kibana.api.* operation is listed below with parameter shapes and return types from the plugin Zod schemas.
Alerting
createRule
alerting.createRule
Create a new alerting rule in Kibana
Risk: write
body full type
body full type
deleteRule
alerting.deleteRule
Delete an alerting rule by ID
Risk: destructive
object
Output full type
Output full type
listRules
alerting.listRules
List alerting rules with pagination and filters
Risk: read
data full type
data full type
listRuleTypes
alerting.listRuleTypes
List available alerting rule types
Risk: read
rule_types full type
rule_types full type
Cases
create
cases.create
Create a new case in Kibana
Risk: write
connector full type
connector full type
settings full type
settings full type
body full type
body full type
list
cases.list
Find and list cases with filters
Risk: read
cases full type
cases full type
Connectors
create
connectors.create
Create a new connector in Kibana
Risk: write
config full type
config full type
secrets full type
secrets full type
delete
connectors.delete
Delete a connector by ID
Risk: destructive
object
Output full type
Output full type
get
connectors.get
Retrieve a connector by ID
Risk: read
list
connectors.list
List all connectors in Kibana
Risk: read
object[]
Output full type
Output full type
listTypes
connectors.listTypes
List available connector (action) types
Risk: read
connector_types full type
connector_types full type
Dashboards
create
dashboards.create
Create a new dashboard in Kibana
Risk: write
panels full type
panels full type
delete
dashboards.delete
Delete a dashboard by ID
Risk: destructive
object
Output full type
Output full type
get
dashboards.get
Retrieve a dashboard by ID
Risk: read
search
dashboards.search
Search dashboards in Kibana
Risk: read
data full type
data full type
meta full type
meta full type
upsert
dashboards.upsert
Create or update a dashboard by ID
Risk: write
panels full type
panels full type
Data Views
create
dataViews.create
Create a new data view in Kibana
Risk: write
data_view full type
data_view full type
get
dataViews.get
Retrieve data view details by ID
Risk: read
data_view full type
data_view full type
list
dataViews.list
List all data views in Kibana
Risk: read
data_view full type
data_view full type
Detection
findAlerts
detection.findAlerts
Find and aggregate detection alerts
Risk: read
query full type
query full type
aggs full type
aggs full type
hits full type
hits full type
aggregations full type
aggregations full type
findRules
detection.findRules
Find detection engine rules with filters
Risk: read
data full type
data full type
Fleet
agentPoliciesList
fleet.agentPoliciesList
List Fleet agent policies with pagination
Risk: read
items full type
items full type
agentsSetup
fleet.agentsSetup
Check Fleet agents setup status
Risk: read
agentsVersions
fleet.agentsVersions
List available Fleet agent versions
Risk: read
checkPermissions
fleet.checkPermissions
Check permissions for the Fleet API
Risk: read
enrollmentKeyGet
fleet.enrollmentKeyGet
Retrieve a Fleet enrollment API key by ID
Risk: read
item full type
item full type
enrollmentKeysList
fleet.enrollmentKeysList
List Fleet enrollment API keys
Risk: read
items full type
items full type
epmCategories
fleet.epmCategories
List Fleet EPM package categories
Risk: read
response full type
response full type
epmDataStreams
fleet.epmDataStreams
List Fleet EPM data streams
Risk: read
data_streams full type
data_streams full type
epmPackageDetails
fleet.epmPackageDetails
Retrieve details of a Fleet EPM package version
Risk: read
response full type
response full type
epmPackageFile
fleet.epmPackageFile
Retrieve a file from a Fleet EPM package
Risk: read
epmPackagesInstalled
fleet.epmPackagesInstalled
List installed Fleet EPM packages
Risk: read
response full type
response full type
epmPackagesLimited
fleet.epmPackagesLimited
List Fleet EPM package names only
Risk: read
epmPackagesList
fleet.epmPackagesList
List available Fleet EPM packages
Risk: read
response full type
response full type
epmPackageStats
fleet.epmPackageStats
Retrieve usage statistics for a Fleet package
Risk: read
response full type
response full type
outputDelete
fleet.outputDelete
Delete a Fleet output by ID
Risk: destructive
object
Output full type
Output full type
packagePoliciesList
fleet.packagePoliciesList
List Fleet package policies with pagination
Risk: read
items full type
items full type
proxyDelete
fleet.proxyDelete
Delete a Fleet proxy by ID
Risk: destructive
object
Output full type
Output full type
serverHostGet
fleet.serverHostGet
Retrieve a Fleet Server host by ID
Risk: read
item full type
item full type
serverHostsList
fleet.serverHostsList
List Fleet Server hosts
Risk: read
items full type
items full type
Index
listIndices
index.listIndices
List indices via Index Management (not in the official OpenAPI spec; disabled on serverless, works where Index Management UI is enabled)
Risk: read
indices full type
indices full type
Lists
delete
lists.delete
Delete a value list by ID
Risk: destructive
object
Output full type
Output full type
Metrics
get
metrics.get
Retrieve Elasticsearch node metrics
Risk: read
nodes full type
nodes full type
Osquery
deleteSavedQuery
osquery.deleteSavedQuery
Delete an Osquery saved query by ID
Risk: destructive
object
Output full type
Output full type
Reporting
listJobs
reporting.listJobs
List Kibana reporting jobs (legacy stateful-only API; not in the official OpenAPI spec, 404 on serverless)
Risk: read
jobs full type
jobs full type
Saved Objects
create
savedObjects.create
Create a new saved object in Kibana
Risk: write
attributes full type
attributes full type
references full type
references full type
attributes full type
attributes full type
references full type
references full type
delete
savedObjects.delete
Delete a saved object by type and ID
Risk: destructive
object
Output full type
Output full type
find
savedObjects.find
Find saved objects matching search query or type filters
Risk: read
has_reference full type
has_reference full type
saved_objects full type
saved_objects full type
get
savedObjects.get
Retrieve a specific saved object by type and ID
Risk: read
attributes full type
attributes full type
references full type
references full type
update
savedObjects.update
Update attributes of an existing saved object by type and ID
Risk: write
attributes full type
attributes full type
references full type
references full type
attributes full type
attributes full type
references full type
references full type
Security
entitiesList
security.entitiesList
List Entity Store entities
Risk: read
records full type
records full type
entityStoreEngines
security.entityStoreEngines
Retrieve Entity Store engines (derived from the entity-store status response; no separate engines endpoint exists in the spec)
Risk: read
engines full type
engines full type
entityStoreStatus
security.entityStoreStatus
Retrieve Entity Store status
Risk: read
engines full type
engines full type
listEndpointItems
security.listEndpointItems
List Endpoint exception list items
Risk: read
data full type
data full type
Status
get
status.get
Retrieve health and version status of the Kibana instance
Risk: read
version full type
version full type
status full type
status full type