Official agent skill

Elasticsearch Anomaly Detection

by elastic in elastic/agent-skills

Create and manage Elastic ML anomaly detection jobs via the API.

OfficialApache-2.0Auto-check passedData & Analytics

Install Elasticsearch Anomaly Detection

skills CLI
$ npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills elasticsearch-anomaly-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-anomaly-detection .claude/skills/elasticsearch-anomaly-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch-anomaly-detection
GitHub stars
592
Token cost
~2.4k tokens
SKILL.md length
876 words
Files
2 (incl. references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create and manage Elastic ML anomaly detection jobs via the API.

  • Works in 7 steps: Discover the target index and time… → Choose detector function and direction.… → Set immutable job shape before creation.… → …
  • Setting up jobs on an index
  • SKILL.md covers Environment Configuration, Process, Teardown and Guidelines, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Elasticsearch Anomaly Detection is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Elastic ML anomaly detection jobs via the API. Use when setting up jobs on an index or data stream, configuring jobs and datafeeds, or opening, starting, or stopping them.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/anomaly-detection-reference.md`). Compatibility notes: Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manageml privilege to create and…

It sits in Data & Analytics, covering Anomaly detection and Search implementation. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • Setting up jobs on an index
  • Configuring jobs and datafeeds

Example prompts

  • “/elasticsearch-anomaly-detection”

Requirements

  • Compatibility (from SKILL.md): Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manage_ml privilege to create and manage jobs.

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Discover the target index and time field. List candidate indices with GET /_cat/indices (pass a pattern when
  2. Choose detector function and direction. Match the user's intent to a count-family detector in
  3. Set immutable job shape before creation. These fields cannot change after PUT /_ml/anomaly_detectors/{job_id}
  4. Create the job. Call PUT /_ml/anomaly_detectors/{job_id} with the job id the user requested (or a descriptive
  5. Create the datafeed. Call PUT /_ml/datafeeds/datafeed-{job_id} immediately after job creation. Set job_id to
  6. Open the job, then start the datafeed — in that order. This sequence is mandatory; do not skip or reorder
  7. Confirm running state from stats. Verify the outcome with

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manage_ml privilege to create and manage jobs.

    From compatibility in the SKILL.md frontmatter.

Context cost

Elasticsearch Anomaly Detection loads about 2.4k tokens when it runs, and up to ~4k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 876 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 876 words, ~2,387 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch-anomaly-detection/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
elasticsearch-anomaly-detection
description
Create and manage Elastic ML anomaly detection jobs via the API. Use when setting up jobs on an index or data stream, configuring jobs and datafeeds, or opening, starting, or stopping them.
compatibility
Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manage_ml privilege to create and manage jobs.
metadata.author
elastic
metadata.version
1.1.0
metadata.universal
true

Elasticsearch Anomaly Detection

Create, open, and start ML anomaly detection jobs on time-series data. Choose the right count-family detector direction, configure bucket span and time field, wire the datafeed to the correct index, and confirm running state from stats — not from assumptions.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

Prerequisite: ML anomaly detection requires a Platinum-equivalent license on self-managed clusters. Serverless projects include ML. The caller needs manage_ml to create and manage jobs.

Related skill: For interpreting anomaly scores, influencers, and model behavior after a job is running, use elasticsearch-anomaly-detection-explainer — not this skill.

Process

  1. Discover the target index and time field. List candidate indices with GET /_cat/indices (pass a pattern when the user names one). Fetch field types for the chosen index with GET /{index}/_mapping. The decision: confirm the index exists, identify the time field (often @timestamp), and verify document volume is sufficient for baseline learning. Never guess index or field names — they vary across deployments.

  2. Choose detector function and direction. Match the user's intent to a count-family detector in analysis_config.detectors:

    • Spike, surge, unusual increase in event volume → high_count (or count, which flags both directions but is acceptable when the user cares about spikes). Do not use low_count — it will miss spikes.
    • Drop, outage, absence of events, traffic stops → low_count. Do not use high_count — it will miss drops and silence.
    • Metric deviation (CPU, latency, a numeric field) → mean-family functions (mean, high_mean, low_mean) with field_name set — only when the user asks about a numeric metric, not raw event volume.

    The decision: pick one primary detector whose direction matches the anomaly type. For volume spike/drop questions on document counts, stay in the count family — mean detectors are unsuited to "how many events" questions.

  3. Set immutable job shape before creation. These fields cannot change after PUT /_ml/anomaly_detectors/{job_id}:

    • analysis_config.bucket_span — use the interval the user specifies (e.g. 15m for 15-minute buckets). Match the granularity of anomalies they care about; too short is noisy, too long is slow to detect.
    • data_description.time_field — the time field from the mapping (commonly @timestamp).
    • analysis_config.detectors — the function and direction from step 2.

    Example job body for a volume-spike detector:

    json
    {
      "analysis_config": {
        "bucket_span": "15m",
        "detectors": [{ "function": "high_count" }]
      },
      "data_description": { "time_field": "@timestamp" }
    }

    Example for an outage / drop detector:

    json
    {
      "analysis_config": {
        "bucket_span": "15m",
        "detectors": [{ "function": "low_count" }]
      },
      "data_description": { "time_field": "@timestamp" }
    }
  4. Create the job. Call PUT /_ml/anomaly_detectors/{job_id} with the job id the user requested (or a descriptive id you propose). The job starts in closed state — creating it does not start analysis.

  5. Create the datafeed. Call PUT /_ml/datafeeds/datafeed-{job_id} immediately after job creation. Set job_id to the same id, indices to the target index (exact name or pattern from step 1), and a query that selects the relevant documents (typically match_all). The datafeed id convention is datafeed-{job_id}.

    json
    {
      "job_id": "{job_id}",
      "indices": ["{index}"],
      "query": { "match_all": {} }
    }
  6. Open the job, then start the datafeed — in that order. This sequence is mandatory; do not skip or reorder:

    1. POST /_ml/anomaly_detectors/{job_id}/_open — transitions the job to opened.
    2. POST /_ml/datafeeds/datafeed-{job_id}/_start — transitions the datafeed to started.

    Opening before the datafeed exists fails. Starting the datafeed before opening the job fails. Do not report success after only creating resources — the job is not running until both are active.

  7. Confirm running state from stats. Verify the outcome with:

    • GET /_ml/anomaly_detectors/{job_id}/_stats — expect state: "opened".
    • GET /_ml/datafeeds/datafeed-{job_id}/_stats — expect state: "started".

    Optionally call GET /_ml/anomaly_detectors/{job_id} to confirm configuration (detectors, bucket_span, time_field, datafeed indices). Report both stats states explicitly — "created" is not the same as "opened" and "started".

Show full SKILL.md (251 more words)Show less

Teardown

When stopping or deleting a job, reverse the startup order:

  1. POST /_ml/datafeeds/datafeed-{job_id}/_stop — stop the datafeed first.
  2. POST /_ml/anomaly_detectors/{job_id}/_close — then close the job.

Stop the datafeed before closing the job. Close the job before resetting or deleting it.

Guidelines

  • Required lifecycle order (create): job → datafeed → open job → start datafeed. Every new job follows this sequence.
  • Detector direction is the highest-impact decision for volume anomalies. Re-read the user's wording: "spike", "surge", and "unusual increase" → high direction; "drop", "outage", "stops", "absence" → low direction.
  • Immutable fields (bucket_span, detectors, time_field) require delete-and-recreate if wrong — validate mapping and intent before the first PUT.
  • Datafeed index must match the user's target. Point indices at the exact index or pattern they named — not a nearby guess.
  • Entity-level analysis (by_field_name, over_field_name, partition_field_name) and advanced tuning live in references/anomaly-detection-reference.md.

Full Reference

For API paths, request/response fields, score semantics, and field interactions, read references/anomaly-detection-reference.md.

Operations

HTTP API (shorthand)elastic CLI command
GET /_cat/indiceselastic es cat indices --index '<pattern>'
GET /{index}/_mappingelastic es indices get-mapping --index '<index>'
PUT /_ml/anomaly_detectors/{job_id}elastic es ml put-job --job-id '<job_id>' --analysis-config '<json>' --data-description '<json>'
PUT /_ml/datafeeds/datafeed-{job_id}elastic es ml put-datafeed --datafeed-id 'datafeed-<job_id>' --job-id '<job_id>' --indices '<index>' --query '<json>'
POST /_ml/anomaly_detectors/{job_id}/_openelastic es ml open-job --job-id '<job_id>'
POST /_ml/datafeeds/datafeed-{job_id}/_startelastic es ml start-datafeed --datafeed-id 'datafeed-<job_id>'
GET /_ml/anomaly_detectors/{job_id}elastic es ml get-jobs --job-id '<job_id>'
GET /_ml/anomaly_detectors/{job_id}/_statselastic es ml get-job-stats --job-id '<job_id>'
GET /_ml/datafeeds/datafeed-{job_id}/_statselastic es ml get-datafeed-stats --datafeed-id 'datafeed-<job_id>'
POST /_ml/datafeeds/datafeed-{job_id}/_stopelastic es ml stop-datafeed --datafeed-id 'datafeed-<job_id>'
POST /_ml/anomaly_detectors/{job_id}/_closeelastic es ml close-job --job-id '<job_id>'

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/elasticsearch/elasticsearch-anomaly-detection of elastic/agent-skills.

  • SKILL.md
  • references/anomaly-detection-reference.md

Open the folder on GitHubat commit baa5111

Compare with similar skills

Elasticsearch Anomaly Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch Anomaly Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch Anomaly Detection this skillelastic/agent-skills592—~2.4kAutomated safety check: PassApache-2.0
Amazon Opensearch Serviceaws/agent-toolkit-for-aws2.8k—~2.4kAutomated safety check: PassApache-2.0
Elasticsearch File IngestKilo-Org/kilo-marketplace190—~2.8kAutomated safety check: PassApache-2.0
TimesFM Forecastinggoogle-research/timesfm34k—~4.7kAutomated safety check: PassApache-2.0
Anomalib Adding A Modelopen-edge-platform/anomalib6.2k—~1.9kAutomated safety check: PassApache-2.0
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • Amazon Opensearch Service

    aws/agent-toolkit-for-aws

    Official

    Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…

    2.8k GitHub stars~2.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • TimesFM Forecasting

    google-research/timesfm

    Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.

    34k GitHub stars~4.7k tokensUpdated 10 days ago
    Data & AnalyticsAuto-check passed
  • Anomalib Adding A Model

    open-edge-platform/anomalib

    Adds a new anomaly-detection model to anomalib under src/anomalib/models/.

    6.2k GitHub stars~1.9k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Anomalib Tiled Ensemble

    open-edge-platform/anomalib

    Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.

    6.2k GitHub stars~1.4k tokensUpdated today
    Data & AnalyticsAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Elasticsearch Anomaly Detection

What does Elasticsearch Anomaly Detection do?

Create and manage Elastic ML anomaly detection jobs via the API. Elasticsearch Anomaly Detection is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Elastic ML anomaly detection jobs via the API.

When should I use Elasticsearch Anomaly Detection?

Elasticsearch Anomaly Detection fits situations like: setting up jobs on an index; configuring jobs and datafeeds.

How do I install Elasticsearch Anomaly Detection in Claude Code?

Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection in elastic/agent-skills) into .claude/skills/elasticsearch-anomaly-detection in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch Anomaly Detection in Codex?

Run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-anomaly-detection in elastic/agent-skills) into .agents/skills/elasticsearch-anomaly-detection in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch Anomaly Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-anomaly-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-anomaly-detection, .gemini/skills/elasticsearch-anomaly-detection, .github/skills/elasticsearch-anomaly-detection and .opencode/skills/elasticsearch-anomaly-detection in your project.

What does Elasticsearch Anomaly Detection need to run?

SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Anomaly Detection is instructions for the agent only. Compatibility (from SKILL.md): Requires Elasticsearch 8.x+ or Elastic Cloud Serverless with ML anomaly detection. Uses the ML REST API only. User needs manage_ml privilege to create and manage jobs. .

Does Elasticsearch Anomaly Detection access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Elasticsearch Anomaly Detection safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch Anomaly Detection use?

Elasticsearch Anomaly Detection is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch Anomaly Detection use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Elasticsearch Anomaly Detection?

Skills that share tags, products or a category with Elasticsearch Anomaly Detection: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars), TimesFM Forecasting (google-research/timesfm, 34k stars) and Anomalib Adding A Model (open-edge-platform/anomalib, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch Anomaly Detection?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.