Skip to main content

← All sources

Elastic skills

Elasticsearch and Elastic Stack skills skills-hub.ai mirrors 35 skills from Elastic daily, every skill links back to its upstream GitHub source. Install with one command across Claude Code, Cursor, Codex, Windsurf, and any MCP-compatible tool.

Upstream: github.com/elastic/agent-skills

Installing a Elastic skill

Pick a skill below, then run the install command for your AI coding tool. The skills-hub CLI writes the SKILL.md to the right directory and tracks the install in .skills.json so your team gets reproducible installs.

# Install a Elastic skill
npx @skills-hub-ai/cli install <skill-slug>

# Browse all Elastic skills via API
curl https://skills-hub.ai/api/v1/skills?source=elastic

# Browse all sources
open https://skills-hub.ai/sources

Top Elastic skills

See all →

The most-installed skills from Elastic, ranked by adoption.

  1. 01kibana-audit

    Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.

    Buildfrom Elastic
  2. 02cloud-create-project

    Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.

    Buildfrom Elastic
  3. 03kibana-agent-builder

    Create and manage Agent Builder agents and custom tools in Kibana. Use when asked to create, update, delete, test, or inspect agents or tools in Agent Builder.

    Buildfrom Elastic
  4. 04cloud-access-management

    Manage Elastic Cloud organization access: invite users, assign roles to Serverless projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.

    Buildfrom Elastic
  5. 05observability-edot-dotnet-migrate

    Migrate a .NET application from the classic Elastic APM .NET agent to the EDOT .NET SDK. Use when switching from Elastic.Apm.* packages to Elastic.OpenTelemetry.

    Buildfrom Elastic
  6. 06observability-edot-dotnet-instrument

    Instrument a .NET application with the Elastic Distribution of OpenTelemetry (EDOT) .NET SDK for automatic tracing, metrics, and logs. Use when adding observability to a .NET service that has no existing APM agent.

    Buildfrom Elastic
  7. 07elasticsearch-authz

    Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.

    Buildfrom Elastic
  8. 08observability-edot-python-migrate

    Migrate a Python application from the classic Elastic APM Python agent to the EDOT Python agent. Use when switching from elastic-apm to elastic-opentelemetry.

    Buildfrom Elastic
  9. 09cloud-manage-project

    Manages existing Elastic Cloud Serverless projects: list, get, update, delete, reset credentials, resume, and load saved credentials. Connects to existing projects by resolving endpoints and acquiring scoped Elasticsearch API keys. Use when performing day-2 operations on serverless projects, connecting to an existing project, loading or resetting project credentials, or looking up project details.

    Buildfrom Elastic
  10. 10observability-llm-obs

    Monitor LLMs and agentic apps: performance, token/cost, response quality, and workflow orchestration. Use when the user asks about LLM monitoring, GenAI observability, or AI cost/quality.

    Buildfrom Elastic
  11. 11cloud-setup

    Configures Elastic Cloud authentication and environment defaults. Use when setting up EC_API_KEY, configuring Cloud API access, or when another cloud skill requires credentials.

    Buildfrom Elastic
  12. 12observability-edot-java-instrument

    Instrument a Java application with the Elastic Distribution of OpenTelemetry (EDOT) Java agent for automatic tracing, metrics, and logs. Use when adding observability to a Java service that has no existing APM agent.

    Buildfrom Elastic
  13. 13cloud-network-security

    Manage Serverless network security (traffic filters): create, update, and delete IP filters and AWS PrivateLink VPC filters. Use when restricting network access or configuring private connectivity.

    Buildfrom Elastic
  14. 14observability-logs-search

    Search and filter Observability logs using ES|QL. Use when investigating log spikes, errors, or anomalies; getting volume and trends; or drilling into services or containers during incidents.

    Buildfrom Elastic
  15. 15security-alert-triage

    Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.

    Securityfrom Elastic
  16. 16elasticsearch-esql

    Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.

    Buildfrom Elastic
  17. 17kibana-alerting-rules

    Create and manage Kibana alerting rules via REST API or Terraform. Use when creating, updating, or managing rule lifecycle (enable, disable, mute, snooze) or rules-as-code workflows.

    Buildfrom Elastic
  18. 18security-case-management

    Create, search, update, and manage SOC cases via the Kibana Cases API. Use when tracking incidents, linking alerts to cases, adding investigation notes, or managing triage output.

    Securityfrom Elastic
  19. 19kibana-streams

    List, inspect, enable, disable, and resync Kibana Streams via the REST API. Use when the user needs stream details, ingest/query settings, queries, significant events, or attachments.

    Buildfrom Elastic
  20. 20security-generate-security-sample-data

    Generate sample security events, attack scenarios, and synthetic alerts for Elastic Security. Use when demoing, populating dashboards, testing detection rules, or setting up a POC.

    Securityfrom Elastic
  21. 21kibana-connectors

    Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Use when configuring third-party integrations or managing connectors as code.

    Buildfrom Elastic
  22. 22security-detection-rule-management

    Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use for false positives, exceptions, new coverage, noisy rules, or rule management via Kibana API.

    Securityfrom Elastic
  23. 23elasticsearch-security-troubleshooting

    Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.

    Buildfrom Elastic
  24. 24observability-edot-java-migrate

    Migrate a Java application from the classic Elastic APM Java agent to the EDOT Java agent. Use when switching from elastic-apm-agent.jar to elastic-otel-javaagent.jar.

    Buildfrom Elastic

About this source

skills-hub.ai mirrors skills from 90+ official GitHub repositories every day. Each imported skill is parsed from a SKILL.md file in the source repo, gets a security scan and quality score on import, and links back to its upstream source of truth.

Last sync: Jun 14, 2026, 4:11 PM (success).

Elastic skills, frequently asked

What are Elastic skills?

Elastic skills are AI coding skills published by Elastic (Elasticsearch and Elastic Stack skills) and mirrored daily on skills-hub.ai. They are SKILL.md files that follow the open Agent Skills standard, so they work in Claude Code, Cursor, Codex CLI, Windsurf, Copilot, and any MCP-compatible tool.

How many Elastic skills are available?

skills-hub.ai indexes 35 skills from Elastic, synced daily from the upstream GitHub repository (https://github.com/elastic/agent-skills).

How do I install a Elastic skill?

Run `npx @skills-hub-ai/cli install <skill-slug>` in your project. The CLI writes the SKILL.md to the right directory for your AI tool and adds it to your `.skills.json` lockfile so your team gets the same skills at the same versions.

Are these official Elastic skills?

Yes. Every skill from this source is mirrored from Elastic's own GitHub repository (https://github.com/elastic/agent-skills). Each skill page links back to the upstream source of truth, so you can verify the original.