Official agent skill

Kibana Alerting Rules

by elastic in elastic/agent-skills

Create and manage Kibana alerting rules. An agent skill from elastic/agent-skills.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Kibana Alerting Rules

skills CLI
$ npx skills add elastic/agent-skills --skill kibana-alerting-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills kibana-alerting-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kibana/kibana-alerting-rules .claude/skills/kibana-alerting-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kibana-alerting-rules
GitHub stars
592
Token cost
~4.2k tokens
SKILL.md length
1,475 words
Files
3 (incl. references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create and manage Kibana alerting rules. An agent skill from elastic/agent-skills.

  • Works in 8 steps: Classify the task. Decide whether the… → For find/list tasks, filter and page… → For create tasks, choose the rule type… → …
  • Managing rule lifecycle (enable
  • SKILL.md covers Environment Configuration, Core concepts, Process and Examples, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kibana Alerting Rules is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana alerting rules. Use when creating, updating, or managing rule lifecycle (enable, disable, mute, snooze), choosing metric threshold rule types and params, or read-only find/list with tag filters.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/connectors-actions-terraform.md` and `references/rule-types-reference.md`). Compatibility notes: Kibana 8.x or 9.x with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; some rule types and features are version- or…

It sits in DevOps & Cloud. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • Managing rule lifecycle (enable
  • Choosing metric threshold rule types and params
  • Read-only find/list with tag filters

Example prompts

  • “/kibana-alerting-rules”

Requirements

  • Compatibility (from SKILL.md): Kibana 8.x or 9.x with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; some rule types and features are version- or license-gated (for example, rule-level flapping is GA in 9.3). Requires the `elastic` CLI ≥ 0.2 with `stack kb` support.

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Classify the task. Decide whether the user needs to create a rule, find/list rules (read-only),
  2. For find/list tasks, filter and page sensibly. Call GET kbn:/api/alerting/rules/_find with query parameters
  3. For create tasks, choose the rule type before writing params. Match the user's intent to a metric/threshold rule
  4. Encode threshold, duration, and grouping correctly. These three dimensions are independent
  5. Build the create payload. Required fields: name, rule_type_id, consumer, schedule, params. Optional
  6. Create and confirm. Call POST kbn:/api/alerting/rule/{id} with the payload. On 409 Conflict, the id already
  7. For update tasks, read then replace. rule_type_id and consumer are immutable. Call
  8. For lifecycle tasks, call the narrowest endpoint. Disable temporarily with

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • elastic.co
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Kibana 8.x or 9.x with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; some rule types and features are version- or license-gated (for example, rule-level flapping is GA in 9.3). Requires the `elastic` CLI ≥ 0.2 with `stack kb` support.

    From compatibility in the SKILL.md frontmatter.

Context cost

Kibana Alerting Rules loads about 4.2k tokens when it runs, and up to ~6.7k if it reads all its reference files. Until then it costs about 60 tokens; SKILL.md has 1,475 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,475 words, ~4,226 tokens.

Download SKILL.mdSave it as .claude/skills/kibana-alerting-rules/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
kibana-alerting-rules
description
Create and manage Kibana alerting rules. Use when creating, updating, or managing rule lifecycle (enable, disable, mute, snooze), choosing metric threshold rule types and params, or read-only find/list with tag filters.
compatibility
Kibana 8.x or 9.x with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; some rule types and features are version- or license-gated (for example, rule-level flapping is GA in 9.3). Requires the `elastic` CLI ≥ 0.2 with `stack kb` support.
metadata.author
elastic
metadata.version
0.3.0
metadata.universal
true

Kibana Alerting Rules

Create, inspect, update, and manage Kibana alerting rules: choose the right rule type, encode threshold and grouping semantics, attach actions only when requested, and list or filter rules read-only when the user asks to discover existing coverage.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

Core concepts

A rule has three parts: conditions (params + rule_type_id), schedule (how often conditions are checked), and actions (optional connectors run when alerts fire). When conditions are met, the rule creates alerts; actions deliver notifications through connectors. Do not create connectors or actions unless the user explicitly asks for notification wiring — many tasks require only the rule definition.

Required privileges: all on the owning Kibana feature (Stack Rules, Observability, Security, etc.) and all on Rules Settings. Managing connectors needs all on Actions and Connectors; read is sufficient to attach existing connectors as rule actions.

On-premises prerequisite: configure a stable xpack.encryptedSavedObjects.encryptionKey in kibana.yml before creating rules — it encrypts rule API keys and connector secrets. If it is unset, each restart regenerates it and breaks existing rules; all Kibana nodes in a cluster must share the same key.

Process

  1. Classify the task. Decide whether the user needs to create a rule, find/list rules (read-only), update an existing rule, or perform a lifecycle change (enable, disable, mute, snooze, delete). If the user only asks to show or list rules, treat the request as read-only — do not create, update, enable, or delete anything.

  2. For find/list tasks, filter and page sensibly. Call GET kbn:/api/alerting/rules/_find with query parameters that narrow results instead of dumping every rule:

    • By tag: filter=alert.attributes.tags:"production" (KQL on saved-object attributes).
    • By text: search with search_fields and default_search_operator as needed.
    • Paging: set per_page and iterate page when results may exceed one page.
    • Sort: sort_field=name and sort_order=asc for stable listings.

    Enumerate matching rule ids and names. If no rules match, say so plainly — do not invent results. Query alerting rules specifically, not connectors or streams.

  3. For create tasks, choose the rule type before writing params. Match the user's intent to a metric/threshold rule type — not log, anomaly, or unrelated types:

    • Numeric metric over a time window, optionally per host/service → .index-threshold with consumer: "stackAlerts".
    • Document count or Query DSL condition → .es-query with consumer: "stackAlerts".
    • Observability metric in the metrics app → metrics.alert.threshold with consumer: "metrics" or "infrastructure".

    Read rule-types-reference.md for param schemas, valid consumers, and action groups. When the user specifies an index, field, threshold, duration, and grouping field, encode all four explicitly in params — do not substitute a connector or action for the condition.

  4. Encode threshold, duration, and grouping correctly. These three dimensions are independent:

    • Threshold: set threshold and thresholdComparator on the aggregated value. Match field scale — ECS system.cpu.total.pct is typically fractional (0.9 for 90%); use 90 only when the field is on a 0–100 scale.
    • "For N minutes" semantics: set timeWindowSize and timeWindowUnit in params (lookback evaluated each run). Align schedule.interval with that window (e.g., both five minutes) so a brief spike does not fire on a mismatched cadence. Add alert_delay: {"active": N} only when the user wants N consecutive matching runs, not a single lookback window.
    • Per-host / per-entity grouping: for .index-threshold, set groupBy: "top", termField to the grouping field (e.g., host.name), and a termSize large enough to cover all entities ("any host"). Without grouping, the rule aggregates globally and will not alert per host.
  5. Build the create payload. Required fields: name, rule_type_id, consumer, schedule, params. Optional: tags, enabled, actions, alert_delay, flapping. Use the user-supplied rule id in the URL when given; otherwise let Kibana generate one.

    Example params — CPU > 90% on any host for 5 minutes on eval-alert-metrics:

    json
    {
      "name": "CPU exceeds 90% for 5 minutes",
      "rule_type_id": ".index-threshold",
      "consumer": "stackAlerts",
      "schedule": { "interval": "5m" },
      "params": {
        "index": ["eval-alert-metrics"],
        "timeField": "@timestamp",
        "aggType": "avg",
        "aggField": "system.cpu.total.pct",
        "groupBy": "top",
        "termField": "host.name",
        "termSize": 1000,
        "threshold": [0.9],
        "thresholdComparator": ">",
        "timeWindowSize": 5,
        "timeWindowUnit": "m"
      },
      "tags": ["production"]
    }

    Omit actions when the user only asks to create the rule condition.

  6. Create and confirm. Call POST kbn:/api/alerting/rule/{id} with the payload. On 409 Conflict, the id already exists — call GET kbn:/api/alerting/rule/{id} to inspect or choose a different id. After a successful create, call GET kbn:/api/alerting/rule/{id} and confirm success to the user with the live rule id, name, and enabled state — do not claim success without verifying on Kibana.

  7. For update tasks, read then replace. rule_type_id and consumer are immutable. Call GET kbn:/api/alerting/rule/{id}, merge intended changes, then PUT kbn:/api/alerting/rule/{id} with the complete rule body. On 409 Conflict, another user changed the rule — re-fetch and retry. Set per-action frequency objects; rule-level notify_when and throttle are deprecated.

  8. For lifecycle tasks, call the narrowest endpoint. Disable temporarily with POST kbn:/api/alerting/rule/{id}/_disable (rule retains config); re-enable with POST kbn:/api/alerting/rule/{id}/_enable. Mute all alerts with POST kbn:/api/alerting/rule/{id}/_mute_all; restore with POST kbn:/api/alerting/rule/{id}/_unmute_all. Mute a single active alert with POST kbn:/api/alerting/rule/{rule_id}/alert/{alert_id}/_mute; unmute with POST kbn:/api/alerting/rule/{rule_id}/alert/{alert_id}/_unmute. Schedule snoozes with POST kbn:/api/alerting/rule/{id}/snooze_schedule; remove with DELETE kbn:/api/alerting/rule/{ruleId}/snooze_schedule/{scheduleId}. Delete permanently with DELETE kbn:/api/alerting/rule/{id}. When a rule fails due to API key ownership, call POST kbn:/api/alerting/rule/{id}/_update_api_key.

Examples

Show full SKILL.md (616 more words)Show less
Create a threshold alert

User: "Alert me when CPU exceeds 90% on any host for 5 minutes. Query eval-alert-metrics (system.cpu.total.pct, grouped by host.name). Create the rule with id eval-cpu-rule."

  1. Choose .index-threshold / stackAlerts.
  2. Encode fractional threshold [0.9], five-minute timeWindowSize/timeWindowUnit, and groupBy/termField for host.name.
  3. POST kbn:/api/alerting/rule/eval-cpu-rule with schedule.interval: "5m". Omit actions.
  4. GET kbn:/api/alerting/rule/eval-cpu-rule and confirm to the user.
Find rules by tag (read-only)

User: "Show me all production alerting rules."

  1. GET kbn:/api/alerting/rules/_find with filter=alert.attributes.tags:"production", sensible per_page, and sort_field=name.
  2. Page through results if total exceeds per_page.
  3. Report ids and names only — no mutations.
Pause a rule temporarily

User: "Disable rule abc123 until next Monday."

  1. POST kbn:/api/alerting/rule/abc123/_disable.
  2. Re-enable later with POST kbn:/api/alerting/rule/abc123/_enable.

For planned downtime spanning multiple rules, prefer a maintenance window over disabling or snoozing each rule individually.

Guidelines

  • Set frequency inside each action object — rule-level notify_when and throttle are deprecated.
  • rule_type_id and consumer are immutable after creation; delete and recreate to change them.
  • Prefix paths with kbn:/s/<space_id>/api/alerting/ for non-default Kibana Spaces (connectors are space-scoped too).
  • A rule action cannot reference a connector from a different space — the rule and its connectors must share one Space.
  • Pair active notification actions with a Recovered action for PagerDuty, Jira, and ServiceNow.
  • Use alert_delay to require consecutive matches; use flapping settings to suppress unstable alerts. Per-rule tuning via the flapping object is GA since 9.3; earlier versions support only space-level flapping settings.
  • Debug action templates with {{{.}}} in any template field — it renders the whole variable context as JSON, which helps discover correct paths like {{context.reason}} or {{alert.flapping}}.
  • Do not use this skill for Security detection rules: consumer: "securitySolution"/"siem" belongs to the dedicated Security Detections API (/api/detection_engine/rules), which has different rule type ids and lifecycle.
  • Tag rules consistently (production, staging, team names) for find API filtering.
  • Minimum recommended check interval is 1m; expensive rules are cancelled after the server run timeout (default 5m).

Common pitfalls

  1. Wrong rule type — using a log or ML rule for a metric threshold condition.
  2. Missing per-entity grouping — global aggregation when the user asked for "any host" or "per service".
  3. Threshold scale mismatch — 90 vs 0.9 on fractional CPU fields.
  4. Duration conflated with schedule — a one-minute schedule with a five-minute window behaves differently from both set to five minutes.
  5. Unrequested actions — attaching connectors when the user only asked to create the rule.
  6. Read-only violations — creating or mutating rules when the user asked only to list or filter.
  7. Concurrent update conflicts — PUT without a fresh GET returns 409.
  8. Import/export — saved-object import disables rules and strips connector secrets.

References

Operations

HTTP API (shorthand)elastic CLI command
GET kbn:/api/alerting/rules/_findelastic kb alerting get-alerting-rules-find [--filter '<kql>'] [--search '<q>'] [--per-page <n>] [--page <n>] [--sort-field <field>] [--sort-order asc|desc]
POST kbn:/api/alerting/rule/{id}elastic kb alerting post-alerting-rule-id --id '<id>' --name '<name>' --rule-type-id '<type>' --consumer '<consumer>' --schedule '<json>' --params '<json>' [--tags '<json>'] [--actions '<json>'] [--enabled]
GET kbn:/api/alerting/rule/{id}elastic kb alerting get-alerting-rule-id --id '<id>'
PUT kbn:/api/alerting/rule/{id}elastic kb alerting put-alerting-rule-id --id '<id>' --name '<name>' --schedule '<json>' --params '<json>' [--tags '<json>'] [--actions '<json>']
DELETE kbn:/api/alerting/rule/{id}elastic kb alerting delete-alerting-rule-id --id '<id>'
POST kbn:/api/alerting/rule/{id}/_enableelastic kb alerting post-alerting-rule-id-enable --id '<id>'
POST kbn:/api/alerting/rule/{id}/_disableelastic kb alerting post-alerting-rule-id-disable --id '<id>' [--untrack]
POST kbn:/api/alerting/rule/{id}/_mute_allelastic kb alerting post-alerting-rule-id-mute-all --id '<id>'
POST kbn:/api/alerting/rule/{id}/_unmute_allelastic kb alerting post-alerting-rule-id-unmute-all --id '<id>'
POST kbn:/api/alerting/rule/{id}/_update_api_keyelastic kb alerting post-alerting-rule-id-update-api-key --id '<id>'
POST kbn:/api/alerting/rule/{rule_id}/alert/{alert_id}/_muteelastic kb alerting post-alerting-rule-rule-id-alert-alert-id-mute --rule-id '<rule_id>' --alert-id '<alert_id>'
POST kbn:/api/alerting/rule/{rule_id}/alert/{alert_id}/_unmuteelastic kb alerting post-alerting-rule-rule-id-alert-alert-id-unmute --rule-id '<rule_id>' --alert-id '<alert_id>'
POST kbn:/api/alerting/rule/{id}/snooze_scheduleelastic kb alerting post-alerting-rule-id-snooze-schedule --id '<id>' --schedule '<json>'
DELETE kbn:/api/alerting/rule/{ruleId}/snooze_schedule/{scheduleId}elastic kb alerting delete-alerting-rule-ruleid-snooze-schedule-scheduleid --rule-id '<ruleId>' --schedule-id '<scheduleId>'

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/kibana/kibana-alerting-rules of elastic/agent-skills.

  • SKILL.md
  • references/connectors-actions-terraform.md
  • references/rule-types-reference.md

Open the folder on GitHubat commit baa5111

Compare with similar skills

Kibana Alerting Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kibana Alerting Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kibana Alerting Rules this skillelastic/agent-skills592—~4.2kAutomated safety check: PassApache-2.0
UI Architectopenobserve/openobserve22k—~16kAutomated safety check: NotesAGPL-3.0
Ecs Rfc Guideelastic/ecs1.1k—~1.2kAutomated safety check: PassApache-2.0
UModel Root Cause Analysisalibaba/UnifiedModel415—~1.9kAutomated safety check: PassCustom licence
Aspire Diagnosticsexceptionless/Exceptionless2.5k—~769Automated safety check: PassApache-2.0
Proto Backend Moduleaide-family/moon253—~4.1kAutomated safety check: PassNone

Similar skills

  • UI Architect

    openobserve/openobserve

    ALWAYS use this skill for ANY change to the OpenObserve web UI (web/) — even a single-line UI modification.

    22k GitHub stars~16k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Ecs Rfc Guide

    elastic/ecs

    Official

    Guides contributors through the Elastic Common Schema (ECS) RFC (Proposal) process: template sections, target maturity (alpha/beta), rfcs/text artifacts, and optional OTel mapping.

    1.1k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • UModel Root Cause Analysis

    alibaba/UnifiedModel

    Investigates a service incident to its root cause by querying a UModel object graph alongside metrics, logs, topology and recent deployments.

    415 GitHub stars~1.9k tokensUpdated 16 days ago
    DevOps & CloudAuto-check passed
  • Aspire Diagnostics

    exceptionless/Exceptionless

    Inspect local Aspire resource health, logs, traces, and browser telemetry.

    2.5k GitHub stars~769 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Proto Backend Module

    aide-family/moon

    Implements backend modules from proto definitions for goddess, marksman, and rabbit apps.

    253 GitHub stars~4.1k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Create and manage Kibana alerting rules via REST API or Terraform.

    405 GitHub stars~1.8k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated 2 days ago
    Auto-check passed

Works with

Categories

Questions about Kibana Alerting Rules

What does Kibana Alerting Rules do?

Create and manage Kibana alerting rules. An agent skill from elastic/agent-skills. Kibana Alerting Rules is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana alerting rules.

When should I use Kibana Alerting Rules?

Kibana Alerting Rules fits situations like: managing rule lifecycle (enable; choosing metric threshold rule types and params; read-only find/list with tag filters.

How do I install Kibana Alerting Rules in Claude Code?

Run `npx skills add elastic/agent-skills --skill kibana-alerting-rules -a claude-code`. Or copy the skill folder (skills/kibana/kibana-alerting-rules in elastic/agent-skills) into .claude/skills/kibana-alerting-rules in your project. Claude Code loads it when a task matches its description.

How do I install Kibana Alerting Rules in Codex?

Run `npx skills add elastic/agent-skills --skill kibana-alerting-rules -a codex`. Or copy the skill folder (skills/kibana/kibana-alerting-rules in elastic/agent-skills) into .agents/skills/kibana-alerting-rules in your project. Codex loads it when a task matches its description.

Can I use Kibana Alerting Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill kibana-alerting-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-alerting-rules, .gemini/skills/kibana-alerting-rules, .github/skills/kibana-alerting-rules and .opencode/skills/kibana-alerting-rules in your project.

What does Kibana Alerting Rules need to run?

SKILL.md names no scripts, command-line tools or credentials: Kibana Alerting Rules is instructions for the agent only. Compatibility (from SKILL.md): Kibana 8.x or 9.x with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless; some rule types and features are version- or license-gated (for example, rule-level flapping is GA in 9.3). Requires the `elastic` CLI ≥ 0.2 with `stack kb` support..

Does Kibana Alerting Rules access the network?

SKILL.md names 2 domains. As links in the text: elastic.co and github.com. This is read from the text; nothing was executed.

Is Kibana Alerting Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kibana Alerting Rules use?

Kibana Alerting Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kibana Alerting Rules use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Kibana Alerting Rules?

Skills that share tags, products or a category with Kibana Alerting Rules: UI Architect (openobserve/openobserve, 22k stars), Ecs Rfc Guide (elastic/ecs, 1.1k stars), UModel Root Cause Analysis (alibaba/UnifiedModel, 415 stars) and Aspire Diagnostics (exceptionless/Exceptionless, 2.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kibana Alerting Rules?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.