Agent skill

Esql

by meain in meain/dotfiles

Query Elasticsearch/Kibana using ES|QL via the Kibana async search API.

MITAuto-check passedBackend & APIs

Install Esql

skills CLI
$ npx skills add meain/dotfiles --skill esql -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install meain/dotfiles esql --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/.agents/skills/esql .claude/skills/esql && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
esql
GitHub stars
285
Token cost
~3k tokens
SKILL.md length
1,021 words
Files
1
Skills in repo
36
Repo updated
First seen
Licence
MIT

At a glance

Query Elasticsearch/Kibana using ES|QL via the Kibana async search API.

  • Works in 2 steps: Look up the Kibana URL on the Confluence… → If that's not possible, fall back to…
  • Tasks that involve Search implementation
  • SKILL.md covers Setup, How to query with ,es-web, EARN-specific reference and Known service names, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Esql is an agent skill from meain/dotfiles. Query Elasticsearch/Kibana using ES|QL via the Kibana async search API. Requires an initial curl command from the user to extract session credentials. Triggers: /esql, 'query elastic', 'search logs', 'check elastic logs', 'run esql', 'elasticsearch query', 'check kibana'

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Search implementation. It works with Elasticsearch. The repository describes itself as: If there is a shell, there is a way! The licence is MIT.

When your agent uses it

  • Tasks that involve Search implementation

Example prompts

  • “query elastic”
  • “search logs”
  • “check elastic logs”
  • “/esql”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Look up the Kibana URL on the Confluence Speed Dial page (confluence page 405504500), open /app/discover#/ with open (with…
  2. If that's not possible, fall back to clipboard mode

What it can do on your machine

Read from SKILL.md and the folder at commit f469fb6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Esql loads about 3k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 1,021 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from meain/dotfiles at commit f469fb6, republished under its MIT licence (© meain). 1,021 words, ~2,980 tokens.

Download SKILL.mdSave it as .claude/skills/esql/SKILL.md (or your agent's skills folder).
name
esql
description
Query Elasticsearch/Kibana using ES|QL via the Kibana async search API. Requires an initial curl command from the user to extract session credentials. Triggers: /esql, 'query elastic', 'search logs', 'check elastic logs', 'run esql', 'elasticsearch query', 'check kibana'
user_invocable
true

ES|QL Query Skill

Query Elasticsearch via the Kibana ES|QL async search API. Run ES|QL queries directly against Kibana clusters without the user needing to copy-paste results.

Setup

Staging / Production — ,es-web CLI

The ,es-web CLI at /Users/meain/.local/bin/utils/,es-web handles Kibana ES|QL queries with automatic async polling, session management, and table output.

First-time setup for a cluster: open Kibana's ES|QL tab (use the URL with dataSource:(type:esql) so an esql_async request fires on load), open DevTools → Network, filter by esql_async, right-click the request → Copy as cURL, then run:

bash
pbpaste | ,es-web init stg-us
pbpaste | ,es-web init prd-eu

Check configured clusters:

bash
,es-web list

Session cookies expire after a few hours. If you get a 401/session expired error, use reinit — it reopens Kibana and waits for a fresh curl on the clipboard itself, then tests & saves:

bash
,es-web reinit prd-us

Run this with dangerouslyDisableSandbox: true since it needs to open the browser. It blocks until a valid curl shows up on the clipboard, so tell the user to copy one (DevTools → Network → filter esql_async → right-click → Copy as cURL) while it's waiting.

How to query with ,es-web

bash
# Simple: service + time window
,es-web -c stg-us -s earn -t 1h -n 20

# With additional WHERE clause
,es-web -c stg-us -s earn -t 1h -q 'message LIKE "*validation*"'

# Custom fields
,es-web -c stg-us -s earn -t 1h -f '@timestamp, message, labels.error'

# Raw ES|QL query
,es-web -c stg-us 'FROM logs-* | WHERE service.name == "earn" | STATS count = COUNT(*) BY labels.event_type | SORT count DESC | LIMIT 10'

# JSON output for further processing
,es-web -c stg-us -s earn -t 30m --json

# Debug: print generated query
,es-web -c stg-us -s earn -t 1h --debug
,es-web options
  • -c — Cluster alias (e.g. stg-us, prd-eu)
  • -s — service.name filter
  • -t — Time window (e.g. 30m, 1h, 2d). Defaults to 4h if omitted (a warning is printed to stderr)
  • -n — Max rows (default: 20)
  • -q — Additional WHERE clause
  • -f — Comma-separated fields for KEEP clause
  • -i — Index pattern (default: logs-*)
  • --json — Raw JSON output
  • --debug — Print generated query to stderr
Important notes
  • ,es-web swallows unknown-column errors — a KEEP/STATS BY on a non-existent field returns an empty "No results", not an error. Before concluding "no data", confirm the field exists (e.g. ... | WHERE <field> IS NOT NULL | STATS COUNT(*)). Field names vary by dataset (e.g. apm.app.earn has no HTTP path field; apm.app.nginx uses labels.path).
  • labels.status is a keyword field — compare with strings, not integers (e.g., labels.status >= "500")
  • When no -f is specified, default fields are: @timestamp, service.name, message, labels.error, labels.error_message, labels.path, labels.status, trace.id
  • For raw ES|QL queries, pass the full query as a positional argument — no default KEEP is added
  • LIKE queries on message across many services can be slow — scope with service and tight time windows

EARN-specific reference

For EARN log fields, structured labels, message strings, query patterns, and metrics, read: .mdocs/reference/earn-kibana-esql-reference.md (relative to the control-plane-backend repo root).

That doc is authoritative for EARN. The quick summary of EARN-specific field names (these differ from other services):

  • labels.workload_tenant_id — workload tenant UUID (not labels.workload_tenant.id)
  • labels.event_type — EARN event type (not labels.earn.event.type)
  • labels.organization_id — org UUID in EARN context
  • labels.operation — EARN operation name (e.g. get_workload_tenant_metadata)
  • labels.clog_labels — structured log category (e.g. [earn_event_dropped])
  • log.level — log level in EARN APM logs (not level)

Note: EARN logs appear twice in logs-* — once as APM-parsed (data_stream.dataset: apm.app.earn, has structured fields) and once as raw filebeat (data_stream.dataset: kubernetes.container_logs, has JSON in message). Filter to data_stream.dataset == "apm.app.earn" to avoid double-counting in STATS.

Known service names

These are the service.name values for control-plane-backend services:

Serviceservice.name
Workload Tenantsworkload-tenants-svc
Subscriptionssubscriptions-svc
User Managementuser-management
Routingrouting
EARNearn
EARN Telemetryearn-telemetry
Usage Reportsusage_reports
Onboardingonboarding
Schedulerscheduler

The nginx ingress controller logs under service.name == "nginx".

Common log fields

Standard fields
  • @timestamp — event timestamp (ISO 8601)
  • service.name — service identifier (see table above)
  • service.environment — prod, prd, qa, dev
  • message — log message text
  • level — log level (info, warn, error)
  • trace.id — distributed trace ID for correlating across services
Label fields (keyword/string type)
  • labels.status — HTTP status code (string, not int)
  • labels.path — request path
  • labels.method — HTTP method
  • labels.error / labels.error_message — error details
  • labels.organization_id / labels.org_id — organization identifier
  • labels.organization.id — alternative org ID field
  • labels.workload_tenant_id — workload tenant identifier (EARN: same field, see EARN reference)
  • labels.user.id / labels.principal.id — user/principal identifiers
  • labels.operation — operation being performed
  • labels.handler — handler name
  • labels.event_type — EARN event type (use labels.event_type, not labels.earn.event.type)
  • labels.earn.event.dedupe_key — EARN dedup key
  • labels.scheduler.event.id — scheduler event ID
  • labels.request.url — outgoing request URL
  • labels.http.router.request_id — request ID
Show full SKILL.md (412 more words)Show less
Numeric label fields
  • numeric_labels.* — numeric values (latency, counts, etc.)
Overview labels (for filtering structured log categories)

These are set via clog.Label() and appear in a labels field:

  • http_server_overview, dispatcher_overview, queue_dispatcher_overview
  • earn_event_delivery, events_processor
  • panic_recovery, panic_recovered
  • azure_sdk_logging, secrets_handling
  • deprecated_behavior_overview

Common query patterns

List services in a time window
FROM logs-*
| WHERE service.environment == "prod"
  AND @timestamp >= "2026-04-07T07:00:00.000Z"
  AND @timestamp <= "2026-04-07T08:00:00.000Z"
| STATS count = COUNT(*) BY service.name
| SORT count DESC
| LIMIT 30
Find 5xx errors from nginx
FROM logs-*
| WHERE service.name == "nginx"
  AND service.environment == "prod"
  AND labels.status >= "500"
| SORT @timestamp DESC
| LIMIT 20
| KEEP @timestamp, labels.status, labels.path, labels.method, message
Find errors for a specific service
FROM logs-*
| WHERE service.name == "earn"
  AND service.environment == "prod"
  AND level == "error"
  AND @timestamp >= "START"
  AND @timestamp <= "END"
| SORT @timestamp DESC
| LIMIT 30
| KEEP @timestamp, message, labels.error, labels.error_message, labels.operation, trace.id
Search by org/tenant ID across all services
FROM logs-*
| WHERE service.environment == "prod"
  AND @timestamp >= "START"
  AND @timestamp <= "END"
  AND (labels.organization_id == "ORG_ID" OR labels.org_id == "ORG_ID" OR labels.organization.id == "ORG_ID")
| SORT @timestamp DESC
| LIMIT 20
| KEEP @timestamp, service.name, message, labels.error, trace.id
Search by workload tenant ID
FROM logs-*
| WHERE service.environment == "prod"
  AND @timestamp >= "START"
  AND @timestamp <= "END"
  AND labels.workload_tenant_id == "TENANT_ID"
| SORT @timestamp DESC
| LIMIT 30
| KEEP @timestamp, service.name, message, labels.error, labels.operation
Trace a request across services
FROM logs-*
| WHERE trace.id == "TRACE_ID"
| SORT @timestamp ASC
| LIMIT 100
| KEEP @timestamp, service.name, level, message, labels.error, labels.status, labels.path
Check latency metrics
FROM logs-*
| WHERE service.name == "SERVICE"
  AND service.environment == "prod"
  AND message LIKE "*metric*latency*"
| SORT @timestamp DESC
| LIMIT 30
| KEEP @timestamp, message, numeric_labels.value_ms
Error rate by service (last hour)
FROM logs-*
| WHERE service.environment == "prod"
  AND @timestamp >= "START"
  AND @timestamp <= "END"
  AND level == "error"
| STATS error_count = COUNT(*) BY service.name
| SORT error_count DESC
| LIMIT 20
Find panics
FROM logs-*
| WHERE service.environment == "prod"
  AND @timestamp >= "START"
  AND @timestamp <= "END"
  AND (message LIKE "*panic*" OR labels.panic_recovered == "true" OR labels.panic_recovery == "true")
| SORT @timestamp DESC
| LIMIT 20
| KEEP @timestamp, service.name, message, labels.error, trace.id

Dev / Personal Environments — ,es CLI

The ,es CLI at /Users/meain/.local/bin/utils/,es provides a simpler way to query Elasticsearch, but it only works for the dev environment. Do not use it for staging or production.

Common queries

Search by trace ID:

,es -q 'trace.id:<TRACE_ID>' -n 50

Filter for errors:

,es -q 'trace.id:<TRACE_ID> AND event.type:error' -n 10

Broader service-level search (no trace ID):

,es -q 'service.name:<SERVICE_NAME> AND (level:error OR event.type:error)' -n 20
,es CLI options
  • -q — Lucene query string
  • -n — Number of results
  • -f — Comma-separated fields to display
  • -s — Sort field (e.g. @timestamp:desc)

Choosing the right approach

EnvironmentMethod
Dev / personalUse ,es CLI directly
Staging / productionUse ,es-web -c <cluster> (requires session cookie from user)
No session availableFall back to clipboard mode (see below)

Cluster naming convention: <env>-<region>, e.g. stg-us, stg-eu, prd-us, prd-eu, prd-apj (APJ, not apac).

When no ,es-web session is configured for the target cluster:

  1. Look up the Kibana URL on the Confluence Speed Dial page (confluence page 405504500), open <kibana-base-url>/app/discover#/ with open <url> (with dangerouslyDisableSandbox: true), then ask the user to copy a curl from the network tab and run ! pbpaste | ,es-web init <cluster>
  2. If that's not possible, fall back to clipboard mode:
    • Copy the ES|QL query to the user's clipboard with pbcopy
    • Tell the user to open Kibana, run the query in Discover (ES|QL mode)
    • Have them copy the response JSON from the network tab

Investigation workflow tips

  • Start broad, narrow down. First identify which services are involved, then drill into specific errors.
  • nginx → upstream. nginx logs show external-facing status codes; upstream service logs show root cause.
  • Use trace.id to correlate requests across services when available.
  • Error details live in labels.error and labels.error_message.
  • Field types matter: numeric_labels.* fields are numeric; labels.* fields are keywords (strings).
  • Time windows: Default is 4h when -t is omitted. If a query times out, retry with a narrower window (e.g., 1h → 30m). For very broad searches (e.g., no service filter), start at 30m and expand only if needed.
  • Overview labels (like http_server_overview, dispatcher_overview) are useful for filtering to structured log categories without needing to match on message text.

© meain, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agents/.agents/skills/esql of meain/dotfiles.

Open the folder on GitHubat commit f469fb6

Compare with similar skills

Esql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Esql compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Esql this skillmeain/dotfiles285—~3kAutomated safety check: PassMIT
Cloud Provisioningelastic/agent-skills592—~5.4kAutomated safety check: PassApache-2.0
Implementing Log Forwarding With Fluentdmukul975/Anthropic-Cybersecurity-Skills34k—~697Automated safety check: PassApache-2.0
Detecting Debug Endpointsjeremylongshore/tons-of-skills-marketplace2.8k—~2kAutomated safety check: PassMIT
Elasticsearch Index Managerjeremylongshore/tons-of-skills-marketplace2.8k—~591Automated safety check: PassMIT
Product Full-Text Searchlobehub/lobehub83k—~4.1kAutomated safety check: PassCustom licence

Similar skills

  • Cloud Provisioning

    elastic/agent-skills

    Official

    Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…

    592 GitHub stars~5.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Implementing Log Forwarding With Fluentd

    mukul975/Anthropic-Cybersecurity-Skills

    Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for…

    34k GitHub stars~697 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Detecting Debug Endpoints

    jeremylongshore/tons-of-skills-marketplace

    Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…

    2.8k GitHub stars~2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Elasticsearch Index Manager

    jeremylongshore/tons-of-skills-marketplace

    Manage elasticsearch index manager operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~591 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.

    83k GitHub stars~4.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Foundatio Repositories

    exceptionless/Exceptionless

    Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.

    2.5k GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from meain/dotfiles

All 36 skills in this repo
  • Recall

    meain/dotfiles

    Search past Claude Code and Codex sessions. An agent skill from meain/dotfiles.

    285 GitHub starsUsed in 1 repo~684 tokens
    Auto-check passed
  • Grill With Docs

    meain/dotfiles

    Grilling session that challenges your plan against the existing domain model, sharpens terminology, and updates documentation (CONTEXT.md, ADRs) inline as decisions crystallise.

    285 GitHub starsUsed in 21 repos~875 tokens
    Auto-check passed
  • Backlog

    meain/dotfiles

    Daily backlog management — full planning review OR add a single entry from a URL.

    285 GitHub stars~3k tokensUpdated 1 mo ago
    Auto-check passed
  • Concern Review

    meain/dotfiles

    Generate an interactive local HTML review page for a large PR or diff, grouping the changed files by logical concern (not just by file) so a reviewer can go through one theme at a time instead of a…

    285 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • My Weekly Report

    meain/dotfiles

    Generate a concise weekly status update in team format. An agent skill from meain/dotfiles.

    285 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Search

    meain/dotfiles

    Search the web using lynx and DuckDuckGo. An agent skill from meain/dotfiles.

    285 GitHub stars~830 tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Esql

What does Esql do?

Query Elasticsearch/Kibana using ES|QL via the Kibana async search API. Esql is an agent skill from meain/dotfiles. Query Elasticsearch/Kibana using ES|QL via the Kibana async search API.

When should I use Esql?

Esql fits situations like: tasks that involve Search implementation.

How do I install Esql in Claude Code?

Run `npx skills add meain/dotfiles --skill esql -a claude-code`. Or copy the skill folder (agents/.agents/skills/esql in meain/dotfiles) into .claude/skills/esql in your project. Claude Code loads it when a task matches its description.

How do I install Esql in Codex?

Run `npx skills add meain/dotfiles --skill esql -a codex`. Or copy the skill folder (agents/.agents/skills/esql in meain/dotfiles) into .agents/skills/esql in your project. Codex loads it when a task matches its description.

Can I use Esql in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add meain/dotfiles --skill esql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/esql, .gemini/skills/esql, .github/skills/esql and .opencode/skills/esql in your project.

What does Esql need to run?

SKILL.md names no scripts, command-line tools or credentials: Esql is instructions for the agent only.

Does Esql access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Esql safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Esql use?

Esql is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Esql use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Esql?

Skills that share tags, products or a category with Esql: Cloud Provisioning (elastic/agent-skills, 592 stars), Implementing Log Forwarding With Fluentd (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Debug Endpoints (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Elasticsearch Index Manager (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Esql?

meain (a GitHub user) maintains it in meain/dotfiles, which has 285 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on September 5, 2026.

Source: meain/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.