Official agent skill

Kibana Workflows

by elastic in elastic/agent-skills

Author, validate, test, run, and inspect Elastic Workflow YAML definitions.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Kibana Workflows

skills CLI
$ npx skills add elastic/agent-skills --skill kibana-workflows -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/agent-skills kibana-workflows --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kibana/kibana-workflows .claude/skills/kibana-workflows && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kibana-workflows
GitHub stars
592
Token cost
~4.8k tokens
SKILL.md length
1,779 words
Files
8 (incl. references)
Skills in repo
26
Repo updated
First seen
Licence
Apache-2.0

At a glance

Author, validate, test, run, and inspect Elastic Workflow YAML definitions.

  • Works in 5 steps: Capture the user's intent before writing… → Look up only what you'll use. For the… → Draft the whole workflow in one pass. A… → …
  • The user wants to turn natural language into a Kibana workflow
  • SKILL.md covers Environment Configuration, Pick the authoring path, Guidelines (all paths) and Discovery-tools path, plus 5 more sections
  • Calls python3

What it does

Kibana Workflows is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Author, validate, test, run, and inspect Elastic Workflow YAML definitions. Use when the user wants to turn natural language into a Kibana workflow, fix workflow YAML, understand triggers or steps, or run a quick test loop against a real Kibana.

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/demo-test-loop.md`, `references/generation-tips.md` and `references/generator-path.md`). Compatibility notes: Kibana 9.4 or later with matching Elasticsearch and an Enterprise license, or an Elastic Serverless project with Workflows available; requires the elastic CLI…

It sits in DevOps & Cloud, covering CI/CD. It works with Elasticsearch. The repository describes itself as: Official Elastic Skills. The licence is Apache-2.0.

When your agent uses it

  • The user wants to turn natural language into a Kibana workflow
  • Fix workflow YAML
  • Understand triggers
  • Run a quick test loop against a real Kibana

Example prompts

  • “/kibana-workflows”

Requirements

  • Python 3
  • Compatibility (from SKILL.md): Kibana 9.4 or later with matching Elasticsearch and an Enterprise license, or an Elastic Serverless project with Workflows available; requires the `elastic` CLI ≥ 0.2 with `stack kb workflows` support. When Agent Builder is enabled on the target Kibana, the `platform.core.generate_workflow` and `platform.workflows.*` tools are preferred over the raw schema.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Capture the user's intent before writing YAML. Identify, in order, the trigger (manual / scheduled /
  2. Look up only what you'll use. For the specific step types this workflow needs
  3. Draft the whole workflow in one pass. A workflow requires name, at least one trigger, and a non-empty steps
  4. Validate once. Call platform.workflows.validate_workflow with { "yaml": "..." }. On failure it returns
  5. Test, save, and run. See Test / save / run below. Use

What it can do on your machine

Read from SKILL.md and the folder at commit baa5111. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Kibana 9.4 or later with matching Elasticsearch and an Enterprise license, or an Elastic Serverless project with Workflows available; requires the `elastic` CLI ≥ 0.2 with `stack kb workflows` support. When Agent Builder is enabled on the target Kibana, the `platform.core.generate_workflow` and `platform.workflows.*` tools are preferred over the raw schema.

    From compatibility in the SKILL.md frontmatter.

Context cost

Kibana Workflows loads about 4.8k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,779 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from elastic/agent-skills at commit baa5111, republished under its Apache-2.0 licence (© elastic). 1,779 words, ~4,762 tokens.

Download SKILL.mdSave it as .claude/skills/kibana-workflows/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
kibana-workflows
description
Author, validate, test, run, and inspect Elastic Workflow YAML definitions. Use when the user wants to turn natural language into a Kibana workflow, fix workflow YAML, understand triggers or steps, or run a quick test loop against a real Kibana.
compatibility
Kibana 9.4 or later with matching Elasticsearch and an Enterprise license, or an Elastic Serverless project with Workflows available; requires the `elastic` CLI ≥ 0.2 with `stack kb workflows` support. When Agent Builder is enabled on the target Kibana, the `platform.core.generate_workflow` and `platform.workflows.*` tools are preferred over the raw schema.
metadata.author
elastic
metadata.version
0.5.0
metadata.universal
true

Author Elastic Workflows

Create and iterate on Elastic Workflow YAML definitions. Workflows are declarative automations that run inside Kibana: they query Elasticsearch, set data, branch, loop, call connectors, create cases, notify external systems, and invoke AI steps.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

If the user asks only for a draft or explanation and explicitly forbids live access, skip connection verification and do not call the CLI or APIs. State that the draft was not validated against a target deployment.

If workflow APIs are unavailable, report the returned status and message. Common causes are an unsupported Kibana version, insufficient license or feature privileges, or Workflows not being offered on the target project. The workflows:ui:enabled setting controls the Kibana UI; it does not remove the public Workflows APIs.

Pick the authoring path

Default to the Discovery-tools path below — the platform.workflows.* tools are registered by default on Kibana 9.5+ and Serverless. Confirm with one probe: GET kbn:/api/agent_builder/tools returns { "results": [ { "id": ... } ] }; save it to a file and grep for "id": "platform.workflows.". Two fallbacks, both loaded only when needed:

  • No agent_builder endpoint (404) or no platform.workflows.* ids (e.g. Kibana 9.4) → read references/schema-path.md and hand-author from the raw JSON Schema.
  • An LLM connector is wired into Agent Builder and the user prefers Kibana's own generator → read references/generator-path.md.

State which path you picked and why in one sentence before proceeding. Measured path benchmarks live in references/path-performance.md.

Guidelines (all paths)

  • Treat tests as executions. POST kbn:/api/workflows/test runs the workflow graph, and POST kbn:/api/workflows/step/test runs the selected step. Test only when every executed action is read-only or the user authorized its effects. Otherwise test a copy whose writes, notifications, and external calls are replaced with console, then restore the real steps and save the workflow disabled.
  • Cite endpoints in HTTP shorthand, never raw transport. This skill's body refers to operations like POST kbn:/api/workflows/test. The Operations table is the single place where shorthand binds to a concrete CLI command.
  • Prefer purpose-built actions over generic http. For Slack/Jira/PagerDuty/etc., prefer the connector step type (e.g. slack2.sendMessage) over a raw http call. Discover the exact action type via get_step_definitions (or the strict schema on the fallback path).
  • Reference step outputs as steps.<name>.output, never steps.<name>.with.*. Trigger event data is event, never trigger.event or triggers.event.
  • Don't guess connector ids. Call platform.workflows.get_connectors (Discovery-tools path) or GET kbn:/api/workflows/connectors (Schema path), or ask the user. Placeholders should be obviously fake.
  • Handle failure deliberately. Add retry or fallback behavior where the user's requirements call for resilience. Do not add continue: true everywhere: it can hide a failed action and allow the workflow to report false success.
  • Surface gates, don't paper over them. If the API returns 403 ... not available, report the required license or privileges; do not silently retry or blame the UI setting.

Discovery-tools path

Use when platform.workflows.* tools are registered on the target Kibana. All calls go through POST kbn:/api/agent_builder/tools/_execute with { "tool_id": "...", "tool_params": { ... } }. Response shape: { "results": [ { "type": "other", "data": { ... }, "tool_result_id": "..." } ] } — the payload you want is .results[0].data. Send the request body from a file and write the response to a file (see Operations), then jq against that file; do not inline python3 -c on multi-line JSON.

Keep context small; minimize round-trips. Do NOT front-load the whole step catalog — pull only the targeted details you need, keep large tool output in files (not the transcript), and author in as few turns as possible (measured rationale: references/path-performance.md).

  1. Capture the user's intent before writing YAML. Identify, in order, the trigger (manual / scheduled / alert), the inputs the workflow will receive at runtime, the data sources it must read, the actions it must take, and the desired output. If a required dependency is unknown (e.g. a Slack connector id), ask the user or use a clearly-marked placeholder.

  2. Look up only what you'll use. For the specific step types this workflow needs:

    • platform.workflows.get_step_definitions with an exact stepType (e.g. "http", "elasticsearch.esql.query", "slack2.sendMessage"), or with search to browse. The response includes input params, config params, an outputSummary when you pass includeOutputSummary: true, and usage examples. Pass includeFullSchema: true only if the compact summary is insufficient.
    • platform.workflows.get_trigger_definitions for the trigger event schema.
    • platform.workflows.get_connectors to resolve real connector-id values for connector actions.
    • platform.workflows.get_examples when you need a working YAML shape for a pattern.

    Write each response to a file and jq the field you need — don't let full tool output land in the transcript.

  3. Draft the whole workflow in one pass. A workflow requires name, at least one trigger, and a non-empty steps array. Use 2-space indentation. Reference outputs as steps.<name>.output.*. Build the complete YAML in a single edit rather than growing it across many turns.

  4. Validate once. Call platform.workflows.validate_workflow with { "yaml": "..." }. On failure it returns errors + step definitions for referenced step types automatically, so you rarely need a second get_step_definitions call. Fix all reported issues in a single edit, then re-validate.

  5. Test, save, and run. See Test / save / run below. Use platform.workflows.workflow_execute_step to iterate on a single step (with confirmation_body for unsafe steps).

Schema path (last resort)

Only for Kibanas without the platform.workflows.* tools (see the probe above). Full recipe: references/schema-path.md.

Test / save / run

Shared final phase for both paths.

  1. Test only an execution-safe draft. Call POST kbn:/api/workflows/test with the YAML inline as workflowYaml and the run-time inputs. For any workflow that writes / notifies / calls external services, replace those steps with console in the tested copy first, then restore them and save the workflow disabled.

  2. Poll the execution. The response carries a workflowExecutionId. Poll GET kbn:/api/workflows/executions/{executionId} until status is one of completed, failed, cancelled, or timed_out; then fetch GET kbn:/api/workflows/executions/{executionId}/logs for step-by-step output. Only treat status: completed as success.

  3. Save. POST kbn:/api/workflows/workflow with { yaml, id? }. Save side-effecting workflows with enabled: false until the user has authorized a real run. Subsequent edits use PUT kbn:/api/workflows/workflow/{id} and may update yaml, enabled, name, tags, or description (partial updates supported).

  4. Run only when authorized. Enable the workflow, then call POST kbn:/api/workflows/workflow/{id}/run with the same inputs shape used at test time. Inspect via the execution + logs endpoints.

Show full SKILL.md (705 more words)Show less

Workflow YAML Quick Reference

yaml
version: "1"
name: Manual Hello Workflow
description: Logs a hello message from a manual workflow
enabled: true
tags: ["demo", "workflow"]

triggers:
  - type: manual
    inputs:
      properties:
        name:
          type: string
          description: Name to greet
          default: "world"

steps:
  - name: log_hello
    type: console
    with:
      message: "Hello {{ inputs.name }}"

An ordinary action step can use fields like these when its strict schema allows them:

yaml
- name: unique_step_name
  type: step_type
  with:
    param: value
  connector-id: connector-id-for-connector-actions # connector actions only
  if: "steps.previous.output.ok: true"
  timeout: "30s"
  on-failure:
    retry:
      max-attempts: 3
      delay: "5s"
    fallback:
      - name: handle_error
        type: console
        with:
          message: "Step failed"

Use {{ ... }} when rendering text. Use ${{ ... }} when an entire value must retain its native type, for example documents: "${{ steps.search.output.hits.hits }}".

Common step types include:

Step typeUse for
consoleDebug logging during tests
elasticsearch.searchQuery Elasticsearch with Query DSL
elasticsearch.esql.queryQuery Elasticsearch with ES|QL
elasticsearch.bulkBulk indexing
kibana.requestCall a Kibana API
data.setSet values under variables
ifBranch on a KQL-style condition
foreachLoop over a collection
waitPause execution
httpGeneric HTTP requests
workflow.executeRun another saved workflow

This is not an exhaustive compatibility list. On the Discovery-tools path, platform.workflows.get_step_definitions answers "does step X exist and what does it take". On the schema path, GET kbn:/api/workflows/schema?loose=false is the source of truth, and GET kbn:/api/workflows/connectors lists configured connector instances.

data.set stores variables for the current execution; it does not persist durable data. Use an Elasticsearch or Kibana write action when the user asks to retain data after the execution.

Examples

Manual hello (smallest possible draft): "Make a workflow that logs hello." → manual trigger + one console step that prints Hello {{ inputs.name | default: "world" }}. Test with POST kbn:/api/workflows/test. See Demo Test Loop.

Scheduled health check: "Every 5 minutes, ping https://api.example.com/health and log the response." → scheduled trigger (every: 5m) + http step + console. Look up the exact with shape with get_step_definitions("http"). Add bounded retry if requested.

Alert-triggered case + Slack notify: "When a Security alert fires, create a case and post to #soc-incidents." → alert trigger + foreach over event.alerts + connector actions. Use get_step_definitions("cases.createCase") and get_step_definitions(search: "slack") (current fixtures use cases.createCase and slack2.sendMessage), then get_connectors for the real connector-ids. See Workflow Patterns.

For unfamiliar shapes on the schema path, read Workflow Patterns and Generation Tips before drafting.

Operations

The HTTP-shorthand references in the body above bind to the elastic CLI commands below. Multi-line YAML and JSON payloads are easier to pass via --input-file <path> than as inline flags.

Workflows API (both paths).

HTTP API (shorthand)elastic CLI command
GET /elastic es info
GET kbn:/api/workflowselastic stack kb workflows get-workflows
GET kbn:/api/workflows/workflow/{id}elastic stack kb workflows get-workflows-workflow-id --id <id>
POST kbn:/api/workflows/workflowelastic stack kb workflows post-workflows-workflow --input-file <path>
PUT kbn:/api/workflows/workflow/{id}elastic stack kb workflows put-workflows-workflow-id --id <id> --input-file <path>
DELETE kbn:/api/workflows/workflow/{id}elastic stack kb workflows delete-workflows-workflow-id --id <id>
DELETE kbn:/api/workflows/workflow/{id}?force=trueelastic stack kb workflows delete-workflows-workflow-id --id <id> --force true
POST kbn:/api/workflows/testelastic stack kb workflows post-workflows-test --input-file <path>
POST kbn:/api/workflows/workflow/{id}/runelastic stack kb workflows post-workflows-workflow-id-run --id <id> --inputs <json>
POST kbn:/api/workflows/step/testelastic stack kb workflows post-workflows-step-test --input-file <path>
GET kbn:/api/workflows/executions/{executionId}elastic stack kb workflows get-workflows-executions-executionid --execution-id <id>
GET kbn:/api/workflows/executions/{executionId}/logselastic stack kb workflows get-workflows-executions-executionid-logs --execution-id <id>
POST kbn:/api/workflows/executions/{executionId}/cancelelastic stack kb workflows post-workflows-executions-executionid-cancel --execution-id <id>
POST kbn:/api/workflows/executions/{executionId}/resumeelastic stack kb workflows post-workflows-executions-executionid-resume --execution-id <id>
GET kbn:/api/workflows/workflow/{workflowId}/executionselastic stack kb workflows get-workflows-workflow-workflowid-executions --workflow-id <id>
GET kbn:/api/workflows/schema?loose=falseelastic stack kb workflows get-workflows-schema --loose false
GET kbn:/api/workflows/connectorselastic stack kb workflows get-workflows-connectors

Agent Builder tools (Discovery-tools path).

Every tool below is invoked through the same execute endpoint. Pass --input-file a JSON file with { "tool_id": "...", "tool_params": { ... } }.

HTTP API (shorthand)elastic CLI command
GET kbn:/api/agent_builder/toolselastic stack kb agent-builder get-agent-builder-tools
POST kbn:/api/agent_builder/tools/_executeelastic stack kb agent-builder post-agent-builder-tools-execute --input-file <path>

Workflow-relevant tool_ids:

tool_idPurpose
platform.workflows.validate_workflowValidate a YAML string; failure response includes step definitions for referenced step types.
platform.workflows.workflow_execute_stepExecute one step against the real environment (with user confirmation for unsafe steps).
platform.workflows.get_step_definitionsLook up step type params, outputs, examples. stepType for exact match, search for keyword.
platform.workflows.get_trigger_definitionsLook up a trigger's full event schema.
platform.workflows.get_connectorsList connector instances configured on the target.
platform.workflows.get_examplesSearch the bundled example library for working YAML patterns.

Notes.

For post-workflows-test, the input file is JSON of the form { "workflowYaml": "...", "inputs": {} } (or workflowId in place of workflowYaml). For post-workflows-workflow, use { "yaml": "...", "id": "..." } — id is optional. For put-workflows-workflow-id, include only the fields to update from name, enabled, tags, yaml, and description. Deletion is soft by default. Use force=true only when permanent deletion and immediate ID reuse are intended. The Kibana API version is 2023-10-31; the CLI sets it automatically.

When invoking read-only get- commands from a shell that leaves stdin open (some terminals and agent runtimes do this), append </dev/null to avoid an EAGAIN: resource temporarily unavailable crash — e.g. elastic stack kb workflows get-workflows-executions-executionid --execution-id "{id}" </dev/null.

© elastic, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in skills/kibana/kibana-workflows of elastic/agent-skills.

  • SKILL.md
  • references/demo-test-loop.md
  • references/generation-tips.md
  • references/generator-path.md
  • references/path-performance.md
  • references/schema-path.md
  • references/workflow-patterns.md
  • references/workflow-yaml-reference.md

Open the folder on GitHubat commit baa5111

Compare with similar skills

Kibana Workflows next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kibana Workflows compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kibana Workflows this skillelastic/agent-skills592—~4.8kAutomated safety check: PassApache-2.0
Kt Search Releasejillesvangurp/kt-search155—~1.2kAutomated safety check: PassMIT
Nuget Trusted Publishingdotnet/skills5.6k2 repos~2.3kAutomated safety check: PassMIT
Neo4j Aura Provisioning Skillneo4j-contrib/neo4j-skills1141 repos~3.7kAutomated safety check: NotesMIT
Proto Backend Moduleaide-family/moon253—~4.1kAutomated safety check: PassNone
APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills202—~3.6kAutomated safety check: PassMIT

Similar skills

  • Kt Search Release

    jillesvangurp/kt-search

    A skill your agent uses when the user wants to cut, publish, tag, or create a GitHub release for kt-search, especially when the task includes version bumping, validating that commits are pushed…

    155 GitHub stars~1.2k tokensUpdated 3 mo ago
    DevelopmentAuto-check passed
  • Official

    Set up NuGet trusted publishing (OIDC) on a GitHub Actions repo — replaces long-lived API keys with short-lived tokens.

    5.6k GitHub starsUsed in 2 repos~2.3k tokens
    DevOps & CloudAuto-check passed
  • Neo4j Aura Provisioning Skill

    neo4j-contrib/neo4j-skills

    Provisions and manages Neo4j Aura instances via CLI (aura-cli v1.7+) or REST API.

    114 GitHub starsUsed in 1 repo~3.7k tokens
    DevOps & CloudAuto-check: notes
  • Proto Backend Module

    aide-family/moon

    Implements backend modules from proto definitions for goddess, marksman, and rabbit apps.

    253 GitHub stars~4.1k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed

More from elastic/agent-skills

All 26 skills in this repo
  • Security Alert Triage

    elastic/agent-skills

    Official

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge.

    592 GitHub starsUsed in 1 repo~3.5k tokens
    Auto-check: notes
  • Security Case Management

    elastic/agent-skills

    Official

    Create, search, update, and manage SOC cases via the Kibana Cases API.

    592 GitHub starsUsed in 1 repo~2.6k tokens
    Auto-check: notes
  • Official

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint).

    592 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check: notes
  • Kibana Dashboards

    elastic/agent-skills

    Official

    Create and manage Kibana Dashboards and Lens visualizations.

    592 GitHub starsUsed in 1 repo~3.7k tokens
    Auto-check passed
  • Official

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security.

    592 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Kibana Workflows

What does Kibana Workflows do?

Author, validate, test, run, and inspect Elastic Workflow YAML definitions. Kibana Workflows is an agent skill from elastic/agent-skills, published by the product's own GitHub organization. Author, validate, test, run, and inspect Elastic Workflow YAML definitions.

When should I use Kibana Workflows?

Kibana Workflows fits situations like: the user wants to turn natural language into a Kibana workflow; fix workflow YAML; understand triggers; run a quick test loop against a real Kibana.

How do I install Kibana Workflows in Claude Code?

Run `npx skills add elastic/agent-skills --skill kibana-workflows -a claude-code`. Or copy the skill folder (skills/kibana/kibana-workflows in elastic/agent-skills) into .claude/skills/kibana-workflows in your project. Claude Code loads it when a task matches its description.

How do I install Kibana Workflows in Codex?

Run `npx skills add elastic/agent-skills --skill kibana-workflows -a codex`. Or copy the skill folder (skills/kibana/kibana-workflows in elastic/agent-skills) into .agents/skills/kibana-workflows in your project. Codex loads it when a task matches its description.

Can I use Kibana Workflows in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/agent-skills --skill kibana-workflows -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kibana-workflows, .gemini/skills/kibana-workflows, .github/skills/kibana-workflows and .opencode/skills/kibana-workflows in your project.

What does Kibana Workflows need to run?

Going by SKILL.md and its folder, Kibana Workflows needs the command-line tools its instructions call (python3). Our summary lists: Python 3. Compatibility (from SKILL.md): Kibana 9.4 or later with matching Elasticsearch and an Enterprise license, or an Elastic Serverless project with Workflows available; requires the `elastic` CLI ≥ 0.2 with `stack kb workflows` support. When Agent Builder is enabled on the target Kibana, the `platform.core.generate_workflow` and `platform.workflows.*` tools are preferred over the raw schema..

Does Kibana Workflows access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Kibana Workflows safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kibana Workflows use?

Kibana Workflows is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kibana Workflows use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.3k tokens, read only when the agent opens those files.

What are the alternatives to Kibana Workflows?

Skills that share tags, products or a category with Kibana Workflows: Kt Search Release (jillesvangurp/kt-search, 155 stars), Nuget Trusted Publishing (dotnet/skills, 5.6k stars), Neo4j Aura Provisioning Skill (neo4j-contrib/neo4j-skills, 114 stars) and Proto Backend Module (aide-family/moon, 253 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kibana Workflows?

elastic (a GitHub organization, an official publisher) maintains it in elastic/agent-skills, which has 592 GitHub stars. The repository holds 26 skills in this directory. The repository was last updated on October 7, 2026.

Source: elastic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.