Official agent skill

Elasticsearch Ingest

by elastic in elastic/agent-skills

Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter.

OfficialApache-2.0Auto-check passedBackend & APIs

Install Elasticsearch Ingest

skills CLI
$ npx skills add elastic/agent-skills --skill elasticsearch-ingest -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills elasticsearch-ingest --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/elasticsearch/elasticsearch-ingest .claude/skills/elasticsearch-ingest && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
elasticsearch-ingest
GitHub stars
592
Token cost
~2.7k tokens
SKILL.md length
1,262 words
Files
4 (incl. references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter.

  • Works in 8 steps: Confirm connectivity. Call GET /. If the… → Inspect the source file and classify its… → Choose the target index name. Use the… → …
  • Batch-importing local files
  • SKILL.md covers Environment Configuration, Scope, Process and Guidelines, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Elasticsearch Ingest is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Use when batch-importing local files, converting CSV rows or JSON arrays to NDJSON bulk format, or verifying document counts and mappings after ingest — not for Logstash pipelines, Beats, custom scripts, or index-to-index reindex.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/mapping-design.md`, `references/ndjson-bulk-format.md` and `references/troubleshooting.md`). Compatibility notes: Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the…

It sits in Backend & APIs, covering Search implementation and CSV and tabular files. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • Batch-importing local files
  • Converting CSV rows
  • JSON arrays to NDJSON bulk format
  • Verifying document counts and mappings after ingest — not for Logstash pipelines

Example prompts

  • “/elasticsearch-ingest”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support.

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Confirm connectivity. Call GET /. If the call fails, stop and resolve CLI configuration before reading files or
  2. Inspect the source file and classify its shape. Open the file (or sample the first lines) and decide
  3. Choose the target index name. Use the name the user supplied, or propose a lowercase name derived from the file.
  4. Decide whether an explicit mapping is required. Call GET /{index}/_mapping if the index may already exist.
  5. Create the index when needed. When step 4 requires explicit types (or the index does not exist), call
  6. Convert the file to bulk NDJSON. Write a temporary NDJSON file where each document occupies two lines
  7. Bulk index the documents. Call POST /_bulk with the NDJSON file produced in step 6. Inspect the response: if
  8. Verify the outcome. Always confirm the load — never report counts from file inspection alone.

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are csv and json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support.

    From compatibility in the SKILL.md frontmatter.

Context cost

Elasticsearch Ingest loads about 2.7k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 92 tokens; SKILL.md has 1,262 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~92
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,262 words, ~2,694 tokens.

Download SKILL.mdSave it as .claude/skills/elasticsearch-ingest/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
elasticsearch-ingest
description
Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Use when batch-importing local files, converting CSV rows or JSON arrays to NDJSON bulk format, or verifying document counts and mappings after ingest — not for Logstash pipelines, Beats, custom scripts, or index-to-index reindex.
compatibility
Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support.
metadata.author
elastic
metadata.version
0.1.0
metadata.universal
true

Elasticsearch File Ingest

Load local data files into Elasticsearch by converting them to bulk NDJSON, creating an index with the right mappings when types matter, bulk-indexing documents, and verifying the outcome.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

Scope

This skill covers file → index loading through POST /_bulk. It does not use Logstash, Filebeat, Elastic Agent, Node.js ingest tools, or other sidecar pipelines. For copying documents between existing indices, use index-to-index reindex instead of re-parsing source files.

Supported source shapes:

Source shapeExampleBulk requirement
CSV with header rowid,name,age,... then data rowsParse header into field names; emit one action line + one JSON object per data row
JSON array file[{"a":1},{"a":2}]Split into per-document lines — never bulk-load the raw array as a single document
NDJSON / JSON Linesone JSON object per lineOptionally add action lines if missing; otherwise ready for bulk

Parquet, Arrow, and other binary columnar formats are out of scope unless the user converts them to CSV or JSON first.

Process

  1. Confirm connectivity. Call GET /. If the call fails, stop and resolve CLI configuration before reading files or mutating cluster state.

  2. Inspect the source file and classify its shape. Open the file (or sample the first lines) and decide:

    • CSV — first line is a comma-separated header; subsequent lines are records. Count data rows (exclude the header) — you will report this count after load.
    • JSON array — file starts with [ and contains an array of objects. Count array elements — each element becomes one indexed document, not one.
    • NDJSON — one JSON value per line; lines alternate action metadata and document source, or each line is a document that still needs a preceding action line.

    The decision: pick the conversion path from NDJSON Bulk Format. Never send raw CSV text or a raw JSON array body to POST /_bulk.

  3. Choose the target index name. Use the name the user supplied, or propose a lowercase name derived from the file. Index names must be lowercase, cannot contain spaces or /, and should not start with -, _, or +.

  4. Decide whether an explicit mapping is required. Call GET /{index}/_mapping if the index may already exist.

    Create an explicit mapping before bulk loading when:

    • CSV columns include numbers, dates, or booleans that must be queryable as typed fields (not plain text).
    • The user asks for usable column types or aggregation-friendly fields.
    • A prior load indexed everything as text/keyword strings and must be corrected.

    When every field can remain string-like and the user did not specify types, dynamic mapping on first bulk ingest may suffice — but prefer explicit mappings for CSV unless the user explicitly accepts all-string typing.

    Read Mapping Design for Ingest for type choices. When the index exists with wrong types, ask the user before calling DELETE /{index} and recreating it.

  5. Create the index when needed. When step 4 requires explicit types (or the index does not exist), call PUT /{index} with a mappings block before bulk loading. Do not rely on dynamic mapping to infer long, date, or boolean from CSV string cells — dynamic mapping often maps ambiguous strings to text with a .keyword sub-field.

  6. Convert the file to bulk NDJSON. Write a temporary NDJSON file where each document occupies two lines:

    • Line 1 — action metadata, e.g. {"index":{"_index":"<index>"}} (add "_id" only when the user requires stable IDs).
    • Line 2 — document JSON with correctly typed values (numbers as JSON numbers, booleans as true/false, dates as ISO-8601 strings such as 2023-01-15).

    For CSV, map the header row to JSON field names and convert cell values to the JSON types that match the mapping from step 5. For JSON arrays, iterate each array element and emit the action line + object line pair. See worked examples in NDJSON Bulk Format.

  7. Bulk index the documents. Call POST /_bulk with the NDJSON file produced in step 6. Inspect the response: if errors is true, read per-item error objects, fix mapping or document issues, and retry failed items after remediation. Do not assume success from a zero exit code alone.

  8. Verify the outcome. Always confirm the load — never report counts from file inspection alone.

    • Call GET /{index}/_count and compare to the expected row/element count from step 2.
    • When typed columns matter, call GET /{index}/_mapping and confirm fields such as age are numeric (long / integer), dates are date, and booleans are boolean — not text.

    Report the verified document count and, when relevant, the confirmed field types. If count or mapping checks fail, see Troubleshooting.

Show full SKILL.md (444 more words)Show less

Guidelines

  • Bulk only. All file loads go through POST /_bulk with NDJSON action lines — not single-document PUT loops for batch files, not ingest pipelines as a substitute for client-side CSV parsing, and not posting the untouched source file.
  • JSON arrays must be split. A four-element array bulk-loaded as one document yields count 1; the correct load yields count 4.
  • CSV header is schema. The first CSV row names fields; each remaining row is one document. A file with one header plus five data rows must report count 5 after ingest.
  • Type coercion happens in the document JSON. CSV cells arrive as strings; when mappings declare long, date, or boolean, emit JSON numbers, ISO date strings, and boolean literals in the bulk body — do not rely on Elasticsearch to infer types from quoted CSV strings after dynamic mapping chose text.
  • Prefer explicit mappings for typed CSV. Creating the index with PUT /{index} first prevents silent all-text indexing that breaks range queries and aggregations.
  • Idempotent re-loads. When reloading into an existing index, ask the user before deleting data. Duplicate bulk index actions append new documents unless _id is specified.

Examples

CSV with typed columns

Source (users.csv — header + 5 data rows):

csv
id,name,age,signup_date,active
1,Ada Lovelace,36,2023-01-15,true

Create the index with explicit types, convert rows to NDJSON (five action+document pairs for five data rows), bulk load, then verify count 5 and mapping types. Full walkthrough: Mapping Design for Ingest and NDJSON Bulk Format.

JSON array file

Source (events.json):

json
[
  { "event_id": "e-1", "type": "login", "user_id": 1, "value": 12.5 },
  { "event_id": "e-2", "type": "logout", "user_id": 1, "value": 0.0 }
]

Convert to four bulk line pairs for four array elements (not one pair for the whole array). Verify GET /{index}/_count returns 4. See NDJSON Bulk Format.

NDJSON already prepared

When the file alternates action lines and document lines, validate the format and pass it directly to POST /_bulk after confirming the target index and mappings.

When Not to Use

  • Continuous or streaming ingestion — use Elastic Agent or Beats to tail logs and metrics.
  • Complex enrichment pipelines — design server-side ingest pipelines separately; this skill still converts files to bulk NDJSON client-side before load.
  • Index-to-index copy or mapping migration — reindex between indices instead of exporting to files.
  • Very large binary columnar files — convert to CSV or JSON offline first, then follow this skill.

References

Operations

HTTP API (shorthand)elastic CLI command
GET /elastic es info
PUT /{index}elastic es indices create --index '<index>' --mappings '<json>'
DELETE /{index}elastic es indices delete --index '<index>'
POST /_bulkelastic es bulk --index '<index>' --input-file '<ndjson-path>'
GET /{index}/_countelastic es count --index '<index>'
GET /{index}/_mappingelastic es indices get-mapping --index '<index>'

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/elasticsearch/elasticsearch-ingest of elastic/agent-skills.

  • SKILL.md
  • references/mapping-design.md
  • references/ndjson-bulk-format.md
  • references/troubleshooting.md

Open the folder on GitHubat commit baa5111

Compare with similar skills

Elasticsearch Ingest next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Elasticsearch Ingest compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Elasticsearch Ingest this skillelastic/agent-skills592—~2.7kAutomated safety check: PassApache-2.0
Elasticsearch File Ingestaspectrr/deer405—~684Automated safety check: PassMIT
Elasticsearch File IngestKilo-Org/kilo-marketplace190—~2.8kAutomated safety check: PassApache-2.0
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence
Foundatio Repositoriesexceptionless/Exceptionless2.5k—~1.9kAutomated safety check: PassApache-2.0
Elasticsearch Authnaspectrr/deer405—~1.2kAutomated safety check: NotesMIT

Similar skills

  • Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    405 GitHub stars~684 tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Elasticsearch Authn

    aspectrr/deer

    Authenticate to Elasticsearch using native, file-based, LDAP/AD, SAML, OIDC, Kerberos, JWT, or certificate realms.

    405 GitHub stars~1.2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Elasticsearch Authz

    aspectrr/deer

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Elasticsearch Ingest

What does Elasticsearch Ingest do?

Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Elasticsearch Ingest is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter.

When should I use Elasticsearch Ingest?

Elasticsearch Ingest fits situations like: batch-importing local files; converting CSV rows; JSON arrays to NDJSON bulk format; verifying document counts and mappings after ingest — not for Logstash pipelines.

How do I install Elasticsearch Ingest in Claude Code?

Run `npx skills add elastic/agent-skills --skill elasticsearch-ingest -a claude-code`. Or copy the skill folder (skills/elasticsearch/elasticsearch-ingest in elastic/agent-skills) into .claude/skills/elasticsearch-ingest in your project. Claude Code loads it when a task matches its description.

How do I install Elasticsearch Ingest in Codex?

Run `npx skills add elastic/agent-skills --skill elasticsearch-ingest -a codex`. Or copy the skill folder (skills/elasticsearch/elasticsearch-ingest in elastic/agent-skills) into .agents/skills/elasticsearch-ingest in your project. Codex loads it when a task matches its description.

Can I use Elasticsearch Ingest in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill elasticsearch-ingest -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/elasticsearch-ingest, .gemini/skills/elasticsearch-ingest, .github/skills/elasticsearch-ingest and .opencode/skills/elasticsearch-ingest in your project.

What does Elasticsearch Ingest need to run?

SKILL.md names no scripts, command-line tools or credentials: Elasticsearch Ingest is instructions for the agent only. Our summary lists: Node.js. Compatibility (from SKILL.md): Elasticsearch 8.x or 9.x, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; uses the bulk API available on all deployment types. Requires the `elastic` CLI ≥ 0.2 with `stack es` support..

Does Elasticsearch Ingest access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Elasticsearch Ingest safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Elasticsearch Ingest use?

Elasticsearch Ingest is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Elasticsearch Ingest use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Elasticsearch Ingest?

Skills that share tags, products or a category with Elasticsearch Ingest: Elasticsearch File Ingest (aspectrr/deer, 405 stars), Elasticsearch File Ingest (Kilo-Org/kilo-marketplace, 190 stars), Product Full-Text Search (lobehub/lobehub, 83k stars) and Foundatio Repositories (exceptionless/Exceptionless, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Elasticsearch Ingest?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.