Kibana MCP integration
Checks Kibana and cluster health, finds the detection alerts that fired, builds dashboards and data views, and creates alerting rules and connectors.
47actions available
Three actions you can hand over today
Every action runs live through MCP. Nothing to build, nothing to maintain.
Find kibana alerts
Lyro searches Kibana's detection engine for security alerts matching your criteria. You investigate incidents or spot patterns across your security data.
Create alerting rule
Lyro sets up a new alert in Kibana to notify your team of specific conditions. You automate responses to critical events without leaving the chat.
List entity store entities
Lyro retrieves entity records from Kibana's entity store with filtering and pagination. You investigate relationships and attack patterns in your data.
How businesses use Kibana + Lyro
Each card is one request a support team gets, and the Kibana actions Lyro runs to close it.
Find out what actually fired
Lyro finds and aggregates the detection alerts for a period, lists the detection engine rules that produced them, and reads Kibana's own status, so an on-call question starts from facts.
Find Kibana AlertsFind Detection Engine RulesGet Kibana StatusCreate the rule that should have caught it
Lyro checks which rule types the deployment supports, creates the alerting rule against the right condition, and wires up the connector that actually delivers the notification.
Get Rule TypesCreate Alerting RuleCreate Kibana ConnectorStand up a dashboard and the data view under it
Lyro creates the data view that decides which Elasticsearch indices are in scope, builds the dashboard on top of it, and saves the objects that make the whole thing reusable.
Create Data ViewCreate DashboardCreate or Update Saved ObjectAnswer a Fleet or agent rollout question
Lyro reads the Fleet agent policies in place, checks whether Fleet setup is complete and what is missing, and lists the integration packages already installed across the deployment.
Get Fleet Agent PoliciesGet Fleet Agents Setup StatusGet Installed EPM Packages
How it works
Get started in 3 steps
Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Kibana actions it has and picks the ones a request needs.
- 01
Connect Kibana
Authorize the Kibana account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.
- 02
Tell your agent what you need
Describe the job the way you would hand it to a teammate. Lyro maps it to the Kibana actions that close it and chains as many as the request needs.
- 03
Watch it work
The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.
Get started free
Everything else about Kibana
Setup, permissions, and the limits of what Lyro can do inside Kibana.
Yes. Create Case opens a case to track an issue or incident and Get Cases lists the ones already open, so an alert Lyro surfaces becomes a tracked record instead of a message someone has to remember. Connectors created through Create Kibana Connector are what push the notification outward.
Every action available in Kibana
All 47 actions your agent can call on Kibana, straight from the live MCP connection.
Delete alerting rule
Delete an alerting rule in Kibana.
Delete connector
Delete a connector in Kibana.
Delete fleet output
Delete a specific output configuration in Kibana Fleet.
Delete fleet proxy
Deletes a Fleet proxy configuration by its unique identifier.
Delete list
Deletes a list.
Delete osquery saved query
Delete a saved Osquery query by its saved object ID.
Delete saved object
Delete a saved object in Kibana.
Find kibana alerts
Find and/or aggregate detection alerts in Kibana.
Get action types
Retrieves all available connector types (actions) in Kibana.
Get alerting rules
Retrieve a list of alerting rules in Kibana.
Get rule types
Retrieves available rule types (alert types) in Kibana.
Get cases
Retrieve a list of cases in Kibana.
Get all connectors
Retrieve a list of all connectors in Kibana.
Get data views
Retrieves all data views (formerly known as index patterns) available in Kibana.
Find detection engine rules
Retrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options.
Get endpoint list items
Retrieves Elastic Endpoint exception list items with filtering, pagination, and sorting capabilities.
Get entity store engines
Retrieves all entity store engines configured in Kibana.
List entity store entities
List entity records in the entity store with support for paging, sorting, and filtering.
Get entity store status
Retrieves the current status of the Kibana Entity Store and its configured engines.
Get fleet agent policies
Retrieves a paginated list of Fleet agent policies with filtering, sorting, and optional detailed information.
Get fleet agents available versions
Retrieve the available versions for Fleet agents.
Get fleet agents setup status
Check Fleet setup readiness and identify missing requirements.
Check fleet permissions
Check the permissions for the Fleet API.
Get fleet enrollment API key
Retrieve details of a specific enrollment API key by its ID.
Get fleet enrollment API keys
Fetch a list of enrollment API keys.
Get fleet epm categories
Get all available package categories in the Elastic Package Manager (EPM) with package counts.
Get fleet epm data streams
Retrieve the list of data streams in the Elastic Package Manager.
Get fleet epm package details
Retrieves comprehensive details for a specific Fleet integration package version from the Elastic Package Manager (EPM).
Get fleet epm package file
Retrieves a specific file from an Elastic Package Manager (EPM) package.
Get fleet epm packages
Fetch the list of available packages in the Elastic Package Manager.
The tools Kibana sits next to
Same connection, same setup. Pick the next one your team already uses.
Agenty
Extracts structured data from a URL, starts scraping agents and returns their results, maintains input lists, and controls agent schedules.
Corrently
Reads the green power forecast for a German postcode, posts meter readings with a green/grey split, and breaks tariffs down to their cost components.
Google Analytics
Runs GA4 reports on request, checks realtime traffic, creates custom dimensions and audience exports, and audits how a property is wired up.
Microsoft Power Bi
Runs DAX queries against the model, triggers and tracks dataset refreshes, generates report embed tokens, and manages workspace access.
Postgrid verify
Completes and corrects a delivery address while the customer is still in the chat, then cleans stored addresses 2000 at a time.
Stormglass.io
Fetches marine and land weather for a coordinate, returns tide extremes and nearby stations, and reads solar position and elevation on request.

Ready to connect Kibana?
Authorize the account and your agent has all 47 actions from the first conversation.


