Official agent skill

Kibana Dashboards

by elastic in elastic/agent-skills

Create and manage Kibana Dashboards and Lens visualizations.

OfficialApache-2.0Auto-check passedDevelopment

Install Kibana Dashboards

skills CLI
$ npx skills add elastic/agent-skills --skill kibana-dashboards -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills kibana-dashboards --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kibana/kibana-dashboards .claude/skills/kibana-dashboards && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kibana-dashboards
GitHub stars
592
Used in
1 other repo
Token cost
~3.7k tokens
SKILL.md length
1,244 words
Files
12 (incl. references, assets)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Create and manage Kibana Dashboards and Lens visualizations.

  • Works in 7 steps: Verify Kibana connectivity. Call GET… → Classify the task. Decide whether the… → Choose the dataset type before building… → …
  • You need to define dashboards and visualizations declaratively
  • SKILL.md covers Environment Configuration, Prerequisites, Process and Dashboard grid, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kibana Dashboards is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana Dashboards and Lens visualizations. Use when you need to define dashboards and visualizations declaratively, version control them, or automate their deployment.

Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including reference files and assets (for example `assets/bar-chart-esql.json`, `assets/dashboard-basic.json` and `assets/dashboard-with-visualizations.json`). Compatibility notes: Kibana 9.4 or later (Dashboards and Visualizations APIs) with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless…

It sits in Development, covering Git workflow. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • You need to define dashboards and visualizations declaratively
  • Version control them
  • Automate their deployment

Example prompts

  • “/kibana-dashboards”

Requirements

  • Compatibility (from SKILL.md): Kibana 9.4 or later (Dashboards and Visualizations APIs) with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless. Requires the `elastic` CLI ≥ 0.3 with `stack kb` support (dedicated `dashboards` and `visualizations` commands).

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Verify Kibana connectivity. Call GET kbn:/api/status. If the call fails, stop and surface the error — do not
  2. Classify the task. Decide whether the user needs a dashboard (collection of panels, optional time range), a
  3. Choose the dataset type before building metrics or layers.
  4. Build a dashboard body when creating or updating dashboards. The request body is flat — title, panels, and
  5. Build a standalone Lens visualization when the user asks for a library chart. Use the Visualizations API. Upsert
  6. Execute and confirm. Perform the write with PUT kbn:/api/dashboards/{id} or PUT kbn:/api/visualizations/{id}
  7. List, export, or delete when requested. Call GET kbn:/api/dashboards or GET kbn:/api/visualizations to

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json and esql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Kibana 9.4 or later (Dashboards and Visualizations APIs) with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless. Requires the `elastic` CLI ≥ 0.3 with `stack kb` support (dedicated `dashboards` and `visualizations` commands).

    From compatibility in the SKILL.md frontmatter.

Context cost

Kibana Dashboards loads about 3.7k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 51 tokens; SKILL.md has 1,244 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~3.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,244 words, ~3,705 tokens.

Download SKILL.mdSave it as .claude/skills/kibana-dashboards/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.
name
kibana-dashboards
description
Create and manage Kibana Dashboards and Lens visualizations. Use when you need to define dashboards and visualizations declaratively, version control them, or automate their deployment.
compatibility
Kibana 9.4 or later (Dashboards and Visualizations APIs) with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless. Requires the `elastic` CLI ≥ 0.3 with `stack kb` support (dedicated `dashboards` and `visualizations` commands).
metadata.author
elastic
metadata.version
0.3.0
metadata.universal
true

Kibana Dashboards and Lens Visualizations

Create, update, and delete Kibana dashboards and standalone Lens visualizations using the Kibana 9.4+ Dashboards and Visualizations APIs. Produce minimal, diffable JSON bodies; prefer inline panel definitions over library references; and choose the correct dataset type (data view vs ES|QL) before writing metrics or chart layers.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

Prerequisites

Version requirement: Kibana 9.4+ (Dashboards and Visualizations APIs).

ES|QL placement:

  • Standalone library charts: PUT kbn:/api/visualizations/{id} with data_source.type: "esql".
  • ES|QL panels embedded in a dashboard: inline vis panel config with data_source.type: "esql" via PUT kbn:/api/dashboards/{id}.
  • Do not use data_source.type: "data_view_reference" or index-pattern aggregations when the user explicitly requests ES|QL — the persisted Lens state must use a text-based ES|QL datasource (textBased / esql), not a data-view count operation.

Process

  1. Verify Kibana connectivity. Call GET kbn:/api/status. If the call fails, stop and surface the error — do not guess endpoints or credentials. Read version.number to confirm the cluster meets the 9.4+ requirement.

  2. Classify the task. Decide whether the user needs a dashboard (collection of panels, optional time range), a standalone Lens visualization (library item referenced by id or used alone), or both. Determine whether a deterministic saved-object id was supplied — when given, use upsert (PUT) with that id rather than POST (which auto-generates ids).

  3. Choose the dataset type before building metrics or layers.

    User intentDatasetMetric / axis pattern
    Simple count or aggregation on a saved data viewdata_source.type: "data_view_reference" with ref_idmetrics: [{ type: "primary", operation: "count" }] (or other aggregation operations)
    Ad-hoc index patterndata_source.type: "data_view_spec" with index_pattern and time_fieldSame aggregation operation fields
    ES|QL query (explicit or complex logic)data_source.type: "esql" with querymetrics: [{ type: "primary", column: "<alias>" }] or layer axes { column: "<alias>" } — never operation: "count" on the metric

    Write the aggregation in the ES|QL query (STATS count = COUNT()), then reference the resulting column by name.

  4. Build a dashboard body when creating or updating dashboards. The request body is flat — title, panels, and optional time_range at the root. Do not wrap in { data: ... } on write. Required fields:

    • title — exact string the user requested.
    • panels — array; use [] when the user asks for an empty dashboard (do not omit the key or invent panels).
    • time_range — when the user specifies a default time filter, set { "from": "<expr>", "to": "<expr>" } (for example { "from": "now-7d", "to": "now" }). Supplying time_range persists the dashboard time filter on open (equivalent to enabling time restore in the UI).

    Upsert with a deterministic id:

    json
    {
      "title": "Sales Overview",
      "panels": [],
      "time_range": { "from": "now-7d", "to": "now" }
    }

    Call PUT kbn:/api/dashboards/eval-sales-overview with the body above when the user supplies that id.

    Inline ES|QL metric panel example (inside panels):

    json
    {
      "type": "vis",
      "id": "total-requests",
      "grid": { "x": 0, "y": 0, "w": 12, "h": 6 },
      "config": {
        "title": "Total Requests",
        "type": "metric",
        "data_source": {
          "type": "esql",
          "query": "FROM logs* | STATS count = COUNT()"
        },
        "metrics": [{ "type": "primary", "column": "count" }]
      }
    }

    Prefer inline config properties over config.ref_id for portable dashboards. Read Dashboard API Reference for panel types, grid layout, and copy workflows.

  5. Build a standalone Lens visualization when the user asks for a library chart. Use the Visualizations API. Upsert with PUT kbn:/api/visualizations/{id} when an id is supplied; otherwise POST kbn:/api/visualizations and report the generated id from the response.

    ES|QL metric (total count from logs):

    json
    {
      "type": "metric",
      "title": "Total Requests",
      "data_source": {
        "type": "esql",
        "query": "FROM logs* | STATS count = COUNT()"
      },
      "metrics": [{ "type": "primary", "column": "count" }]
    }

    Call PUT kbn:/api/visualizations/eval-total-requests when that id is required. The API persists a Lens saved object whose datasource state uses ES|QL (textBased / esql), not an index-pattern aggregation.

    Read Lens API Reference and Chart Types Reference for xy, gauge, heatmap, and other chart schemas.

  6. Execute and confirm. Perform the write with PUT kbn:/api/dashboards/{id} or PUT kbn:/api/visualizations/{id} (or POST when no id is supplied). Confirm with GET kbn:/api/dashboards/{id} or GET kbn:/api/visualizations/{id}. Report the id and title back to the user — do not claim success without a successful read-back.

  7. List, export, or delete when requested. Call GET kbn:/api/dashboards or GET kbn:/api/visualizations to discover existing objects. Call DELETE kbn:/api/dashboards/{id} or DELETE kbn:/api/visualizations/{id} to remove objects. For bulk export or import of saved objects, call POST kbn:/api/saved_objects/_export or POST kbn:/api/saved_objects/_import.

Show full SKILL.md (552 more words)Show less

Dashboard grid

Dashboards use a 48-column grid. On 16:9 screens, roughly 20–24 rows fit above the fold — target 8–12 panels in that band.

WidthColumnsHeight (rows)Use case
Full4814–16Wide time series, tables
Half2410–12Primary charts
Quarter125–6KPI metrics
Sixth84–5Dense metric rows

Grid packing: When stacking rows, set the next panel's y to the previous panel's y + h. Panels sharing a row should use the same h. Do not add markdown panels as dashboard titles — use descriptive chart titles instead.

ES|QL patterns

Time series bucket (dashboard time picker injects ?_tstart / ?_tend):

esql
FROM logs*
| WHERE @timestamp <= ?_tend AND @timestamp > ?_tstart
| STATS count = COUNT() BY BUCKET(@timestamp, 75, ?_tstart, ?_tend)

Set "scale": "temporal" on the x-axis for time-series xy charts. See Chart Types Reference for axis and layer details.

Static reference values — use EVAL in the query, then reference the column:

esql
FROM logs* | STATS count = COUNT() | EVAL goal = 15000

Examples

Example JSON definitions live under assets/: demo-dashboard.json, dashboard-with-visualizations.json, metric-esql.json, bar-chart-esql.json, line-chart-timeseries.json.

Guidelines

  1. Match the user's id and title exactly when supplied — do not substitute auto-generated ids.
  2. Honor empty panels — when the user asks for panels: [], send an empty array; do not add placeholder panels.
  3. ES|QL when requested — use data_source.type: "esql" and column references; never satisfy an ES|QL request with operation: "count" on a data view.
  4. Minimal payloads — omit derivable defaults; let the API inject styling and metadata.
  5. Confirm writes — always read back with GET after create or update.
  6. Read references before complex charts — metric and xy schemas differ between data view and ES|QL; consult Chart Types Reference before generating partition or table charts.

Common issues

ErrorLikely causeFix
404 on GET after PUTWrong id or spaceConfirm id and retry GET kbn:/api/dashboards/{id}
400 validationES|QL column mismatchAlign metrics[].column / layer column with STATS aliases in the query
ES|QL panel saved as data viewWrong dataset typeUse data_source.type: "esql", not data_view_reference
Empty dashboard missing time filterOmitted time_rangeInclude { "from": "now-7d", "to": "now" } when a default range is required
XY chart failureMissing layer data_sourcePut data_source inside each layer, not only at the root

Operations

As of CLI v0.3.0 the Dashboards and Visualizations APIs have dedicated elastic kb dashboards and elastic kb visualizations commands for listing, reading, updating, and deleting objects by id. The create-*-redirect commands do not accept a request body yet, so to write a new object supply an id and use the update-*-redirect (PUT) command, which carries the JSON body via --input-file. To author several objects at once, build a saved-object NDJSON and import it with post-saved-objects-import (read it back with post-saved-objects-export).

HTTP API (shorthand)elastic CLI command
GET kbn:/api/statuselastic kb system get-status
POST kbn:/api/saved_objects/_importelastic kb saved-objects post-saved-objects-import --file '<path.ndjson>' --overwrite
POST kbn:/api/saved_objects/_exportelastic kb saved-objects post-saved-objects-export --objects '[{"type":"<type>","id":"<id>"}]'
GET kbn:/api/dashboardselastic kb dashboards get-dashboards-redirect
GET kbn:/api/dashboards/{id}elastic kb dashboards get-dashboard-redirect --id '<id>'
PUT kbn:/api/dashboards/{id}elastic kb dashboards update-dashboard-redirect --id '<id>' --input-file '<path.json>'
DELETE kbn:/api/dashboards/{id}elastic kb dashboards delete-dashboard-redirect --id '<id>'
POST kbn:/api/dashboards (no id)create-dashboard-redirect takes no body yet — supply an id and use update-dashboard-redirect, or author via post-saved-objects-import (type dashboard)
GET kbn:/api/visualizationselastic kb visualizations get-visualizations-redirect
GET kbn:/api/visualizations/{id}elastic kb visualizations get-visualization-redirect --id '<id>'
PUT kbn:/api/visualizations/{id}elastic kb visualizations update-visualization-redirect --id '<id>' --input-file '<path.json>'
DELETE kbn:/api/visualizations/{id}elastic kb visualizations delete-visualization-redirect --id '<id>'
POST kbn:/api/visualizations (no id)create-visualization-redirect takes no body yet — supply an id and use update-visualization-redirect, or author via post-saved-objects-import (type lens)

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 11 other files (references, assets) in skills/kibana/kibana-dashboards of elastic/agent-skills.

  • SKILL.md
  • assets/bar-chart-esql.json
  • assets/dashboard-basic.json
  • assets/dashboard-with-visualizations.json
  • assets/datatable.json
  • assets/demo-dashboard.json
  • assets/ecommerce-analytics-dashboard.json
  • assets/line-chart-timeseries.json
  • assets/metric-esql.json
  • references/chart-types-reference.md
  • references/dashboard-api-reference.md
  • references/lens-api-reference.md

Open the folder on GitHubat commit baa5111

Used in 1 other repository

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in elastic/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Kibana Dashboards next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kibana Dashboards compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kibana Dashboards this skillelastic/agent-skills5921 repos~3.7kAutomated safety check: PassApache-2.0
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Contributor-First PR MergeHKUDS/OpenHarness16k1 repos~847Automated safety check: PassMIT
Migrate Internal Package into GhostTryGhost/Ghost56k—~3.8kAutomated safety check: PassMIT
Create Pull Requestcline/cline70k1 repos~1.6kAutomated safety check: PassApache-2.0
Contextual Commit Messagesyamadashy/repomix29k1 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Merges external GitHub pull requests while keeping the original author credited, and fixes conflicts after the merge instead of rewriting the contribution.

    16k GitHub starsUsed in 1 repo~847 tokens
    DevelopmentAuto-check passed
  • Moves a package from another TryGhost repository into Ghost as an internal workspace package while keeping its Git history, with checkpoints for the steps that need an administrator.

    56k GitHub stars~3.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Opens a GitHub pull request from your current branch with the gh CLI, after reviewing the commits and diff and gathering the details the PR needs.

    70k GitHub starsUsed in 1 repo~1.6k tokens
    DevelopmentAuto-check passed
  • Writes Conventional Commits whose bodies carry action lines recording the intent, decisions and constraints behind a change, not only what changed.

    29k GitHub starsUsed in 1 repo~2.7k tokens
    DevelopmentAuto-check passed
  • Git Merge Conflict Resolver

    tailcallhq/forgecode

    Resolves Git merge conflicts with a plan-first workflow that keeps both sides' intent, regenerates lock files and backs up deleted-but-modified files.

    7.6k GitHub starsUsed in 1 repo~4.5k tokens
    DevelopmentAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated 3 days ago
    Auto-check passed
  • Official

    Create and manage Elastic ML anomaly detection jobs via the API.

    592 GitHub stars~2.4k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Kibana Dashboards

What does Kibana Dashboards do?

Create and manage Kibana Dashboards and Lens visualizations. Kibana Dashboards is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Create and manage Kibana Dashboards and Lens visualizations.

When should I use Kibana Dashboards?

Kibana Dashboards fits situations like: you need to define dashboards and visualizations declaratively; version control them; automate their deployment.

How do I install Kibana Dashboards in Claude Code?

Run `npx skills add elastic/agent-skills --skill kibana-dashboards -a claude-code`. Or copy the skill folder (skills/kibana/kibana-dashboards in elastic/agent-skills) into .claude/skills/kibana-dashboards in your project. Claude Code loads it when a task matches its description.

How do I install Kibana Dashboards in Codex?

Run `npx skills add elastic/agent-skills --skill kibana-dashboards -a codex`. Or copy the skill folder (skills/kibana/kibana-dashboards in elastic/agent-skills) into .agents/skills/kibana-dashboards in your project. Codex loads it when a task matches its description.

Can I use Kibana Dashboards in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill kibana-dashboards -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-dashboards, .gemini/skills/kibana-dashboards, .github/skills/kibana-dashboards and .opencode/skills/kibana-dashboards in your project.

What does Kibana Dashboards need to run?

SKILL.md names no scripts, command-line tools or credentials: Kibana Dashboards is instructions for the agent only. Compatibility (from SKILL.md): Kibana 9.4 or later (Dashboards and Visualizations APIs) with matching Elasticsearch, self-managed, Elastic Cloud Hosted, or Elastic Cloud Serverless. Requires the `elastic` CLI ≥ 0.3 with `stack kb` support (dedicated `dashboards` and `visualizations` commands)..

Does Kibana Dashboards access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Kibana Dashboards safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kibana Dashboards use?

Kibana Dashboards is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kibana Dashboards use?

About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.5k tokens, read only when the agent opens those files.

What are the alternatives to Kibana Dashboards?

Skills that share tags, products or a category with Kibana Dashboards: Finishing a Development Branch (obra/superpowers, 297k stars), Contributor-First PR Merge (HKUDS/OpenHarness, 16k stars), Migrate Internal Package into Ghost (TryGhost/Ghost, 56k stars) and Create Pull Request (cline/cline, 70k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kibana Dashboards?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.