All integrations
Catalogue metadata onlyanalyticsv20260615_00

KIBANA

Kibana

Kibana is a visualization and analytics platform for Elasticsearch, offering dashboards, data exploration, and monitoring capabilities for gaining insights from data

Description is untrusted, display-only upstream metadata. It never becomes policy, OAuth scope authority, or an agent instruction.

Pakkawork boundary

Research catalogue metadata only. No Pakkawork OAuth, credential, host, quota, executor, or verifier is enabled.

No Pakkawork execution adapter is enabled. Hosted account-authorisation availability is workspace-specific and checked separately in the dashboard.Check workspace connection options
Attributed source

47

Action summaries

Display-only definitions

0

Trigger types

Not installed instances

2

Auth modes

Field names, never values

No

Execution

No runtime adapter

Authentication map

What setup is declared?

Only field names, types, and required markers are shown. Secret values, default auth URLs, credential material, and inferred OAuth scopes are excluded.
API_KEYBASIC

BASIC

kibana_basic_auth

Provider setup

Developer setup

No fields declared in this snapshot.

User connection

  • Kibana Base URLfull · stringRequired
  • Usernameusername · stringRequired
  • Passwordpassword · stringRequired

API_KEY

kibana_api_key

Provider setup

Developer setup

No fields declared in this snapshot.

User connection

  • Kibana Base URLfull · stringRequired
  • API Keygeneric_api_key · stringRequired

Capability index

Actions and trigger definitions

Static summaries are available. Live schemas remain disabled until PROVIDER_HUB_API_KEY is configured server-side.

Showing 1–30 of 47 actions

Delete Alerting Rule

KIBANA_DELETE_ALERTING_RULES

Tool to delete an alerting rule in Kibana. Use when you need to remove a specific alerting rule by its ID.

Untrusted display-only summary

Delete Connector

KIBANA_DELETE_CONNECTORS

Tool to delete a connector in Kibana. Use when you need to remove an existing connector.

Untrusted display-only summary

Delete Fleet Output

KIBANA_DELETE_FLEET_OUTPUT

Tool to delete a specific output configuration in Kibana Fleet. Use when you need to remove an existing output by its ID.

Untrusted display-only summary

Delete Fleet Proxy

KIBANA_DELETE_FLEET_PROXY

Deletes a Fleet proxy configuration by its unique identifier. Fleet proxies enable agents to communicate through proxy servers. Use this action to remove proxy configurations that are no longer needed. The proxy must not be in use by any agent policies or outputs before deletion. Requires 'fleet-settings-all' privileg…

Untrusted display-only summary

Delete List

KIBANA_DELETE_LIST

Deletes a list. Use when you want to delete a list by its ID.

Untrusted display-only summary

Delete Osquery Saved Query

KIBANA_DELETE_OSQUERY_SAVED_QUERIES

Delete a saved Osquery query by its saved object ID. Use this to remove a specific Osquery saved query from Kibana. IMPORTANT: This action requires the 'saved_object_id' (UUID format), not the custom 'id' field. You can obtain the saved_object_id by listing queries first or from the response when creating a query.

Untrusted display-only summary

Delete Saved Object

KIBANA_DELETE_SAVED_OBJECTS

Tool to delete a saved object in Kibana. Use when you need to remove a specific saved object like a visualization or dashboard.

Untrusted display-only summary

Find Kibana Alerts

KIBANA_FIND_ALERTS

Tool to find and/or aggregate detection alerts in Kibana. Use this to retrieve a list of alerts, optionally filtering them with a query and performing aggregations.

Untrusted display-only summary

Get Action Types

KIBANA_GET_ACTION_TYPES

Retrieves all available connector types (actions) in Kibana. Connector types (also called action types) are integrations like Slack, Email, Webhook, ServiceNow, etc. that can be used with alerting rules, cases, and workflows. Use this to discover which connector types are available and their requirements (license, fea…

Untrusted display-only summary

Get Alerting Rules

KIBANA_GET_ALERTING_RULES

Tool to retrieve a list of alerting rules in Kibana. Use when you need to get a paginated set of rules based on specified conditions.

Untrusted display-only summary

Get Rule Types

KIBANA_GET_ALERT_TYPES

Retrieves available rule types (alert types) in Kibana. Returns comprehensive metadata about each rule type including: - Available action groups and variables for action templates - License requirements and authorization details - Category (management, observability, securitySolution) - Configuration options like auto…

Untrusted display-only summary

Get Cases

KIBANA_GET_CASES

Tool to retrieve a list of cases in Kibana. Use when you need to find or list existing security or operational cases, potentially filtering by various attributes like status, assignee, or severity.

Untrusted display-only summary

Get All Connectors

KIBANA_GET_CONNECTORS

Tool to retrieve a list of all connectors in Kibana. Use this tool when you need to get information about available connectors.

Untrusted display-only summary

Get Data Views

KIBANA_GET_DATA_VIEWS

Retrieves all data views (formerly known as index patterns) available in Kibana. Data views define which Elasticsearch indices you want to explore and are used throughout Kibana for features like Discover, Visualize, and Dashboard. This action returns a list of all configured data views with their IDs, names, and inde…

Untrusted display-only summary

Find Detection Engine Rules

KIBANA_GET_DETECTION_ENGINE_RULES_FIND

Retrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options. Use this action to: - List all detection rules in your Kibana security solution - Search for specific rules using KQL filters (by name, tags, severity, enabled status, etc.) - Sort rules by various criteria (name,…

Untrusted display-only summary

Get Endpoint List Items

KIBANA_GET_ENDPOINT_LIST_ITEMS

Retrieves Elastic Endpoint exception list items with filtering, pagination, and sorting capabilities. Use this action to: - List all endpoint exceptions in the security solution - Filter exceptions by specific field values (e.g., host.name:test-host) - Sort and paginate through exception items - Verify existing except…

Untrusted display-only summary

Get Entity Store Engines

KIBANA_GET_ENTITY_STORE_ENGINES

Retrieves all entity store engines configured in Kibana. Entity store engines aggregate and manage entity data for different entity types (user, host, service). This action returns detailed configuration and status information for all engines, including their current status (installing, started, stopped, error), index…

Untrusted display-only summary

List Entity Store Entities

KIBANA_GET_ENTITY_STORE_ENTITIES_LIST

Tool to list entity records in the entity store with support for paging, sorting, and filtering. Use when you need to retrieve a list of entities such as users, hosts, or services.

Untrusted display-only summary

Get Entity Store Status

KIBANA_GET_ENTITY_STORE_STATUS

Retrieves the current status of the Kibana Entity Store and its configured engines. The Entity Store is a security feature that collects and organizes entity data (users, hosts, etc.) from various sources. This action returns the overall status ('not_installed', 'installing', 'running', 'stopped', or 'error') and deta…

Untrusted display-only summary

Get Fleet Agent Policies

KIBANA_GET_FLEET_AGENT_POLICIES

Retrieves a paginated list of Fleet agent policies with filtering, sorting, and optional detailed information. Use this action to: - List all agent policies in your Fleet deployment - Filter policies using KQL queries (e.g., by name, namespace, or other fields) - Get agent enrollment counts per policy (use withAgentCo…

Untrusted display-only summary

Get Fleet Agents Available Versions

KIBANA_GET_FLEET_AGENTS_AVAILABLE_VERSIONS

Tool to retrieve the available versions for Fleet agents. Use when you need to get a list of all available Elastic Agent versions.

Untrusted display-only summary

Get Fleet Agents Setup Status

KIBANA_GET_FLEET_AGENTS_SETUP_STATUS

Check Fleet setup readiness and identify missing requirements. Returns whether Fleet is ready (isReady), lists any missing prerequisites (missing_requirements), and shows optional feature availability. Use this to verify Fleet is properly configured before managing agents or policies.

Untrusted display-only summary

Check Fleet Permissions

KIBANA_GET_FLEET_CHECK_PERMISSIONS

Tool to check the permissions for the Fleet API. Use when you need to verify if the current user has the necessary privileges for Fleet operations.

Untrusted display-only summary

Get Fleet Enrollment API Key

KIBANA_GET_FLEET_ENROLLMENT_API_KEY

Tool to retrieve details of a specific enrollment API key by its ID. Use when you have the ID of an enrollment API key and need its details.

Untrusted display-only summary

Get Fleet Enrollment API Keys

KIBANA_GET_FLEET_ENROLLMENT_API_KEYS

Tool to fetch a list of enrollment API keys. Use when you need to retrieve existing enrollment tokens for Kibana Fleet.

Untrusted display-only summary

Get Fleet EPM Categories

KIBANA_GET_FLEET_EPM_CATEGORIES

Get all available package categories in the Elastic Package Manager (EPM) with package counts. Returns categories like Security, Observability, Cloud, etc., along with the number of packages in each category. Use this to discover available integration categories before browsing or filtering packages.

Untrusted display-only summary

Get Fleet EPM Data Streams

KIBANA_GET_FLEET_EPM_DATA_STREAMS

Tool to retrieve the list of data streams in the Elastic Package Manager. Use when you need to get a list of available data streams, optionally filtering by type, dataset, or categorization.

Untrusted display-only summary

Get Fleet EPM Package Details

KIBANA_GET_FLEET_EPM_PACKAGE_DETAILS

Retrieves comprehensive details for a specific Fleet integration package version from the Elastic Package Manager (EPM). Returns detailed information including: - Package metadata (name, title, description, version, type) - Installation status and requirements - Data streams and their configurations - Assets (dashboar…

Untrusted display-only summary

Get Fleet EPM Package File

KIBANA_GET_FLEET_EPM_PACKAGE_FILE

Retrieves a specific file from an Elastic Package Manager (EPM) package. Use this to access package metadata, documentation, changelogs, or configuration files. Common use cases: inspecting manifest.yml for package details, reading README.md for documentation, or reviewing changelog.yml for version history. Requires a…

Untrusted display-only summary

Get Fleet EPM Packages

KIBANA_GET_FLEET_EPM_PACKAGES

Tool to fetch the list of available packages in the Elastic Package Manager. Use when you need to find available integrations or their details.

Untrusted display-only summary

Provenance

Versioned facts, explicit trust.

The detail snapshot comes from an attributed MIT-licensed repository revision. Safe local icons use exact-match CC0 Simple Icons symbols; unmatched brands use monograms.

Repository
https://github.com/provider-directoryHQ/provider-directory
Commit
85e33f6a81dfe987f6fc3637d48d45052cea8ca5
Generated
2026-09-12
Trust policy
untrusted_display_only

Remote text is plain display metadata only. It must never become an agent prompt, execution policy, OAuth grant, or executable instruction.