Connect Kibana with Hookshot™ and your stack

Kibana is a visualization and analytics platform for Elasticsearch, offering dashboards, data exploration, and monitoring capabilities for gaining insights from data

Tools and triggers

What Agents can do in Kibana

Available tools and events after Kibana is connected.

  • Check Fleet Permissions

    Tool to check the permissions for the Fleet API. Use when you need to verify if the current user has the necessary privileges for Fleet operations.

  • Create Alerting Rule

    Tool to create a new alerting rule in Kibana. Use when you need to define a new condition that, when met, triggers an alert and potentially executes predefined actions.

  • Create Case

    Tool to create a new case in Kibana. Use when you need to open and track issues, incidents, or investigations. You can assign users, set severity levels, add tags, and configure external connectors for integration with…

  • Create Dashboard

    Tool to create a new dashboard in Kibana. Use when you need to create a dashboard to visualize data. Dashboards can contain visualizations, saved searches, and other embeddable objects. Note: When using serverless…

  • Create Data View

    Tool to create a new data view (index pattern) in Kibana. Use when you need to define which Elasticsearch indices to query and analyze in Kibana. Data views determine which fields are available in Discover, Visualize…

  • Create Kibana Connector

    Tool to create a new connector in Kibana. Use when you need to integrate Kibana with an external service.

  • Create or Update Saved Object

    Tool to create or update a saved object in Kibana. Use when you need to programmatically manage Kibana dashboards, visualizations, index patterns, etc.

  • Delete Alerting Rule

    Tool to delete an alerting rule in Kibana. Use when you need to remove a specific alerting rule by its ID.

  • Delete Connector

    Tool to delete a connector in Kibana. Use when you need to remove an existing connector.

  • Delete Fleet Output

    Tool to delete a specific output configuration in Kibana Fleet. Use when you need to remove an existing output by its ID.

  • Delete Fleet Proxy

    Deletes a Fleet proxy configuration by its unique identifier. Fleet proxies enable agents to communicate through proxy servers. Use this action to remove proxy configurations that are no longer needed. The proxy must…

  • Delete List

    Deletes a list. Use when you want to delete a list by its ID.

  • Delete Osquery Saved Query

    Delete a saved Osquery query by its saved object ID. Use this to remove a specific Osquery saved query from Kibana. IMPORTANT: This action requires the 'saved_object_id' (UUID format), not the custom 'id' field. You…

  • Delete Saved Object

    Tool to delete a saved object in Kibana. Use when you need to remove a specific saved object like a visualization or dashboard.

  • Find Detection Engine Rules

    Retrieves a paginated list of Kibana detection engine rules with flexible filtering and sorting options. Use this action to: - List all detection rules in your Kibana security solution - Search for specific rules using…

  • Find Kibana Alerts

    Tool to find and/or aggregate detection alerts in Kibana. Use this to retrieve a list of alerts, optionally filtering them with a query and performing aggregations.

  • Get Action Types

    Retrieves all available connector types (actions) in Kibana. Connector types (also called action types) are integrations like Slack, Email, Webhook, ServiceNow, etc. that can be used with alerting rules, cases, and…

  • Get Alerting Rules

    Tool to retrieve a list of alerting rules in Kibana. Use when you need to get a paginated set of rules based on specified conditions.

  • Get All Connectors

    Tool to retrieve a list of all connectors in Kibana. Use this tool when you need to get information about available connectors.

  • Get Cases

    Tool to retrieve a list of cases in Kibana. Use when you need to find or list existing security or operational cases, potentially filtering by various attributes like status, assignee, or severity.

  • Get Data Views

    Retrieves all data views (formerly known as index patterns) available in Kibana. Data views define which Elasticsearch indices you want to explore and are used throughout Kibana for features like Discover, Visualize…

  • Get Endpoint List Items

    Retrieves Elastic Endpoint exception list items with filtering, pagination, and sorting capabilities. Use this action to: - List all endpoint exceptions in the security solution - Filter exceptions by specific field…

  • Get Entity Store Engines

    Retrieves all entity store engines configured in Kibana. Entity store engines aggregate and manage entity data for different entity types (user, host, service). This action returns detailed configuration and status…

  • Get Entity Store Status

    Retrieves the current status of the Kibana Entity Store and its configured engines. The Entity Store is a security feature that collects and organizes entity data (users, hosts, etc.) from various sources. This action…

Setup

Connect Kibana in Hookshot™

Pick a scope, then confirm what can start a Protege and what it can do.

Trigger Access

What can start a Protege from this app.

Tool Access

What a Protege can do after it starts.

Connection scope

Prefer team for production.

Team

Shared credential for production and unattended runs.

Personal

Tied to one user—only when the workflow needs their account.

Chat

Team-scoped for supported chat surfaces.

Full setup guide

Build with us

See Hookshot™ in your stack.

Request early access or book a live walkthrough with the team.

Request Demo
Hookshot™ setup screen — AI agent workflow configuration with model selection, trigger status, and governance controls.