Kibana
for LuumenAI

Read Kibana alerts, rules, and cases, then make changes as approved steps

Connect Kibana and your agent can read what your detection and observability stack is doing: alerting rules, detection engine rules, open cases, connectors, and data views. When something needs to change — a new alerting rule, a case opened for an incident, a stale rule removed — the agent shows the exact call first and waits for your approval. Luumen signs in with basic authentication.

The Kibana toolbox

47 tools: 34 read, 13 write. Reads answer instantly. Writes require approval by default. Everything is logged.

  • ReadFind Kibana AlertsFind and/or aggregate detection alerts in Kibana.
  • ReadGet Action TypesRetrieves all available connector types (actions) in Kibana.
  • ReadGet Alerting RulesRetrieve a list of alerting rules in Kibana.
  • ReadGet Rule TypesRetrieves available rule types (alert types) in Kibana.
  • ReadGet CasesRetrieve a list of cases in Kibana.
  • ReadGet All ConnectorsRetrieve a list of all connectors in Kibana.
  • ReadGet Data ViewsRetrieves all data views (formerly known as index patterns) available in Kibana.
  • ReadFind Detection Engine RulesRetrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options.
  • ReadGet Endpoint List ItemsRetrieves Elastic Endpoint exception list items with filtering, pagination, and sorting capabilities.
  • ReadGet Entity Store EnginesRetrieves all entity store engines configured in Kibana.
  • ReadList Entity Store EntitiesList entity records in the entity store with support for paging, sorting, and filtering.
  • ReadGet Entity Store StatusRetrieves the current status of the Kibana Entity Store and its configured engines.
  • ReadGet Fleet Agent PoliciesRetrieves a paginated list of Fleet agent policies with filtering, sorting, and optional detailed information.
  • ReadGet Fleet Agents Available VersionsRetrieve the available versions for Fleet agents.
  • ReadGet Fleet Agents Setup StatusCheck Fleet setup readiness and identify missing requirements.
  • ReadCheck Fleet PermissionsCheck the permissions for the Fleet API.
  • ReadGet Fleet Enrollment API KeyRetrieve details of a specific enrollment API key by its ID.
  • ReadGet Fleet Enrollment API KeysFetch a list of enrollment API keys.
  • ReadGet Fleet EPM CategoriesGet all available package categories in the Elastic Package Manager (EPM) with package counts.
  • ReadGet Fleet EPM Data StreamsRetrieve the list of data streams in the Elastic Package Manager.
  • ReadGet Fleet EPM Package DetailsRetrieves comprehensive details for a specific Fleet integration package version from the Elastic Package Manager (EPM).
  • ReadGet Fleet EPM Package FileRetrieves a specific file from an Elastic Package Manager (EPM) package.
  • ReadGet Fleet EPM PackagesFetch the list of available packages in the Elastic Package Manager.
  • ReadGet Installed EPM PackagesRetrieve the list of installed packages in the Elastic Package Manager.
  • ReadGet Fleet EPM Packages (Limited)Retrieves a limited list of package names from the Elastic Package Manager (EPM) registry.
  • ReadGet EPM Package StatisticsRetrieves usage statistics for a specific Fleet package in Kibana, including the number of package policies and agent policies using the package.
  • ReadGet Fleet Package PoliciesRetrieves a list of Fleet package policies (integration policies) in Kibana.
  • ReadGet Fleet Server HostFetch details of a specific Fleet server host by its item ID.
  • ReadGet Fleet Server HostsRetrieve the list of Fleet Server hosts.
  • ReadGet Index Management IndicesFetch information about indices managed by Kibana's Index Management feature.
  • ReadGet Node MetricsRetrieve statistics for nodes in an Elasticsearch cluster, often visualized in Kibana.
  • ReadGet Reporting JobsRetrieve a list of reporting jobs in Kibana.
  • ReadGet Saved ObjectsRetrieve a list of saved objects in Kibana based on specified criteria.
  • ReadGet Kibana StatusGet the current status of Kibana.
  • WriteDelete Alerting RuleDelete an alerting rule in Kibana. Approval by default
  • WriteDelete ConnectorDelete a connector in Kibana. Approval by default
  • WriteDelete Fleet OutputDelete a specific output configuration in Kibana Fleet. Approval by default
  • WriteDelete Fleet ProxyDeletes a Fleet proxy configuration by its unique identifier. Approval by default
  • WriteDelete ListDeletes a list. Approval by default
  • WriteDelete Osquery Saved QueryDelete a saved Osquery query by its saved object ID. Approval by default
  • WriteDelete Saved ObjectDelete a saved object in Kibana. Approval by default
  • WriteCreate Alerting RuleCreate a new alerting rule in Kibana. Approval by default
  • WriteCreate CaseCreate a new case in Kibana. Approval by default
  • WriteCreate Kibana ConnectorCreate a new connector in Kibana. Approval by default
  • WriteCreate DashboardCreate a new dashboard in Kibana. Approval by default
  • WriteCreate Data ViewCreate a new data view (index pattern) in Kibana. Approval by default
  • WriteCreate or Update Saved ObjectCreate or update a saved object in Kibana. Approval by default

One prompt, start to finish

What a governed Kibana run looks like inside Luumen.

Questions

How does LuumenAI connect to Kibana?

Authorize once with Basic auth. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.

Can LuumenAI change things in Kibana on its own?

Read actions answer immediately. Anything that writes — delete alerting rule, delete connector, delete fleet output, delete fleet proxy, and more — is shown as a plan and requires approval by default, including the 7 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.

Who gets access to the integration?

You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.

Is there an audit trail?

Every call to Kibana — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.

Put Kibana to work with Luumen

Connect in minutes. Every action scoped, approved, and audited from day one.