Elasticsearch File Ingest
aspectrr/deer
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter.
$ npx skills add elastic/agent-skills --skill elasticsearch-ingest -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills elasticsearch-ingest --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-ingest .claude/skills/elasticsearch-ingest && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "elasticsearch-ingest" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-ingest into .claude/skills/elasticsearch-ingest/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-ingest", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-ingestType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill elasticsearch-ingest -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills elasticsearch-ingest --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-ingest .agents/skills/elasticsearch-ingest && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "elasticsearch-ingest" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-ingest into .agents/skills/elasticsearch-ingest/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-ingest", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-ingest -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills elasticsearch-ingest --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-ingest .cursor/skills/elasticsearch-ingest && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "elasticsearch-ingest" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-ingest into .cursor/skills/elasticsearch-ingest/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-ingest", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/elasticsearch/elasticsearch-ingest--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill elasticsearch-ingest -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills elasticsearch-ingest --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-ingest .gemini/skills/elasticsearch-ingest && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "elasticsearch-ingest" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-ingest into .gemini/skills/elasticsearch-ingest/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-ingest", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills elasticsearch-ingestInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill elasticsearch-ingest -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-ingest .github/skills/elasticsearch-ingest && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-ingest" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-ingest into .github/skills/elasticsearch-ingest/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-ingest", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill elasticsearch-ingest -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills elasticsearch-ingest --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-ingest .opencode/skills/elasticsearch-ingest && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "elasticsearch-ingest" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/elasticsearch/elasticsearch-ingest into .opencode/skills/elasticsearch-ingest/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "elasticsearch-ingest", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
elasticsearch-ingestLoad CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter.
Elasticsearch Ingest is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Use when batch-importing local files, converting CSV rows or JSON arrays to NDJSON bulk format, or verifying document counts and mappings after ingest — not for Logstash pipelines, Beats, custom scripts, or index-to-index reindex.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/mapping-design.md`, `references/ndjson-bulk-format.md` and `references/troubleshooting.md`). Compatibility notes: Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the…
It sits in Backend & APIs, covering Search implementation and CSV and tabular files. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
8 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are csv and json).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support.
From compatibility in the SKILL.md frontmatter.
Elasticsearch Ingest loads about 2.7k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,262 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,262 words, ~2,694 tokens.
.claude/skills/elasticsearch-ingest/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Load local data files into Elasticsearch by converting them to bulk NDJSON, creating an index with the right mappings when types matter, bulk-indexing documents, and verifying the outcome.
<!-- begin-partial: preamble -->
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
<!-- end-partial: preamble -->
This skill covers file → index loading through POST /_bulk. It does not use Logstash, Filebeat, Elastic Agent,
Node.js ingest tools, or other sidecar pipelines. For copying documents between existing indices, use index-to-index
reindex instead of re-parsing source files.
Supported source shapes:
| Source shape | Example | Bulk requirement |
|---|---|---|
| CSV with header row | id,name,age,... then data rows | Parse header into field names; emit one action line + one JSON object per data row |
| JSON array file | [{"a":1},{"a":2}] | Split into per-document lines — never bulk-load the raw array as a single document |
| NDJSON / JSON Lines | one JSON object per line | Optionally add action lines if missing; otherwise ready for bulk |
Parquet, Arrow, and other binary columnar formats are out of scope unless the user converts them to CSV or JSON first.
Confirm connectivity. Call GET /. If the call fails, stop and resolve CLI configuration before reading files or
mutating cluster state.
Inspect the source file and classify its shape. Open the file (or sample the first lines) and decide:
[ and contains an array of objects. Count array elements — each element becomes
one indexed document, not one.The decision: pick the conversion path from NDJSON Bulk Format. Never send
raw CSV text or a raw JSON array body to POST /_bulk.
Choose the target index name. Use the name the user supplied, or propose a lowercase name derived from the file.
Index names must be lowercase, cannot contain spaces or /, and should not start with -, _, or +.
Decide whether an explicit mapping is required. Call GET /{index}/_mapping if the index may already exist.
Create an explicit mapping before bulk loading when:
text/keyword strings and must be corrected.When every field can remain string-like and the user did not specify types, dynamic mapping on first bulk ingest may suffice — but prefer explicit mappings for CSV unless the user explicitly accepts all-string typing.
Read Mapping Design for Ingest for type choices. When the index exists with wrong
types, ask the user before calling DELETE /{index} and recreating it.
Create the index when needed. When step 4 requires explicit types (or the index does not exist), call
PUT /{index} with a mappings block before bulk loading. Do not rely on dynamic mapping to infer long,
date, or boolean from CSV string cells — dynamic mapping often maps ambiguous strings to text with a .keyword
sub-field.
Convert the file to bulk NDJSON. Write a temporary NDJSON file where each document occupies two lines:
{"index":{"_index":"<index>"}} (add "_id" only when the user requires stable
IDs).true/false, dates as
ISO-8601 strings such as 2023-01-15).For CSV, map the header row to JSON field names and convert cell values to the JSON types that match the mapping from step 5. For JSON arrays, iterate each array element and emit the action line + object line pair. See worked examples in NDJSON Bulk Format.
Bulk index the documents. Call POST /_bulk with the NDJSON file produced in step 6. Inspect the response: if
errors is true, read per-item error objects, fix mapping or document issues, and retry failed items after
remediation. Do not assume success from a zero exit code alone.
Verify the outcome. Always confirm the load — never report counts from file inspection alone.
GET /{index}/_count and compare to the expected row/element count from step 2.GET /{index}/_mapping and confirm fields such as age are numeric (long /
integer), dates are date, and booleans are boolean — not text.Report the verified document count and, when relevant, the confirmed field types. If count or mapping checks fail, see Troubleshooting.
POST /_bulk with NDJSON action lines — not single-document PUT loops for
batch files, not ingest pipelines as a substitute for client-side CSV parsing, and not posting the untouched source
file.1; the correct load
yields count 4.5 after ingest.long, date, or
boolean, emit JSON numbers, ISO date strings, and boolean literals in the bulk body — do not rely on Elasticsearch
to infer types from quoted CSV strings after dynamic mapping chose text.PUT /{index} first prevents silent all-text
indexing that breaks range queries and aggregations.index actions append new documents unless _id is specified.Source (users.csv — header + 5 data rows):
id,name,age,signup_date,active
1,Ada Lovelace,36,2023-01-15,trueCreate the index with explicit types, convert rows to NDJSON (five action+document pairs for five data rows), bulk load,
then verify count 5 and mapping types. Full walkthrough:
Mapping Design for Ingest and
NDJSON Bulk Format.
Source (events.json):
[
{ "event_id": "e-1", "type": "login", "user_id": 1, "value": 12.5 },
{ "event_id": "e-2", "type": "logout", "user_id": 1, "value": 0.0 }
]Convert to four bulk line pairs for four array elements (not one pair for the whole array). Verify GET /{index}/_count
returns 4. See NDJSON Bulk Format.
When the file alternates action lines and document lines, validate the format and pass it directly to POST /_bulk
after confirming the target index and mappings.
| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET / | elastic es info |
PUT /{index} | elastic es indices create --index '<index>' --mappings '<json>' |
DELETE /{index} | elastic es indices delete --index '<index>' |
POST /_bulk | elastic es bulk --index '<index>' --input-file '<ndjson-path>' |
GET /{index}/_count | elastic es count --index '<index>' |
GET /{index}/_mapping | elastic es indices get-mapping --index '<index>' |
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/elasticsearch/elasticsearch-ingest of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Elasticsearch Ingest next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Elasticsearch Ingest this skillelastic/agent-skills | 592 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch File Ingestaspectrr/deer | 405 | — | ~684 | Automated safety check: Pass | MIT | |
| Elasticsearch File IngestKilo-Org/kilo-marketplace | 190 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Product Full-Text Searchlobehub/lobehub | 83k | — | ~4.1k | Automated safety check: Pass | Custom licence | |
| Foundatio Repositoriesexceptionless/Exceptionless | 2.5k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Elasticsearch Authnaspectrr/deer | 405 | — | ~1.2k | Automated safety check: Notes | MIT |
aspectrr/deer
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
Kilo-Org/kilo-marketplace
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
exceptionless/Exceptionless
Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.
aspectrr/deer
Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.
aspectrr/deer
Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Elasticsearch Ingest is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter.
Elasticsearch Ingest fits situations like: batch-importing local files; converting CSV rows; JSON arrays to NDJSON bulk format; verifying document counts and mappings after ingest — not for Logstash pipelines.
Run `npx skills add elastic/agent-skills --skill elasticsearch-ingest -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-ingest in elastic/agent-skills) into .claude/skills/elasticsearch-ingest in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill elasticsearch-ingest -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-ingest in elastic/agent-skills) into .agents/skills/elasticsearch-ingest in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-ingest -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-ingest, .gemini/skills/elasticsearch-ingest, .github/skills/elasticsearch-ingest and .opencode/skills/elasticsearch-ingest in your project.
SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Ingest is instructions for the agent only. Our summary lists: Node.js. Compatibility (from SKILL.md): Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support..
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Elasticsearch Ingest is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Elasticsearch Ingest: Elasticsearch File Ingest (aspectrr/deer, 405 stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars), Product Full-Text Search (lobehub/lobehub, 83k stars) and Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.