kibana-agent-builder
elastic/agent-skills
Create and manage Kibana Agent Builder agents and custom tools for Elasticsearch data workflows.
What is kibana-agent-builder?
Build reusable tools (index search, ES|QL, workflow-based) and LLM agents that ground responses in Elasticsearch data. Use this skill when creating, updating, testing, or inspecting Agent Builder resources, or discovering what agents and tools already exist in your Kibana instance.
- Create custom tools for open-ended search, parameterized analytics queries, and multi-step automation
- Build agents with curated toolsets and system instructions that leverage Elasticsearch data
- Inspect, update, and delete existing agents and tools without duplication
- Execute and validate ES|QL tools with parameters before deploying to agents
- Discover built-in platform tools and integrate them into custom agents
How to install kibana-agent-builder
npx skills add https://github.com/elastic/agent-skills --skill kibana-agent-builder- Elastic CLI installed and configured with valid Elasticsearch credentials
- Access to a Kibana instance with Agent Builder enabled
- Knowledge of ES|QL syntax for parameterized query tools (optional but recommended)
How to use kibana-agent-builder
- 1.Classify your task: determine whether you need a tool, agent, or chat session with an existing agent
- 2.List existing tools via GET kbn:/api/agent_builder/tools and agents via GET kbn:/api/agent_builder/agents to avoid conflicts
- 3.Choose the tool type: index_search for broad searches, esql for fixed analytics with parameters, or workflow for multi-step automation
- 4.Build the tool or agent payload with required fields (id, type/name, description, configuration) and POST to the appropriate endpoint
- 5.Verify creation by fetching the resource and confirming the live API response matches your intent
- 6.For ES|QL tools, optionally validate with POST kbn:/api/agent_builder/tools/_execute before assigning to agents
- 7.Update or delete resources only after confirming the action with the user
Use cases
- Build a customer feedback analyzer agent that searches support tickets and trends sentiment over time
- Create a parameterized ES|QL tool for weekly revenue reports filtered by region and date range
- Set up a multi-tool agent that combines index search and workflow automation for incident response
- Validate a new analytics tool query before assigning it to production agents
- List all existing agents to avoid naming conflicts when creating new ones
- Kibana administrators managing Agent Builder resources
- Data analysts building agents for business intelligence and reporting
- DevOps and SRE teams automating incident investigation workflows
- Teams standardizing reusable tools across multiple agents
kibana-agent-builder FAQ
A tool is a reusable function (index search, ES|QL query, or workflow) that retrieves or acts on data. An agent is an LLM entity with instructions and a curated set of tool IDs. Creating a tool does not create an agent; you must explicitly build the agent and assign tools to it.
Yes. Tools are reusable. List all tools with GET kbn:/api/agent_builder/tools, then reference their IDs in multiple agent configurations.
The API returns a 400 error. Always call GET kbn:/api/agent_builder/tools first to discover existing tool IDs and avoid conflicts.
No. The tool API accepts only id, type, description, configuration, and tags. The 'name' field is not valid for tools and will cause a 400 error.
Use ?param::type placeholders in the query string and define each parameter in the 'params' object with type and description. For example, ?lookback_days::integer with {"lookback_days": {"type": "integer", "description": "..."}}. Always include | LIMIT N to control token use.
Full instructions (SKILL.md)
Source of truth, from elastic/agent-skills.
name: kibana-agent-builder description: > Create and manage Kibana Agent Builder agents and custom tools. Use when asked to create, update, delete, test, or inspect agents or tools in Agent Builder, or when the user wants to understand what agents or tools already exist. metadata: author: elastic version: 0.3.0 universal: true
Kibana Agent Builder
Create, inspect, update, delete, and test Agent Builder tools and agents. Ground LLM responses in Elasticsearch data through scoped search tools, parameterized ES|QL, and workflow integrations.
<!-- begin-partial: preamble -->Environment Configuration
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
Resource model
Agent Builder exposes three distinct resource kinds — do not conflate them:
| Kind | Purpose | Typical API |
|---|---|---|
| Tool | Reusable function an agent invokes to retrieve or act on data (index_search, esql, workflow) | POST kbn:/api/agent_builder/tools |
| Agent | LLM entity with instructions and a curated toolset | POST kbn:/api/agent_builder/agents |
| Chat / conversation | Ephemeral messaging session with an existing agent | POST kbn:/api/agent_builder/converse/async |
Creating a tool does not create an agent. Listing or chatting with an agent does not create a tool. When the user asks to "create an agent" or "create a tool," identify which resource they mean before calling a write API.
Built-in tools use the platform.core.* prefix (for example platform.core.search). Custom tools and agents are
user-defined. Read architecture-guide.md for built-in tool inventory, context
engineering, and security notes.
Process
-
Classify the task. Decide whether the user needs a tool, an agent, or chat with an existing agent. If they ask what already exists ("what agents are there?", "list agents"), treat the request as read-only discovery — answer from live data before proposing any create, update, or delete.
-
Discover existing resources before any write. When creating or updating:
- Call
GET kbn:/api/agent_builder/toolsto list available tools (built-in and custom). Do not invent tool IDs. - Call
GET kbn:/api/agent_builder/agentsto list existing agents and avoid duplicate IDs or names.
When the user only asks what agents exist, stop after
GET kbn:/api/agent_builder/agents. Enumerate each agent's id and name. If the list is empty, say so plainly — do not fabricate agents. Only proceed to creation when the user explicitly asks to create one and you have confirmed the target id is unused. - Call
-
Choose the tool type (for tool tasks). Match intent to the narrowest tool type:
- Open-ended search over a known index pattern →
index_searchwith a specific pattern (for examplecustomer-feedback-*), never*or all-indices scope unless the user explicitly requires it. - Fixed analytics, aggregations, or parameterized queries →
esqlwith?paramplaceholders and aparamsobject (use{}when there are no parameters). - Multi-step automation beyond retrieval →
workflowreferencing an existing workflow id.
For ES|QL syntax and query design, follow the
elasticsearch-esqlskill. For workflow YAML, follow thekibana-workflowsskill. - Open-ended search over a known index pattern →
-
Build the tool payload. Required fields:
id,type,description,configuration. Optional:tags.API constraints (violations return 400):
- POST accepts only
id,type,description,configuration,tags.nameis not valid on tools. - Index search configuration uses
"pattern", not"index". - ES|QL tools require
"params"even when empty:"params": {}. - Each param accepts only
typeanddescription— notdefaultoroptional. Hard-code defaults in the query. - PUT on tools accepts only
description,configuration, andtags.idandtypeare immutable.
Index search example (scoped pattern):
{ "id": "customer_feedback_search", "type": "index_search", "description": "Searches customer feedback and support tickets in the customer-feedback indices.", "configuration": { "pattern": "customer-feedback-*" } }ES|QL example (parameterized, with LIMIT):
{ "id": "feedback_sentiment_trend", "type": "esql", "description": "Returns positive vs negative feedback counts by product category over a lookback window.", "configuration": { "query": "FROM customer-feedback-* | WHERE @timestamp >= NOW() - ?lookback_days::integer * 1d | STATS positive = COUNT(*) WHERE sentiment == \"positive\", negative = COUNT(*) WHERE sentiment == \"negative\" BY product_category | SORT negative DESC | LIMIT 20", "params": { "lookback_days": { "type": "integer", "description": "Number of days to look back, e.g. 7, 30, 90" } } } } - POST accepts only
-
Create and verify the tool. Call
POST kbn:/api/agent_builder/toolswith the payload. Confirm success by callingGET kbn:/api/agent_builder/tools/{toolId}and reporting the created id, type, description, and configuration back to the user — do not claim success without a live API response.Optionally validate ES|QL tools with
POST kbn:/api/agent_builder/tools/_execute, passingtool_idandtool_params. Always include| LIMIT Nin ES|QL queries to control token use. -
Build the agent payload (for agent tasks). Required fields:
id,name,description,configuration. Configuration must includeinstructionsand atoolsarray withtool_idsdrawn from Step 2 — only IDs returned byGET kbn:/api/agent_builder/tools.Derive a stable
idfrom the name (lowercase, hyphens, alphanumeric). Check Step 2's agent list for conflicts before posting.{ "id": "customer-feedback-agent", "name": "Customer Feedback Analyst", "description": "Analyzes customer sentiment and feedback trends.", "configuration": { "instructions": "Always use tools to retrieve data. Never answer data questions from memory.", "tools": [ { "tool_ids": ["customer_feedback_search", "platform.core.search"] } ] } }Agent update constraints: PUT accepts only
description,configuration, andtags(plus avatar/labels when applicable). Do not send immutable fields likeid,name, ortypeon update — they cause 400 errors. -
Create and verify the agent. Call
POST kbn:/api/agent_builder/agents. Confirm withGET kbn:/api/agent_builder/agentsorGET kbn:/api/agent_builder/agents/{agentId}. Report the live response. -
Update or delete (when requested). Confirm destructive actions with the user first.
- Update tool:
PUT kbn:/api/agent_builder/tools/{toolId} - Delete tool:
DELETE kbn:/api/agent_builder/tools/{toolId} - Update agent:
PUT kbn:/api/agent_builder/agents/{agentId} - Delete agent:
DELETE kbn:/api/agent_builder/agents/{agentId}
- Update tool:
-
Chat (when requested). Chat is not agent or tool creation. Use
POST kbn:/api/agent_builder/converse/asyncwith an existingagent_idand user input. Expect multi-step reasoning and tool calls; allow sufficient time for streaming completion.
Guidelines
- Discover before create. Always list agents (and tools when relevant) before creating resources. When asked "what agents exist?", answer that question first — read-only — even if the user also mentions wanting a new agent later.
- Scope index search narrowly. Prefer
customer-feedback-*over*. Broad patterns increase noise, token cost, and RBAC surface area. - Write descriptive tool descriptions. The agent selects tools based on descriptions alone — include when to use each tool and example trigger phrases.
- Minimize toolsets. Every assigned tool adds tokens to the agent system prompt on every turn.
- Validate ES|QL before deployment. Execute the tool after creation when parameters or query shape are non-trivial.
- Use aggregations and KEEP. Prefer summary stats over raw document dumps for analytics questions.
Examples
Create an index search tool (eval pattern)
User: "Create a custom Agent Builder tool that searches the customer-feedback-* index. Use the tool id 'eval-feedback-search'."
- List tools — confirm
eval-feedback-searchdoes not already exist. - Choose
index_searchscoped tocustomer-feedback-*(not*). - POST the tool with id, description, and
configuration.pattern. - GET the tool by id and confirm creation to the user.
Answer "what agents already exist?" before creating
User: "I want to create a new agent in Kibana Agent Builder. What agents already exist?"
- Call
GET kbn:/api/agent_builder/agents— read-only. - Enumerate existing agent ids and names (or state that none exist).
- Do not create, update, or delete anything in this step.
- Only if the user then asks to create, pick an unused id informed by the list above.
Create an agent after discovery
User: "Create a sales-helper agent using the esql-sales-data tool."
- List tools — confirm
esql-sales-dataexists. - List agents — confirm no conflicting id.
- POST agent with instructions and selected tool IDs.
- GET agent to verify and report back.
References
- architecture-guide.md — Built-in tools, context engineering, token optimization, MCP/A2A integration, permissions
- use-cases.md — Playbooks for customer feedback, marketing campaign, and contract analysis agents with example tool and agent payloads
Operations
| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET kbn:/api/agent_builder/tools | elastic kb agent-builder get-agent-builder-tools |
POST kbn:/api/agent_builder/tools | elastic kb agent-builder post-agent-builder-tools --id '<id>' --type '<type>' --description '<desc>' --configuration '<json>' |
GET kbn:/api/agent_builder/tools/{toolId} | elastic kb agent-builder get-agent-builder-tools-toolid --tool-id '<toolId>' |
PUT kbn:/api/agent_builder/tools/{toolId} | elastic kb agent-builder put-agent-builder-tools-toolid --tool-id '<toolId>' [--description '<desc>'] [--configuration '<json>'] |
DELETE kbn:/api/agent_builder/tools/{toolId} | elastic kb agent-builder delete-agent-builder-tools-toolid --tool-id '<toolId>' [--force] |
POST kbn:/api/agent_builder/tools/_execute | elastic kb agent-builder post-agent-builder-tools-execute --tool-id '<toolId>' --tool-params '<json>' |
GET kbn:/api/agent_builder/agents | elastic kb agent-builder get-agent-builder-agents |
POST kbn:/api/agent_builder/agents | elastic kb agent-builder post-agent-builder-agents --id '<id>' --name '<name>' --description '<desc>' --configuration '<json>' |
GET kbn:/api/agent_builder/agents/{agentId} | elastic kb agent-builder get-agent-builder-agents-id --id '<agentId>' |
PUT kbn:/api/agent_builder/agents/{agentId} | elastic kb agent-builder put-agent-builder-agents-id --id '<agentId>' [--description '<desc>'] [--configuration '<json>'] |
DELETE kbn:/api/agent_builder/agents/{agentId} | elastic kb agent-builder delete-agent-builder-agents-id --id '<agentId>' |
POST kbn:/api/agent_builder/converse/async | elastic kb agent-builder post-agent-builder-converse-async --agent-id '<agentId>' --input '<message>' |
Related skills
More from elastic/agent-skills and the wider catalog.

kibana-alerting-rules
Create and manage Kibana alerting rules with metric thresholds, grouping, and lifecycle control.

kibana-anomaly-detection
Diagnose and explain Elastic ML anomaly detection results, job lifecycle issues, and entity attribution for incident RCA.

kibana-audit
Enable and configure Kibana audit logging for saved object access, logins, and space operations.

kibana-connectors
Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform.

kibana-dashboards
Create and manage Kibana dashboards and Lens visualizations declaratively with version control and automation.

kibana-streams
List, inspect, enable, disable, and resync Kibana Streams via REST API.