Cloud Provisioning
elastic/agent-skills
Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…
Query Elasticsearch/Kibana using ES|QL via the Kibana async search API.
$ npx skills add meain/dotfiles --skill esql -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install meain/dotfiles esql --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agents/.agents/skills/esql .claude/skills/esql && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "esql" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/esql into .claude/skills/esql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esql", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/esqlType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add meain/dotfiles --skill esql -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install meain/dotfiles esql --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .agents/skills && cp -r skills-src/agents/.agents/skills/esql .agents/skills/esql && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "esql" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/esql into .agents/skills/esql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esql", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add meain/dotfiles --skill esql -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install meain/dotfiles esql --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/agents/.agents/skills/esql .cursor/skills/esql && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "esql" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/esql into .cursor/skills/esql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esql", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/meain/dotfiles.git --path agents/.agents/skills/esql--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add meain/dotfiles --skill esql -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install meain/dotfiles esql --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/agents/.agents/skills/esql .gemini/skills/esql && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "esql" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/esql into .gemini/skills/esql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esql", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install meain/dotfiles esqlInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add meain/dotfiles --skill esql -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .github/skills && cp -r skills-src/agents/.agents/skills/esql .github/skills/esql && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "esql" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/esql into .github/skills/esql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esql", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add meain/dotfiles --skill esql -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install meain/dotfiles esql --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/meain/dotfiles.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/agents/.agents/skills/esql .opencode/skills/esql && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "esql" agent skill from https://github.com/meain/dotfiles/tree/master/agents/.agents/skills/esql into .opencode/skills/esql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esql", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
esqlQuery Elasticsearch/Kibana using ES|QL via the Kibana async search API.
Esql is an agent skill from meain/dotfiles. Query Elasticsearch/Kibana using ES|QL via the Kibana async search API. Requires an initial curl command from the user to extract session credentials. Triggers: /esql, 'query elastic', 'search logs', 'check elastic logs', 'run esql', 'elasticsearch query', 'check kibana'
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Search implementation. It works with Elasticsearch. The repository describes itself as: If there is a shell, there is a way! The licence is MIT.
2 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f469fb6. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Esql loads about 3k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 1,021 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from meain/dotfiles at commit f469fb6, republished under its MIT licence (© meain). 1,021 words, ~2,980 tokens.
.claude/skills/esql/SKILL.md (or your agent's skills folder).Query Elasticsearch via the Kibana ES|QL async search API. Run ES|QL queries directly against Kibana clusters without the user needing to copy-paste results.
,es-web CLIThe ,es-web CLI at /Users/meain/.local/bin/utils/,es-web handles Kibana ES|QL queries with automatic async polling, session management, and table output.
First-time setup for a cluster: open Kibana's ES|QL tab (use the URL with dataSource:(type:esql) so an esql_async request fires on load), open DevTools → Network, filter by esql_async, right-click the request → Copy as cURL, then run:
pbpaste | ,es-web init stg-us
pbpaste | ,es-web init prd-euCheck configured clusters:
,es-web listSession cookies expire after a few hours. If you get a 401/session expired error, use reinit — it reopens Kibana and waits for a fresh curl on the clipboard itself, then tests & saves:
,es-web reinit prd-usRun this with dangerouslyDisableSandbox: true since it needs to open the browser. It blocks until a valid curl shows up on the clipboard, so tell the user to copy one (DevTools → Network → filter esql_async → right-click → Copy as cURL) while it's waiting.
,es-web# Simple: service + time window
,es-web -c stg-us -s earn -t 1h -n 20
# With additional WHERE clause
,es-web -c stg-us -s earn -t 1h -q 'message LIKE "*validation*"'
# Custom fields
,es-web -c stg-us -s earn -t 1h -f '@timestamp, message, labels.error'
# Raw ES|QL query
,es-web -c stg-us 'FROM logs-* | WHERE service.name == "earn" | STATS count = COUNT(*) BY labels.event_type | SORT count DESC | LIMIT 10'
# JSON output for further processing
,es-web -c stg-us -s earn -t 30m --json
# Debug: print generated query
,es-web -c stg-us -s earn -t 1h --debug,es-web options-c — Cluster alias (e.g. stg-us, prd-eu)-s — service.name filter-t — Time window (e.g. 30m, 1h, 2d). Defaults to 4h if omitted (a warning is printed to stderr)-n — Max rows (default: 20)-q — Additional WHERE clause-f — Comma-separated fields for KEEP clause-i — Index pattern (default: logs-*)--json — Raw JSON output--debug — Print generated query to stderr,es-web swallows unknown-column errors — a KEEP/STATS BY on a non-existent field returns an empty "No results", not an error. Before concluding "no data", confirm the field exists (e.g. ... | WHERE <field> IS NOT NULL | STATS COUNT(*)). Field names vary by dataset (e.g. apm.app.earn has no HTTP path field; apm.app.nginx uses labels.path).labels.status is a keyword field — compare with strings, not integers (e.g., labels.status >= "500")-f is specified, default fields are: @timestamp, service.name, message, labels.error, labels.error_message, labels.path, labels.status, trace.idmessage across many services can be slow — scope with service and tight time windowsFor EARN log fields, structured labels, message strings, query patterns, and metrics, read:
.mdocs/reference/earn-kibana-esql-reference.md (relative to the control-plane-backend repo root).
That doc is authoritative for EARN. The quick summary of EARN-specific field names (these differ from other services):
labels.workload_tenant_id — workload tenant UUID (not labels.workload_tenant.id)labels.event_type — EARN event type (not labels.earn.event.type)labels.organization_id — org UUID in EARN contextlabels.operation — EARN operation name (e.g. get_workload_tenant_metadata)labels.clog_labels — structured log category (e.g. [earn_event_dropped])log.level — log level in EARN APM logs (not level)Note: EARN logs appear twice in logs-* — once as APM-parsed (data_stream.dataset: apm.app.earn, has structured fields) and once as raw filebeat (data_stream.dataset: kubernetes.container_logs, has JSON in message). Filter to data_stream.dataset == "apm.app.earn" to avoid double-counting in STATS.
These are the service.name values for control-plane-backend services:
| Service | service.name |
|---|---|
| Workload Tenants | workload-tenants-svc |
| Subscriptions | subscriptions-svc |
| User Management | user-management |
| Routing | routing |
| EARN | earn |
| EARN Telemetry | earn-telemetry |
| Usage Reports | usage_reports |
| Onboarding | onboarding |
| Scheduler | scheduler |
The nginx ingress controller logs under service.name == "nginx".
@timestamp — event timestamp (ISO 8601)service.name — service identifier (see table above)service.environment — prod, prd, qa, devmessage — log message textlevel — log level (info, warn, error)trace.id — distributed trace ID for correlating across serviceslabels.status — HTTP status code (string, not int)labels.path — request pathlabels.method — HTTP methodlabels.error / labels.error_message — error detailslabels.organization_id / labels.org_id — organization identifierlabels.organization.id — alternative org ID fieldlabels.workload_tenant_id — workload tenant identifier (EARN: same field, see EARN reference)labels.user.id / labels.principal.id — user/principal identifierslabels.operation — operation being performedlabels.handler — handler namelabels.event_type — EARN event type (use labels.event_type, not labels.earn.event.type)labels.earn.event.dedupe_key — EARN dedup keylabels.scheduler.event.id — scheduler event IDlabels.request.url — outgoing request URLlabels.http.router.request_id — request IDnumeric_labels.* — numeric values (latency, counts, etc.)These are set via clog.Label() and appear in a labels field:
http_server_overview, dispatcher_overview, queue_dispatcher_overviewearn_event_delivery, events_processorpanic_recovery, panic_recoveredazure_sdk_logging, secrets_handlingdeprecated_behavior_overviewFROM logs-*
| WHERE service.environment == "prod"
AND @timestamp >= "2026-04-07T07:00:00.000Z"
AND @timestamp <= "2026-04-07T08:00:00.000Z"
| STATS count = COUNT(*) BY service.name
| SORT count DESC
| LIMIT 30FROM logs-*
| WHERE service.name == "nginx"
AND service.environment == "prod"
AND labels.status >= "500"
| SORT @timestamp DESC
| LIMIT 20
| KEEP @timestamp, labels.status, labels.path, labels.method, messageFROM logs-*
| WHERE service.name == "earn"
AND service.environment == "prod"
AND level == "error"
AND @timestamp >= "START"
AND @timestamp <= "END"
| SORT @timestamp DESC
| LIMIT 30
| KEEP @timestamp, message, labels.error, labels.error_message, labels.operation, trace.idFROM logs-*
| WHERE service.environment == "prod"
AND @timestamp >= "START"
AND @timestamp <= "END"
AND (labels.organization_id == "ORG_ID" OR labels.org_id == "ORG_ID" OR labels.organization.id == "ORG_ID")
| SORT @timestamp DESC
| LIMIT 20
| KEEP @timestamp, service.name, message, labels.error, trace.idFROM logs-*
| WHERE service.environment == "prod"
AND @timestamp >= "START"
AND @timestamp <= "END"
AND labels.workload_tenant_id == "TENANT_ID"
| SORT @timestamp DESC
| LIMIT 30
| KEEP @timestamp, service.name, message, labels.error, labels.operationFROM logs-*
| WHERE trace.id == "TRACE_ID"
| SORT @timestamp ASC
| LIMIT 100
| KEEP @timestamp, service.name, level, message, labels.error, labels.status, labels.pathFROM logs-*
| WHERE service.name == "SERVICE"
AND service.environment == "prod"
AND message LIKE "*metric*latency*"
| SORT @timestamp DESC
| LIMIT 30
| KEEP @timestamp, message, numeric_labels.value_msFROM logs-*
| WHERE service.environment == "prod"
AND @timestamp >= "START"
AND @timestamp <= "END"
AND level == "error"
| STATS error_count = COUNT(*) BY service.name
| SORT error_count DESC
| LIMIT 20FROM logs-*
| WHERE service.environment == "prod"
AND @timestamp >= "START"
AND @timestamp <= "END"
AND (message LIKE "*panic*" OR labels.panic_recovered == "true" OR labels.panic_recovery == "true")
| SORT @timestamp DESC
| LIMIT 20
| KEEP @timestamp, service.name, message, labels.error, trace.id,es CLIThe ,es CLI at /Users/meain/.local/bin/utils/,es provides a simpler way to query Elasticsearch, but it only works for the dev environment. Do not use it for staging or production.
Search by trace ID:
,es -q 'trace.id:<TRACE_ID>' -n 50Filter for errors:
,es -q 'trace.id:<TRACE_ID> AND event.type:error' -n 10Broader service-level search (no trace ID):
,es -q 'service.name:<SERVICE_NAME> AND (level:error OR event.type:error)' -n 20,es CLI options-q — Lucene query string-n — Number of results-f — Comma-separated fields to display-s — Sort field (e.g. @timestamp:desc)| Environment | Method |
|---|---|
| Dev / personal | Use ,es CLI directly |
| Staging / production | Use ,es-web -c <cluster> (requires session cookie from user) |
| No session available | Fall back to clipboard mode (see below) |
Cluster naming convention: <env>-<region>, e.g. stg-us, stg-eu, prd-us, prd-eu, prd-apj (APJ, not apac).
When no ,es-web session is configured for the target cluster:
confluence page 405504500), open <kibana-base-url>/app/discover#/ with open <url> (with dangerouslyDisableSandbox: true), then ask the user to copy a curl from the network tab and run ! pbpaste | ,es-web init <cluster>pbcopylabels.error and labels.error_message.numeric_labels.* fields are numeric; labels.* fields are keywords (strings).-t is omitted. If a query times out, retry with a narrower window (e.g., 1h → 30m). For very broad searches (e.g., no service filter), start at 30m and expand only if needed.http_server_overview, dispatcher_overview) are useful for filtering to structured log categories without needing to match on message text.© meain, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in agents/.agents/skills/esql of meain/dotfiles.
Open the folder on GitHubat commit f469fb6
Esql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Esql this skillmeain/dotfiles | 285 | — | ~3k | Automated safety check: Pass | MIT | |
| Cloud Provisioningelastic/agent-skills | 592 | — | ~5.4k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Log Forwarding With Fluentdmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~697 | Automated safety check: Pass | Apache-2.0 | |
| Detecting Debug Endpointsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2k | Automated safety check: Pass | MIT | |
| Elasticsearch Index Managerjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~591 | Automated safety check: Pass | MIT | |
| Product Full-Text Searchlobehub/lobehub | 83k | — | ~4.1k | Automated safety check: Pass | Custom licence |
elastic/agent-skills
Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…
mukul975/Anthropic-Cybersecurity-Skills
Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for…
jeremylongshore/tons-of-skills-marketplace
Probe a target for accidentally-public admin / debug / introspection endpoints — Spring Boot Actuator, Apache server-status, Prometheus metrics, GraphQL playground, Swagger UI, phpMyAdmin…
jeremylongshore/tons-of-skills-marketplace
Manage elasticsearch index manager operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.
lobehub/lobehub
Guides work on LobeHub's own product search: the shared search repository, provider choice, Elasticsearch mappings, change syncing and reindexing.
exceptionless/Exceptionless
Query, aggregate, patch, or paginate Exceptionless data through its Elasticsearch repository abstractions.
meain/dotfiles
Search past Claude Code and Codex sessions. An agent skill from meain/dotfiles.
meain/dotfiles
Grilling session that challenges your plan against the existing domain model, sharpens terminology, and updates documentation (CONTEXT.md, ADRs) inline as decisions crystallise.
meain/dotfiles
Daily backlog management — full planning review OR add a single entry from a URL.
meain/dotfiles
Generate an interactive local HTML review page for a large PR or diff, grouping the changed files by logical concern (not just by file) so a reviewer can go through one theme at a time instead of a…
meain/dotfiles
Generate a concise weekly status update in team format. An agent skill from meain/dotfiles.
meain/dotfiles
Search the web using lynx and DuckDuckGo. An agent skill from meain/dotfiles.
Works with
Categories
Query Elasticsearch/Kibana using ES|QL via the Kibana async search API. Esql is an agent skill from meain/dotfiles. Query Elasticsearch/Kibana using ES|QL via the Kibana async search API.
Esql fits situations like: tasks that involve Search implementation.
Run `npx skills add meain/dotfiles --skill esql -a claude-code`. Or copy the skill folder (agents/.agents/skills/esql in meain/dotfiles) into .claude/skills/esql in your project. Claude Code loads it when a task matches its description.
Run `npx skills add meain/dotfiles --skill esql -a codex`. Or copy the skill folder (agents/.agents/skills/esql in meain/dotfiles) into .agents/skills/esql in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add meain/dotfiles --skill esql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/esql, .gemini/skills/esql, .github/skills/esql and .opencode/skills/esql in your project.
SKILL.md names no scripts, command-line tools or credentials: Esql is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Esql is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Esql: Cloud Provisioning (elastic/agent-skills, 592 stars), Implementing Log Forwarding With Fluentd (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Debug Endpoints (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Elasticsearch Index Manager (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
meain (a GitHub user) maintains it in meain/dotfiles, which has 285 GitHub stars. The repository holds 36 skills in this directory. The repository was last updated on September 5, 2026.
Source: meain/dotfiles on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.