-detection, .gemini/skills/elasticsearch-anomaly-detection, .github/skills/elasticsearch-anomaly-detection and .opencode/skills/elasticsearch-anomaly-detection in your project.
SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Anomaly Detection is instructions for the agent only. Compatibility (from SKILL.md): Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manage_ml privilege to create and manage jobs. .
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Elasticsearch Anomaly Detection is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Elasticsearch Anomaly Detection: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars), TimesFM Forecasting (google-research/timesfm, 34k stars) and Anomalib Adding A Model (open-edge-platform/anomalib, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.