Kibana

Kibana MCP integration

Checks Kibana and cluster health, finds the detection alerts that fired, builds dashboards and data views, and creates alerting rules and connectors.

47actions available

Three actions you can hand over today

Every action runs live through MCP. Nothing to build, nothing to maintain.

  • Find kibana alerts

    Lyro searches Kibana's detection engine for security alerts matching your criteria. You investigate incidents or spot patterns across your security data.

  • Create alerting rule

    Lyro sets up a new alert in Kibana to notify your team of specific conditions. You automate responses to critical events without leaving the chat.

  • List entity store entities

    Lyro retrieves entity records from Kibana's entity store with filtering and pagination. You investigate relationships and attack patterns in your data.

See all 47 actions

How businesses use Kibana + Lyro

Each card is one request a support team gets, and the Kibana actions Lyro runs to close it.

  • Find out what actually fired

    Lyro finds and aggregates the detection alerts for a period, lists the detection engine rules that produced them, and reads Kibana's own status, so an on-call question starts from facts.

    Find Kibana AlertsFind Detection Engine RulesGet Kibana Status
  • Create the rule that should have caught it

    Lyro checks which rule types the deployment supports, creates the alerting rule against the right condition, and wires up the connector that actually delivers the notification.

    Get Rule TypesCreate Alerting RuleCreate Kibana Connector
  • Stand up a dashboard and the data view under it

    Lyro creates the data view that decides which Elasticsearch indices are in scope, builds the dashboard on top of it, and saves the objects that make the whole thing reusable.

    Create Data ViewCreate DashboardCreate or Update Saved Object
  • Answer a Fleet or agent rollout question

    Lyro reads the Fleet agent policies in place, checks whether Fleet setup is complete and what is missing, and lists the integration packages already installed across the deployment.

    Get Fleet Agent PoliciesGet Fleet Agents Setup StatusGet Installed EPM Packages

How it works

Get started in 3 steps

Connect once, then just ask. There is no workflow builder to learn and nothing to maintain — Lyro reads the Kibana actions it has and picks the ones a request needs.

  1. 01

    Connect Kibana

    Authorize the Kibana account your team already uses — one consent screen, no API keys, no mapping tables. Lyro can only do what you granted that account, and you can disconnect it at any time.

  2. 02

    Tell your agent what you need

    Describe the job the way you would hand it to a teammate. Lyro maps it to the Kibana actions that close it and chains as many as the request needs.

  3. 03

    Watch it work

    The agent runs the actions inside the conversation the customer is already in, so nobody copies data between tabs and your team can take over at any point.

    Get started free
Kibana · Lyro

Everything else about Kibana

Setup, permissions, and the limits of what Lyro can do inside Kibana.

  • Yes. Create Case opens a case to track an issue or incident and Get Cases lists the ones already open, so an alert Lyro surfaces becomes a tracked record instead of a message someone has to remember. Connectors created through Create Kibana Connector are what push the notification outward.

Every action available in Kibana

All 47 actions your agent can call on Kibana, straight from the live MCP connection.

  • Delete alerting rule

    Delete an alerting rule in Kibana.

  • Delete connector

    Delete a connector in Kibana.

  • Delete fleet output

    Delete a specific output configuration in Kibana Fleet.

  • Delete fleet proxy

    Deletes a Fleet proxy configuration by its unique identifier.

  • Delete list

    Deletes a list.

  • Delete osquery saved query

    Delete a saved Osquery query by its saved object ID.

  • Delete saved object

    Delete a saved object in Kibana.

  • Find kibana alerts

    Find and/or aggregate detection alerts in Kibana.

  • Get action types

    Retrieves all available connector types (actions) in Kibana.

  • Get alerting rules

    Retrieve a list of alerting rules in Kibana.

  • Get rule types

    Retrieves available rule types (alert types) in Kibana.

  • Get cases

    Retrieve a list of cases in Kibana.

  • Get all connectors

    Retrieve a list of all connectors in Kibana.

  • Get data views

    Retrieves all data views (formerly known as index patterns) available in Kibana.

  • Find detection engine rules

    Retrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options.

  • Get endpoint list items

    Retrieves Elastic Endpoint exception list items with filtering, pagination, and sorting capabilities.

  • Get entity store engines

    Retrieves all entity store engines configured in Kibana.

  • List entity store entities

    List entity records in the entity store with support for paging, sorting, and filtering.

  • Get entity store status

    Retrieves the current status of the Kibana Entity Store and its configured engines.

  • Get fleet agent policies

    Retrieves a paginated list of Fleet agent policies with filtering, sorting, and optional detailed information.

  • Get fleet agents available versions

    Retrieve the available versions for Fleet agents.

  • Get fleet agents setup status

    Check Fleet setup readiness and identify missing requirements.

  • Check fleet permissions

    Check the permissions for the Fleet API.

  • Get fleet enrollment API key

    Retrieve details of a specific enrollment API key by its ID.

  • Get fleet enrollment API keys

    Fetch a list of enrollment API keys.

  • Get fleet epm categories

    Get all available package categories in the Elastic Package Manager (EPM) with package counts.

  • Get fleet epm data streams

    Retrieve the list of data streams in the Elastic Package Manager.

  • Get fleet epm package details

    Retrieves comprehensive details for a specific Fleet integration package version from the Elastic Package Manager (EPM).

  • Get fleet epm package file

    Retrieves a specific file from an Elastic Package Manager (EPM) package.

  • Get fleet epm packages

    Fetch the list of available packages in the Elastic Package Manager.

Ready to connect Kibana?

Authorize the account and your agent has all 47 actions from the first conversation.

Support agent working at a laptop next to the Lyro mascot