Amazon Opensearch Service
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
Elastic ML anomaly detection — investigation/RCA, score explanation, job lifecycle troubleshooting, and job operations.
$ npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install elastic/agent-skills kibana-anomaly-detection --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kibana/kibana-anomaly-detection .claude/skills/kibana-anomaly-detection && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "kibana-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-anomaly-detection into .claude/skills/kibana-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-anomaly-detection", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-anomaly-detectionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install elastic/agent-skills kibana-anomaly-detection --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/kibana/kibana-anomaly-detection .agents/skills/kibana-anomaly-detection && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "kibana-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-anomaly-detection into .agents/skills/kibana-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-anomaly-detection", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install elastic/agent-skills kibana-anomaly-detection --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/kibana/kibana-anomaly-detection .cursor/skills/kibana-anomaly-detection && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "kibana-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-anomaly-detection into .cursor/skills/kibana-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-anomaly-detection", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/elastic/agent-skills.git --path skills/kibana/kibana-anomaly-detection--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install elastic/agent-skills kibana-anomaly-detection --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/kibana/kibana-anomaly-detection .gemini/skills/kibana-anomaly-detection && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "kibana-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-anomaly-detection into .gemini/skills/kibana-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-anomaly-detection", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install elastic/agent-skills kibana-anomaly-detectionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/kibana/kibana-anomaly-detection .github/skills/kibana-anomaly-detection && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "kibana-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-anomaly-detection into .github/skills/kibana-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-anomaly-detection", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install elastic/agent-skills kibana-anomaly-detection --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/kibana/kibana-anomaly-detection .opencode/skills/kibana-anomaly-detection && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "kibana-anomaly-detection" agent skill from https://github.com/elastic/agent-skills/tree/main/skills/kibana/kibana-anomaly-detection into .opencode/skills/kibana-anomaly-detection/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "kibana-anomaly-detection", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
kibana-anomaly-detectionElastic ML anomaly detection — investigation/RCA, score explanation, job lifecycle troubleshooting, and job operations.
Kibana Anomaly Detection is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Elastic ML anomaly detection — investigation/RCA, score explanation, job lifecycle troubleshooting, and job operations. Use when answering "what broke?"/"which entity?"/RCA, "why is score high/low?"/renormalization, "datafeed stopped"/"memory limit"/hardlimit, or configuring ML anomaly detection jobs. Reads results from .ml-anomalies- and job state from ML REST APIs.
Its SKILL.md is about 6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files (for example `references/README.md`, `references/agent-builder-companion.md` and `references/anomaly-detection-functions.md`). Compatibility notes: Elasticsearch 8.x–9.x or Elastic Cloud Serverless with ML anomaly detection; Kibana 8.x–9.x for saved-object context only
It sits in Data & Analytics, covering Anomaly detection and REST APIs. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Elasticsearch 8.x–9.x or Elastic Cloud Serverless with ML anomaly detection; Kibana 8.x–9.x for saved-object context only
From compatibility in the SKILL.md frontmatter.
Kibana Anomaly Detection loads about 6k tokens when it runs, and up to ~21k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 2,001 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 2,001 words, ~6,027 tokens.
.claude/skills/kibana-anomaly-detection/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.Expert process for ML anomaly detection: attribute incidents to entities, explain scores and model behavior, diagnose
job lifecycle failures, and manage jobs. Read anomaly results from POST /.ml-anomalies-*/_search (Serverless-safe)
and job/datafeed state from ML REST APIs. When the user embeds fixture evidence (influencer rows, job stats) in the
prompt, apply the judgment below directly — do not re-fetch fields already supplied.
<!-- begin-partial: preamble -->
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
<!-- end-partial: preamble -->
| User intent | Mode |
|---|---|
| "What broke?" / RCA / cross-job / blast radius / influencers / log categories | Investigate |
| "Why score high/low?" / renormalization / model bounds / forecasts | Explain |
| Missing docs / memory limit / datafeed stopped / lifecycle / calendars | Troubleshoot |
| Create a job / configure a datafeed / start analysis / retrieve results | Manage |
| Security framing (attack chains, MITRE, exfil) | Investigate + references/security-anomaly-expert.md |
| Observability/SRE framing (degradation, capacity, deployment regression) | Investigate + references/observability-anomaly-expert.md |
When a question spans modes: Investigate → Explain → Troubleshoot. Finish one mode before blending logic.
Serverless note: Legacy
/_ml/anomaly_detectors/{job_id}/results/*endpoints return HTTP 410 in Serverless. Always query.ml-anomalies-*viaPOST /.ml-anomalies-*/_searchwithresult_typefilters.
record_score bands: >75 critical · 50–75 warning · 25–50 minor · <25 informationalmulti_bucket_impact ≥ 3 → sustained shift (not a transient spike)initial_record_score >> record_score → renormalization (model saw worse anomalies later)actual << typical with count/low_count/low_mean → absence/outage, not just a low valueFull score definitions, renormalization mechanics, and
anomaly_score_explanationcomponents: references/score-reference.md.
Treat .ml-anomalies-* as layered result types via result_type in search queries:
result_type | Scope | Key fields |
|---|---|---|
bucket | Time window | anomaly_score, initial_anomaly_score, timestamp |
record | Detector row | record_score, initial_record_score, actual, typical, anomaly_score_explanation |
influencer | Entity × bucket | influencer_field_name, influencer_field_value, influencer_score |
model_plot | Bounds | model_lower, model_upper, actual |
category_definition | Log patterns | category_id, terms, regex, examples |
Read scores this way:
anomaly_score / record_score = current normalized values (move as the model sees new extremes).initial_anomaly_score / initial_record_score = immutable snapshots from detection time.influencer_score ranks entity responsibility within a bucket — the highest score is the primary suspect, not the
bucket-level anomaly_score alone.partition_field_value / by_field_value / over_field_value.multi_bucket_impact (-5 to +5) to separate single-bucket spikes from sustained trends.When: "what broke?", "which entity caused this?", cross-job correlation, blast radius, attack/cascade chains.
Discover jobs. Call GET /_ml/anomaly_detectors when the job ID is unknown. Call
GET /_ml/anomaly_detectors/{job_id} and GET /_ml/datafeeds/datafeed-{job_id} to learn source indices, entity
fields (by_field_name, over_field_name, partition_field_name), and bucket_span. The decision: identify the
related job group — jobs sharing a datafeed index or entity field monitor the same system from different angles.
Scope the incident window. Call POST /.ml-anomalies-*/_search with result_type: bucket, a time range, and
optional minimum anomaly_score. The decision: fix the incident start/end and count how many jobs co-fire in that
window. Low scores across many jobs simultaneously often indicate a systemic root cause.
Attribute to entities (critical for RCA). For the anomalous bucket timestamp, call
POST /.ml-anomalies-*/_search with result_type: influencer, the job ID(s), and the bucket time range. Sort by
influencer_score descending. The decision: name the entity with the highest influencer_score as the
likely cause — it ranks how unusual each entity is in that bucket. Do not restate only the bucket anomaly_score
without attributing responsibility. Recommend drilling into that entity's records next.
Cross-job confirmation. Re-query influencers (or bucket records) across related job IDs for the same entity values and time window. Entities anomalous in 2+ jobs are prime suspects (resource fault or systemic failure); single-job entities are often downstream victims. See references/protocols/investigation.md.
Drill into records. Call POST /.ml-anomalies-*/_search with result_type: record, exact job ID, entity filters
(partition_field_value, by_field_value), and low minimum record_score (25 or lower). Read
multi_bucket_impact ≥ 3 as sustained behavioral shift. Read actual vs typical for fault class (spike vs
absence/outage).
Confirm with source evidence. Call POST /{index}/_search on the datafeed source index for the suspect entity
and time window. Raw source documents are ground truth — never close an RCA without them.
Synthesize. Report: root cause entity · affected jobs · temporal progression · fault class · severity · recommended actions. Worked walkthrough: references/worked-example.md. Query templates: references/investigation-queries.md.
influencer_score, not anomaly_score, for "which entity?" — bucket score is aggregate; influencer
score attributes cause.multi_bucket_impact ≥ 3 = sustained behavioral shift, weight higher than transient spikes.When: "why is my score 30/90?", "score dropped overnight", "what is renormalization?", "why wasn't this detected?".
Decide fetch vs interpret. If the user supplies a record with record_score, initial_record_score, actual,
and typical, interpret directly. Otherwise load config with GET /_ml/anomaly_detectors/{job_id} and records with
POST /.ml-anomalies-*/_search (result_type: record).
Always show both initial_record_score and record_score. The gap is the renormalization story. Large positive
drift (initial_record_score >> record_score) means a later, more extreme anomaly rescale this record downward —
expected healthy behavior, not a broken model.
Classify the pattern before speculating.
| Pattern | Interpretation |
|---|---|
initial_record_score >> record_score | Renormalization — explain before suggesting config changes |
actual << typical with low_count/count/low_mean | Absence/outage anomaly — investigate the outage, not score tuning |
high_variance_penalty: true in anomaly_score_explanation | Noisy metric — wide bounds absorbed the spike |
incomplete_bucket_penalty: true | Ingest lag or sparse bucket — score legitimately reduced |
Only cite anomaly_score_explanation factors present in the record.
Quantify renormalization (optional). Re-query records sorted by timestamp; compute
score_drift = initial_record_score - record_score and flag large drift.
Add visual context when needed. If model_plot_config.enabled, query result_type: model_plot and compare
actual to model_lower/model_upper. For categorization jobs, query result_type: category_definition.
Check job health when scores look wrong persistently. Call GET /_ml/anomaly_detectors/{job_id}/_stats —
model_size_stats.memory_status of hard_limit corrupts learning and can invalidate scores. Escalate to
Troubleshoot mode.
anomaly_score_explanation components| Component | Effect | What it means |
|---|---|---|
anomaly_length | ↑ score | More consecutive anomalous buckets |
single_bucket_impact | ↑ score | Lower probability → higher impact |
multi_bucket_impact | ↑ score | Sustained pattern contribution |
anomaly_characteristics_impact | ↑ score | Mean shift vs. variance change |
high_variance_penalty | ↓ score | Noisy data → wide bounds → anomaly less surprising |
incomplete_bucket_penalty | ↓ score | Bucket has less data than expected (ingest lag, sparse data) |
actual << typical with count/low_count is an absence anomaly — distinguish outages from value spikes.When: "missing documents", "datafeed stopped", hard_limit, "results look wrong", lifecycle changes.
Load job and datafeed state. Call GET /_ml/anomaly_detectors/{job_id}/_stats and
GET /_ml/datafeeds/datafeed-{job_id}/_stats. Read state, data_counts, model_size_stats, and datafeed
state. If the user embeds stats JSON, diagnose from memory_status and datafeed state directly.
Diagnose memory status first (critical). Inspect model_size_stats:
| Field | Meaning |
|---|---|
memory_status | ok / soft_limit (pruning) / hard_limit (critical) |
model_bytes | Current memory used |
model_bytes_memory_limit | Configured model_memory_limit |
When memory_status is hard_limit and model_bytes equals model_bytes_memory_limit, the model hit its
memory ceiling — it stops learning new entities and results degrade or stop. A stopped datafeed is often a
symptom, not the root cause. Do not recommend only restarting the datafeed — that alone does not clear a hard
limit.
Remediate hard_limit. The fix is to raise model_memory_limit (via job update) and/or reduce model size
by lowering cardinality (fewer partition/by/over field values, split into multiple jobs). Raising the limit requires
the lifecycle sequence below (stop datafeed → close job → update → open → start). Optionally call
POST /_ml/anomaly_detectors/_estimate_model_memory to size the new limit from source cardinality.
Diagnose missing documents / query timing. After memory is healthy, inspect datafeed query_delay and
delayed_data_check_config via GET /_ml/datafeeds/datafeed-{job_id}. Search .ml-annotations-* for delayed-data
events. Set query_delay to P95 ingest latency + buffer (default 60s–120s).
Read job messages. Search .ml-notifications-* for the job ID when errors are unclear.
Recover corrupted model state. Call POST /_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_revert
to revert to a known-good snapshot when the model was corrupted during hard_limit.
Apply in order — skipping steps causes rejected updates:
POST /_ml/datafeeds/datafeed-{job_id}/_stopPOST /_ml/anomaly_detectors/{job_id}/_closePOST /_ml/anomaly_detectors/{job_id}/_update (memory limit) and/or POST /_ml/datafeeds/datafeed-{job_id}/_update
(query_delay)POST /_ml/anomaly_detectors/{job_id}/_openPOST /_ml/datafeeds/datafeed-{job_id}/_startPreview changes with POST /_ml/datafeeds/datafeed-{job_id}/_preview before restarting.
hard_limitcorrupts model state and causes downstream missing-doc false alarms. Fix memory before fixingquery_delay. Full troubleshooting detail: references/troubleshooting-reference.md.
memory_status — not generic "restart it" advice.query_delay — hard_limit invalidates downstream diagnostics.When: "set up a job", "create an ML detector", "monitor X over time".
For the full create/open/start lifecycle, prefer the elasticsearch-anomaly-detection skill. This mode summarizes the
sequence and detector selection:
GET /{index}/_mapping — confirm time field and detector fields exist.PUT /_ml/anomaly_detectors/{job_id} with analysis_config (detectors, bucket_span,
influencers) and data_description.time_field.PUT /_ml/datafeeds/datafeed-{job_id} with indices, query, and query_delay.POST /_ml/anomaly_detectors/{job_id}/_open, then
POST /_ml/datafeeds/datafeed-{job_id}/_start.GET /_ml/anomaly_detectors/{job_id}/_stats and GET /_ml/datafeeds/datafeed-{job_id}/_stats.Choose detector functions from user intent — see references/anomaly-detection-functions.md. Worked JSON bodies: references/job-creation-recipes.md.
query_delay = P95 ingest latency + buffer (60s–120s safe default).by_field_name vs over_field_name: by compares entity to its own history; over compares to peer group.over_field_name cannot be forecasted.RCA: "Something caused a spike in checkout latency — which entity?" → Query influencers for the bucket → web-07
has highest influencer_score (91.5) vs 22.0 and 8.4 → name web-07 as likely cause → recommend drilling into its
records — do not answer with only bucket anomaly_score 88.
Score drop: "Score went from 90 to 55 — did the model change?" → Compare initial_record_score vs record_score →
explain renormalization if drift is large.
Memory limit: "Job shows hard_limit and datafeed stopped." → Diagnose
model_size_stats.memory_status = hard_limit → raise model_memory_limit via close/update/open lifecycle and/or reduce
cardinality — not "just restart the datafeed".
New job: "Detect unusual error rates per host." → high_count with by_field_name: host.keyword →
create/open/start sequence.
influencer_score, not bucket anomaly_score.memory_status before recommending datafeed restarts.initial_record_score alongside record_score — the gap tells the renormalization story.query_delay. Hard_limit invalidates downstream diagnostics.| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET /{index}/_mapping | elastic es indices get-mapping --index '<index>' |
POST /{index}/_search | elastic es search --index '<index>' --input-file '<search-body.json>' |
GET /_ml/anomaly_detectors | elastic es ml get-jobs |
GET /_ml/anomaly_detectors/{job_id} | elastic es ml get-jobs --job-id '<job_id>' |
GET /_ml/anomaly_detectors/{job_id}/_stats | elastic es ml get-job-stats --job-id '<job_id>' |
GET /_ml/datafeeds/datafeed-{job_id} | elastic es ml get-datafeeds --datafeed-id 'datafeed-<job_id>' |
GET /_ml/datafeeds/datafeed-{job_id}/_stats | elastic es ml get-datafeed-stats --datafeed-id 'datafeed-<job_id>' |
POST /.ml-anomalies-*/_search | elastic es search --index '.ml-anomalies-*' --input-file '<search-body.json>' |
POST /.ml-annotations-*/_search | elastic es search --index '.ml-annotations-*' --input-file '<search-body.json>' |
POST /.ml-notifications-*/_search | elastic es search --index '.ml-notifications-*' --input-file '<search-body.json>' |
POST /_ml/anomaly_detectors/_estimate_model_memory | elastic es ml estimate-model-memory --analysis-config '<json>' |
PUT /_ml/anomaly_detectors/{job_id} | elastic es ml put-job --job-id '<job_id>' --input-file '<job-body.json>' |
PUT /_ml/datafeeds/datafeed-{job_id} | elastic es ml put-datafeed --datafeed-id 'datafeed-<job_id>' --input-file '<datafeed-body.json>' |
POST /_ml/anomaly_detectors/{job_id}/_open | elastic es ml open-job --job-id '<job_id>' |
POST /_ml/anomaly_detectors/{job_id}/_close | elastic es ml close-job --job-id '<job_id>' |
POST /_ml/anomaly_detectors/{job_id}/_update | elastic es ml update-job --job-id '<job_id>' --analysis-limits '<json>' |
POST /_ml/datafeeds/datafeed-{job_id}/_update | elastic es ml update-datafeed --datafeed-id 'datafeed-<job_id>' --input-file '<update-body.json>' |
POST /_ml/datafeeds/datafeed-{job_id}/_start | elastic es ml start-datafeed --datafeed-id 'datafeed-<job_id>' |
POST /_ml/datafeeds/datafeed-{job_id}/_stop | elastic es ml stop-datafeed --datafeed-id 'datafeed-<job_id>' |
POST /_ml/datafeeds/datafeed-{job_id}/_preview | elastic es ml preview-datafeed --datafeed-id 'datafeed-<job_id>' |
POST /_ml/anomaly_detectors/{job_id}/model_snapshots/{snapshot_id}/_revert | elastic es ml revert-model-snapshot --job-id '<job_id>' --snapshot-id '<snapshot_id>' |
Search body shapes for each result_type and troubleshooting queries are documented in
references/investigation-queries.md and
references/troubleshooting-reference.md.
© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (references) in skills/kibana/kibana-anomaly-detection of elastic/agent-skills.
Open the folder on GitHubat commit baa5111
Kibana Anomaly Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Kibana Anomaly Detection this skillelastic/agent-skills | 592 | — | ~6k | Automated safety check: Pass | Apache-2.0 | |
| Amazon Opensearch Serviceaws/agent-toolkit-for-aws | 2.8k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | |
| Sentinel Ingestion ReportSCStelz/security-investigator | 249 | — | ~16k | Automated safety check: Pass | MIT | |
| TimesFM Forecastinggoogle-research/timesfm | 34k | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Anomalib Adding A Modelopen-edge-platform/anomalib | 6.2k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Anomalib Tiled Ensembleopen-edge-platform/anomalib | 6.2k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
aws/agent-toolkit-for-aws
Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…
SCStelz/security-investigator
Sentinel Ingestion Report — YAML-driven PowerShell pipeline gathers all data via az monitor/az rest/Graph API, writes a deterministic scratchpad, LLM renders the report.
google-research/timesfm
Forecasts any univariate time series zero-shot with Google's TimesFM model, returning point forecasts and calibrated prediction intervals without training.
open-edge-platform/anomalib
Adds a new anomaly-detection model to anomalib under src/anomalib/models/.
open-edge-platform/anomalib
Runs and configures the anomalib tiled-ensemble pipeline, which trains/evaluates one model per image tile and merges results (with optional seam smoothing) for high-resolution anomaly detection.
microsoft/fabric-rti-mcp
KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.
elastic/agent-skills
Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.
elastic/agent-skills
Create, search, update, and manage SOC cases via the Kibana Cases API.
elastic/agent-skills
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).
elastic/agent-skills
Create and manage Kibana Dashboards and Lens visualizations.
elastic/agent-skills
Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.
elastic/agent-skills
Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…
Works with
Categories
Elastic ML anomaly detection — investigation/RCA, score explanation, job lifecycle troubleshooting, and job operations. Kibana Anomaly Detection is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Elastic ML anomaly detection — investigation/RCA, score explanation, job lifecycle troubleshooting, and job operations.
Kibana Anomaly Detection fits situations like: answering what broke?/which entity?/RCA; why is score high/low?/renormalization; datafeed stopped/memory limit/hardlimit; configuring ML anomaly detection jobs.
Run `npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a claude-code`. Or copy the skill folder (skills/kibana/kibana-anomaly-detection in elastic/agent-skills) into .claude/skills/kibana-anomaly-detection in your project. Claude Code loads it when a task matches its description.
Run `npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a codex`. Or copy the skill folder (skills/kibana/kibana-anomaly-detection in elastic/agent-skills) into .agents/skills/kibana-anomaly-detection in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill kibana-anomaly-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-anomaly-detection, .gemini/skills/kibana-anomaly-detection, .github/skills/kibana-anomaly-detection and .opencode/skills/kibana-anomaly-detection in your project.
SKILL.md names no scripts, command-line tools or credentials: Kibana Anomaly Detection is instructions for the agent only. Compatibility (from SKILL.md): Elasticsearch 8.x–9.x or Elastic Cloud Serverless with ML anomaly detection; Kibana 8.x–9.x for saved-object context only.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Kibana Anomaly Detection is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6k tokens (SKILL.md is roughly 24k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Kibana Anomaly Detection: Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars), Sentinel Ingestion Report (SCStelz/security-investigator, 249 stars), TimesFM Forecasting (google-research/timesfm, 34k stars) and Anomalib Adding A Model (open-edge-platform/anomalib, 6.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.
Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.