{"id":"134ebf8a-ec1d-41f6-b3d3-f95315a2e4a1","entityType":"agent","slug":"clawhub-hith3sh-kibana-observability","name":"Kibana","canonicalUrl":"https://www.xpersona.co/agent/clawhub-hith3sh-kibana-observability","canonicalPath":"/agent/clawhub-hith3sh-kibana-observability","generatedAt":"2026-10-09T19:20:19.068Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T12:33:44.688Z","emptyReason":null},"description":"Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent polic... Skill: Kibana Owner: hith3sh Summary: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent polic... Tags: latest:1.0.6 Version history: v1.0.6 | 2026-06-09T07:12:18.090Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.6K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s173vws87a7ss71xf9rq53k5gd8568kv:kibana-observability","sourceUrl":"https://clawhub.ai/hith3sh/kibana-observability","homepage":"https://clawhub.ai/hith3sh/skills/kibana-observability","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/hith3sh/kibana-observability","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/hith3sh/skills/kibana-observability","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":68,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent polic..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:33:44.688Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:33:44.688Z","emptyReason":null},"stars":null,"forks":null,"downloads":2644,"packageName":null,"latestVersion":"1.0.6","tractionLabel":"2.6K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T12:33:44.655Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T12:33:44.688Z","lastCrawledAt":"2026-10-09T12:33:44.655Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T12:33:44.655Z","lastVerifiedAt":null,"highlights":[{"version":"1.0.6","createdAt":"2026-06-09T07:12:18.090Z","changelog":"Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source.","fileCount":3,"zipByteSize":6168},{"version":"1.0.5","createdAt":"2026-06-09T06:10:11.894Z","changelog":"- Updated documentation in SKILL.md, including minor formatting improvements and asset (logo) URL versioning. - Removed the file skill-card.md.","fileCount":3,"zipByteSize":6253},{"version":"1.0.4","createdAt":"2026-06-09T04:59:03.682Z","changelog":"- Removed the file skill-card.md from the project. - No user-facing functionality changes.","fileCount":3,"zipByteSize":6184},{"version":"1.0.1","createdAt":"2026-06-08T16:38:52.813Z","changelog":"- Added a Kibana logo image to the skill documentation for improved branding and visual identification. - Removed the file skill-card.md. - No changes to functionality or tool references. Documentation update only.","fileCount":3,"zipByteSize":6086},{"version":"0.1.1","createdAt":"2026-06-07T13:32:20.525Z","changelog":"Full rewrite to new standard: added tool reference tables, 3-step GIF table, architecture diagram, code examples, error handling, and troubleshooting.","fileCount":3,"zipByteSize":6074},{"version":"0.1.0","createdAt":"2026-05-16T19:13:50.214Z","changelog":"Initial release of kibana-observability. - Enables chat-based management of Kibana saved objects, dashboards, spaces, alerts, cases, and observability data via ClawLink integration. - Guides users through installing and pairing the ClawLink plugin with OpenClaw. - Provides step-by-step instructions for connecting Kibana securely, without requiring direct API credential sharing. - Supports dynamic discovery and safe execution of available Kibana tools based on user's catalog and permissions. - Includes clear rules for safe operations, user confirmation on sensitive actions, and use of live ClawLink capabilities only. - Links to relevant ClawLink and Kibana documentation and resources.","fileCount":3,"zipByteSize":3546}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173vws87a7ss71xf9rq53k5gd8568kv:kibana-observability","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T19:20:19.065Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-hith3sh-kibana-observability/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T12:33:44.688Z","emptyReason":null},"readme":"Skill: Kibana\n\nOwner: hith3sh\n\nSummary: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent polic...\n\nTags: latest:1.0.6\n\nVersion history:\n\nv1.0.6 | 2026-06-09T07:12:18.090Z | user\n\nAdd UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source.\n\nv1.0.5 | 2026-06-09T06:10:11.894Z | auto\n\n- Updated documentation in SKILL.md, including minor formatting improvements and asset (logo) URL versioning.\n- Removed the file skill-card.md.\n\nv1.0.4 | 2026-06-09T04:59:03.682Z | auto\n\n- Removed the file skill-card.md from the project.\n- No user-facing functionality changes.\n\nv1.0.1 | 2026-06-08T16:38:52.813Z | auto\n\n- Added a Kibana logo image to the skill documentation for improved branding and visual identification.\n- Removed the file skill-card.md.\n- No changes to functionality or tool references. Documentation update only.\n\nv0.1.1 | 2026-06-07T13:32:20.525Z | user\n\nFull rewrite to new standard: added tool reference tables, 3-step GIF table, architecture diagram, code examples, error handling, and troubleshooting.\n\nv0.1.0 | 2026-05-16T19:13:50.214Z | auto\n\nInitial release of kibana-observability.\n\n- Enables chat-based management of Kibana saved objects, dashboards, spaces, alerts, cases, and observability data via ClawLink integration.\n- Guides users through installing and pairing the ClawLink plugin with OpenClaw.\n- Provides step-by-step instructions for connecting Kibana securely, without requiring direct API credential sharing.\n- Supports dynamic discovery and safe execution of available Kibana tools based on user's catalog and permissions.\n- Includes clear rules for safe operations, user confirmation on sensitive actions, and use of live ClawLink capabilities only.\n- Links to relevant ClawLink and Kibana documentation and resources.\n\nArchive index:\n\nArchive v1.0.6: 3 files, 6168 bytes\n\nFiles: skill-card.md (2390b), SKILL.md (15576b), _meta.json (139b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: kibana-observability\ndescription: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n---\n\n# Kibana\n\n![Kibana](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/kibana.svg?v=2)\n\nManage Elastic Kibana for observability, security, and infrastructure monitoring. Query data views, manage alerting rules, handle detection engine rules, manage Fleet agent policies, and work with cases and security alerts.\n\nThis skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=kibana-observability) for hosted connection flows and credentials so you do not need to configure Kibana API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Kibana |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│  Kibana REST API │\n│   (User Chat)   │     │   (OAuth)    │     │   (v8.x)        │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin  │                       │\n         │  2. Pair Device   │                       │\n         │  3. Connect Kibana │                      │\n         │                   │  4. Secure Token      │\n         │                   │  5. Proxy Requests    │\n         │                   │                       │\n         ▼                   ▼                       ▼\n   ┌──────────┐      ┌──────────┐           ┌──────────┐\n   │  SKILL   │      │ Dashboard│           │  Kibana  │\n   │  File    │      │ Auth     │           │ Stack   │\n   └──────────┘      └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Kibana again.\"\n\n## Quick Start\n\n```bash\n# List data views\nclawlink_call_tool --tool \"kibana_get_data_views\" --params '{}'\n\n# Get alert types\nclawlink_call_tool --tool \"kibana_get_alert_types\" --params '{}'\n\n# List cases\nclawlink_call_tool --tool \"kibana_get_cases\" --params '{}'\n```\n\n## Authentication\n\nAll Kibana tool calls are authenticated automatically by ClawLink using the user's connected Kibana instance.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Kibana API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=kibana and connect Kibana (requires an active Kibana instance).\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `kibana` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration kibana\n```\n\n**Response:** Returns the live tool catalog for Kibana.\n\n### Reconnect\n\nIf Kibana tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=kibana\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration kibana`\n\n## Security & Permissions\n\n- Access is scoped to the connected Kibana instance only.\n- **All write operations require explicit user confirmation.** Before executing any alerting, case, or Fleet action, confirm the target resource and intended effect with the user.\n- Destructive actions (delete rule, delete saved object, delete connector) are marked as high-impact and must be confirmed.\n- Fleet agent policy changes affect deployed agents — confirm before executing.\n- Detection engine rule changes affect security monitoring — confirm before executing.\n\n## Tool Reference\n\n### Data Views\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_data_views` | List all data views (index patterns) available in Kibana | Read |\n\n### Alerting\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_alert_types` | Get available rule types with license requirements and configuration options | Read |\n| `kibana_get_alerting_rules` | List alerting rules with pagination and filtering | Read |\n| `kibana_delete_alerting_rules` | Delete an alerting rule by ID | Write |\n\n### Actions & Connectors\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_action_types` | Get available connector types (Slack, Email, Webhook, ServiceNow, etc.) | Read |\n| `kibana_get_connectors` | List all configured connectors | Read |\n| `kibana_delete_connectors` | Delete a connector by ID | Write |\n\n### Cases\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_cases` | List cases with optional filtering by status, assignee, or severity | Read |\n\n### Saved Objects\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_saved_objects` | Delete a saved object (visualization or dashboard) by ID | Write |\n\n### Security Detection Engine\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_detection_engine_rules_find` | List detection engine rules with KQL filtering and sorting | Read |\n\n### Alerts\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_find_alerts` | Find and aggregate detection alerts with optional query filtering | Read |\n\n### Endpoint Exceptions\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_endpoint_list_items` | List Elastic Endpoint exception list items with filtering | Read |\n\n### Entity Store\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_entity_store_engines` | Get entity store engine configurations and status | Read |\n| `kibana_get_entity_store_entities_list` | List entity records (users, hosts, services) with paging and filtering | Read |\n| `kibana_get_entity_store_status` | Get Entity Store status and configured engines | Read |\n\n### Fleet\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_agent_policies` | List Fleet agent policies with filtering and enrollment counts | Read |\n| `kibana_get_fleet_agents_available_versions` | Get available Elastic Agent versions | Read |\n| `kibana_get_fleet_agents_setup_status` | Check Fleet setup readiness and missing requirements | Read |\n| `kibana_get_fleet_check_permissions` | Verify user permissions for Fleet API operations | Read |\n| `kibana_get_fleet_enrollment_api_keys` | List enrollment API keys for agent authentication | Read |\n| `kibana_get_fleet_enrollment_api_key` | Get details of a specific enrollment API key by ID | Read |\n| `kibana_delete_fleet_output` | Delete a Fleet output configuration by ID | Write |\n| `kibana_delete_fleet_proxy` | Delete a Fleet proxy configuration by ID | Write |\n\n### Fleet EPM (Elastic Package Manager)\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_epm_categories` | Get available package categories with counts | Read |\n| `kibana_get_fleet_epm_packages` | List available Fleet integration packages | Read |\n| `kibana_get_fleet_epm_packages_installed` | List installed Fleet packages | Read |\n| `kibana_get_fleet_epm_package_details` | Get detailed package information including data streams and assets | Read |\n| `kibana_get_fleet_epm_package_stats` | Get usage statistics for a specific Fleet package | Read |\n| `kibana_get_fleet_epm_package_file` | Get a specific file from an EPM package (manifest, README, changelog) | Read |\n| `kibana_get_fleet_epm_data_streams` | List available data streams with filtering | Read |\n\n### Lists\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_list` | Delete a list by ID | Write |\n\n### Osquery\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_osquery_saved_queries` | Delete an Osquery saved query by saved object ID | Write |\n\n## Code Examples\n\n### List data views\n\n```bash\nclawlink_call_tool --tool \"kibana_get_data_views\" \\\n  --params '{}'\n```\n\n### Get alert types\n\n```bash\nclawlink_call_tool --tool \"kibana_get_alert_types\" \\\n  --params '{}'\n```\n\n### List cases\n\n```bash\nclawlink_call_tool --tool \"kibana_get_cases\" \\\n  --params '{}'\n```\n\n### Get detection engine rules\n\n```bash\nclawlink_call_tool --tool \"kibana_get_detection_engine_rules_find\" \\\n  --params '{\"page\": 1, \"per_page\": 25}'\n```\n\n### Get Fleet agent policies\n\n```bash\nclawlink_call_tool --tool \"kibana_get_fleet_agent_policies\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Kibana is connected.\n2. Call `clawlink_list_tools --integration kibana` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `kibana`.\n5. If no Kibana tools appear, direct the user to https://claw-link.dev/dashboard?add=kibana.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                     │\n│                                                             │\n│  Example: List data views → Get index fields → Query data  │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call          │\n│                                                             │\n│  Example: Preview rule delete → User approves → Execute     │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- Alert types include Elasticsearch query alerts, index threshold alerts, machine learning anomaly detection, and security detection rules.\n- Connector types (action types) include Slack, Email, Webhook, ServiceNow, and more — each with different license requirements.\n- Fleet agent policies define configuration for groups of Elastic Agents including which integrations are enabled.\n- Entity store aggregates and manages entity data (users, hosts, services) from various sources.\n- Endpoint exception list contains security exceptions applied to Elastic Endpoint agents.\n- Osquery saved queries require the saved_object_id (UUID format), not the custom id field.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration kibana`. |\n| Missing connection | Kibana is not connected. Direct the user to https://claw-link.dev/dashboard?add=kibana. |\n| Permission error | The authenticated user lacks permission for this operation. Check Kibana roles. |\n| Fleet not ready | Fleet is not properly configured. Check setup status first. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Fleet Not Ready\n\n1. Check Fleet setup status:\n   ```bash\n   clawlink_call_tool --tool \"kibana_get_fleet_agents_setup_status\" --params '{}'\n   ```\n2. Review missing prerequisites and address them before managing agents or policies.\n3. Verify Elasticsearch connection and license status.\n\n## Resources\n\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html)\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)\n- [Elastic Security Solution](https://www.elastic.co/security)\n- ClawLink: https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=kibana-observability\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [New Relic Observability](https://clawhub.ai/hith3sh/new-relic-observability) — For New Relic monitoring and alerting\n- [Make Automation](https://clawhub.ai/hith3sh/make-automation) — For Make.com workflow automation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=kibana-observability)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"kibana-observability\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1780989138090\n}\n\nFile v1.0.6:skill-card.md\n\n## Description:\n\nManage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hith3sh](https://clawhub.ai/user/hith3sh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, site reliability engineers, and security operations teams use this skill to inspect and manage Kibana observability and security resources through ClawLink-connected Kibana tools.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill requires enabling an unpinned third-party ClawLink plugin that handles Kibana credentials.\n\nMitigation: Install only if the publisher is trusted, verify the plugin source and version where possible, and use a dedicated Kibana identity with least-privilege access.\n\nRisk: Kibana write operations can delete or modify alerting rules, connectors, saved objects, Fleet outputs, Fleet proxies, lists, and security monitoring resources.\n\nMitigation: Review tool previews carefully and approve delete, Fleet, and security changes only after the target resource and intended effect match the user's request.\n\n## Reference(s):\n\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html)\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)\n- [Elastic Security Solution](https://www.elastic.co/security)\n- [ClawLink OpenClaw Documentation](https://docs.claw-link.dev/openclaw)\n- [ClawLink Kibana Connection](https://claw-link.dev/dashboard?add=kibana)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration instructions, API calls, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON parameters]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes confirmation guidance for write and destructive Kibana operations.]\n\n## Skill Version(s):\n\n1.0.6 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.5: 3 files, 6253 bytes\n\nFiles: skill-card.md (2920b), SKILL.md (15357b), _meta.json (139b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: kibana-observability\ndescription: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n---\n\n# Kibana\n\n![Kibana](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/kibana.svg?v=2)\n\nManage Elastic Kibana for observability, security, and infrastructure monitoring. Query data views, manage alerting rules, handle detection engine rules, manage Fleet agent policies, and work with cases and security alerts.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure Kibana API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Kibana |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│  Kibana REST API │\n│   (User Chat)   │     │   (OAuth)    │     │   (v8.x)        │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin  │                       │\n         │  2. Pair Device   │                       │\n         │  3. Connect Kibana │                      │\n         │                   │  4. Secure Token      │\n         │                   │  5. Proxy Requests    │\n         │                   │                       │\n         ▼                   ▼                       ▼\n   ┌──────────┐      ┌──────────┐           ┌──────────┐\n   │  SKILL   │      │ Dashboard│           │  Kibana  │\n   │  File    │      │ Auth     │           │ Stack   │\n   └──────────┘      └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Kibana again.\"\n\n## Quick Start\n\n```bash\n# List data views\nclawlink_call_tool --tool \"kibana_get_data_views\" --params '{}'\n\n# Get alert types\nclawlink_call_tool --tool \"kibana_get_alert_types\" --params '{}'\n\n# List cases\nclawlink_call_tool --tool \"kibana_get_cases\" --params '{}'\n```\n\n## Authentication\n\nAll Kibana tool calls are authenticated automatically by ClawLink using the user's connected Kibana instance.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Kibana API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=kibana and connect Kibana (requires an active Kibana instance).\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `kibana` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration kibana\n```\n\n**Response:** Returns the live tool catalog for Kibana.\n\n### Reconnect\n\nIf Kibana tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=kibana\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration kibana`\n\n## Security & Permissions\n\n- Access is scoped to the connected Kibana instance only.\n- **All write operations require explicit user confirmation.** Before executing any alerting, case, or Fleet action, confirm the target resource and intended effect with the user.\n- Destructive actions (delete rule, delete saved object, delete connector) are marked as high-impact and must be confirmed.\n- Fleet agent policy changes affect deployed agents — confirm before executing.\n- Detection engine rule changes affect security monitoring — confirm before executing.\n\n## Tool Reference\n\n### Data Views\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_data_views` | List all data views (index patterns) available in Kibana | Read |\n\n### Alerting\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_alert_types` | Get available rule types with license requirements and configuration options | Read |\n| `kibana_get_alerting_rules` | List alerting rules with pagination and filtering | Read |\n| `kibana_delete_alerting_rules` | Delete an alerting rule by ID | Write |\n\n### Actions & Connectors\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_action_types` | Get available connector types (Slack, Email, Webhook, ServiceNow, etc.) | Read |\n| `kibana_get_connectors` | List all configured connectors | Read |\n| `kibana_delete_connectors` | Delete a connector by ID | Write |\n\n### Cases\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_cases` | List cases with optional filtering by status, assignee, or severity | Read |\n\n### Saved Objects\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_saved_objects` | Delete a saved object (visualization or dashboard) by ID | Write |\n\n### Security Detection Engine\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_detection_engine_rules_find` | List detection engine rules with KQL filtering and sorting | Read |\n\n### Alerts\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_find_alerts` | Find and aggregate detection alerts with optional query filtering | Read |\n\n### Endpoint Exceptions\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_endpoint_list_items` | List Elastic Endpoint exception list items with filtering | Read |\n\n### Entity Store\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_entity_store_engines` | Get entity store engine configurations and status | Read |\n| `kibana_get_entity_store_entities_list` | List entity records (users, hosts, services) with paging and filtering | Read |\n| `kibana_get_entity_store_status` | Get Entity Store status and configured engines | Read |\n\n### Fleet\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_agent_policies` | List Fleet agent policies with filtering and enrollment counts | Read |\n| `kibana_get_fleet_agents_available_versions` | Get available Elastic Agent versions | Read |\n| `kibana_get_fleet_agents_setup_status` | Check Fleet setup readiness and missing requirements | Read |\n| `kibana_get_fleet_check_permissions` | Verify user permissions for Fleet API operations | Read |\n| `kibana_get_fleet_enrollment_api_keys` | List enrollment API keys for agent authentication | Read |\n| `kibana_get_fleet_enrollment_api_key` | Get details of a specific enrollment API key by ID | Read |\n| `kibana_delete_fleet_output` | Delete a Fleet output configuration by ID | Write |\n| `kibana_delete_fleet_proxy` | Delete a Fleet proxy configuration by ID | Write |\n\n### Fleet EPM (Elastic Package Manager)\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_epm_categories` | Get available package categories with counts | Read |\n| `kibana_get_fleet_epm_packages` | List available Fleet integration packages | Read |\n| `kibana_get_fleet_epm_packages_installed` | List installed Fleet packages | Read |\n| `kibana_get_fleet_epm_package_details` | Get detailed package information including data streams and assets | Read |\n| `kibana_get_fleet_epm_package_stats` | Get usage statistics for a specific Fleet package | Read |\n| `kibana_get_fleet_epm_package_file` | Get a specific file from an EPM package (manifest, README, changelog) | Read |\n| `kibana_get_fleet_epm_data_streams` | List available data streams with filtering | Read |\n\n### Lists\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_list` | Delete a list by ID | Write |\n\n### Osquery\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_osquery_saved_queries` | Delete an Osquery saved query by saved object ID | Write |\n\n## Code Examples\n\n### List data views\n\n```bash\nclawlink_call_tool --tool \"kibana_get_data_views\" \\\n  --params '{}'\n```\n\n### Get alert types\n\n```bash\nclawlink_call_tool --tool \"kibana_get_alert_types\" \\\n  --params '{}'\n```\n\n### List cases\n\n```bash\nclawlink_call_tool --tool \"kibana_get_cases\" \\\n  --params '{}'\n```\n\n### Get detection engine rules\n\n```bash\nclawlink_call_tool --tool \"kibana_get_detection_engine_rules_find\" \\\n  --params '{\"page\": 1, \"per_page\": 25}'\n```\n\n### Get Fleet agent policies\n\n```bash\nclawlink_call_tool --tool \"kibana_get_fleet_agent_policies\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Kibana is connected.\n2. Call `clawlink_list_tools --integration kibana` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `kibana`.\n5. If no Kibana tools appear, direct the user to https://claw-link.dev/dashboard?add=kibana.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                     │\n│                                                             │\n│  Example: List data views → Get index fields → Query data  │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call          │\n│                                                             │\n│  Example: Preview rule delete → User approves → Execute     │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- Alert types include Elasticsearch query alerts, index threshold alerts, machine learning anomaly detection, and security detection rules.\n- Connector types (action types) include Slack, Email, Webhook, ServiceNow, and more — each with different license requirements.\n- Fleet agent policies define configuration for groups of Elastic Agents including which integrations are enabled.\n- Entity store aggregates and manages entity data (users, hosts, services) from various sources.\n- Endpoint exception list contains security exceptions applied to Elastic Endpoint agents.\n- Osquery saved queries require the saved_object_id (UUID format), not the custom id field.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration kibana`. |\n| Missing connection | Kibana is not connected. Direct the user to https://claw-link.dev/dashboard?add=kibana. |\n| Permission error | The authenticated user lacks permission for this operation. Check Kibana roles. |\n| Fleet not ready | Fleet is not properly configured. Check setup status first. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Fleet Not Ready\n\n1. Check Fleet setup status:\n   ```bash\n   clawlink_call_tool --tool \"kibana_get_fleet_agents_setup_status\" --params '{}'\n   ```\n2. Review missing prerequisites and address them before managing agents or policies.\n3. Verify Elasticsearch connection and license status.\n\n## Resources\n\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html)\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)\n- [Elastic Security Solution](https://www.elastic.co/security)\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [New Relic Observability](https://clawhub.ai/hith3sh/new-relic-observability) — For New Relic monitoring and alerting\n- [Make Automation](https://clawhub.ai/hith3sh/make-automation) — For Make.com workflow automation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"kibana-observability\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1780985411894\n}\n\nFile v1.0.5:skill-card.md\n\n## Description: <br>\nManage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, observability teams, and security operators use this skill to inspect and manage a connected Kibana environment through ClawLink. It supports data views, alerting, detection rules, cases, Fleet policies, endpoint exceptions, entity store status, and related Kibana workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can operate against a connected Kibana environment with access to sensitive observability and security data. <br>\nMitigation: Use a least-privilege Kibana account and install the skill only for environments where ClawLink-mediated access is intended. <br>\nRisk: Some supported actions can delete or change Kibana resources such as alerting rules, connectors, saved objects, Fleet outputs, proxies, lists, and saved queries. <br>\nMitigation: Preview and explicitly confirm destructive or high-impact actions only after checking the target resource and intended effect. <br>\nRisk: Kibana tools depend on a working ClawLink connection and the user's connected Kibana permissions. <br>\nMitigation: Verify the ClawLink integration and tool catalog before use, and check Kibana role permissions when an operation fails. <br>\n\n\n## Reference(s): <br>\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html) <br>\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html) <br>\n- [Elastic Security Solution](https://www.elastic.co/security) <br>\n- [ClawLink](https://claw-link.dev) <br>\n- [ClawLink OpenClaw Documentation](https://docs.claw-link.dev/openclaw) <br>\n- [ClawHub Skill Page](https://clawhub.ai/hith3sh/kibana-observability) <br>\n- [Publisher Profile](https://clawhub.ai/user/hith3sh) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell command examples and tool-call guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May guide authenticated ClawLink tool calls against the user's connected Kibana instance.] <br>\n\n## Skill Version(s): <br>\n1.0.5 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.4: 3 files, 6184 bytes\n\nFiles: skill-card.md (2695b), SKILL.md (15353b), _meta.json (139b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: kibana-observability\ndescription: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n---\n\n# Kibana\n\n![Kibana](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/kibana.svg)\n\nManage Elastic Kibana for observability, security, and infrastructure monitoring. Query data views, manage alerting rules, handle detection engine rules, manage Fleet agent policies, and work with cases and security alerts.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure Kibana API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Kibana |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│  Kibana REST API │\n│   (User Chat)   │     │   (OAuth)    │     │   (v8.x)        │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin  │                       │\n         │  2. Pair Device   │                       │\n         │  3. Connect Kibana │                      │\n         │                   │  4. Secure Token      │\n         │                   │  5. Proxy Requests    │\n         │                   │                       │\n         ▼                   ▼                       ▼\n   ┌──────────┐      ┌──────────┐           ┌──────────┐\n   │  SKILL   │      │ Dashboard│           │  Kibana  │\n   │  File    │      │ Auth     │           │ Stack   │\n   └──────────┘      └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Kibana again.\"\n\n## Quick Start\n\n```bash\n# List data views\nclawlink_call_tool --tool \"kibana_get_data_views\" --params '{}'\n\n# Get alert types\nclawlink_call_tool --tool \"kibana_get_alert_types\" --params '{}'\n\n# List cases\nclawlink_call_tool --tool \"kibana_get_cases\" --params '{}'\n```\n\n## Authentication\n\nAll Kibana tool calls are authenticated automatically by ClawLink using the user's connected Kibana instance.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Kibana API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=kibana and connect Kibana (requires an active Kibana instance).\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `kibana` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration kibana\n```\n\n**Response:** Returns the live tool catalog for Kibana.\n\n### Reconnect\n\nIf Kibana tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=kibana\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration kibana`\n\n## Security & Permissions\n\n- Access is scoped to the connected Kibana instance only.\n- **All write operations require explicit user confirmation.** Before executing any alerting, case, or Fleet action, confirm the target resource and intended effect with the user.\n- Destructive actions (delete rule, delete saved object, delete connector) are marked as high-impact and must be confirmed.\n- Fleet agent policy changes affect deployed agents — confirm before executing.\n- Detection engine rule changes affect security monitoring — confirm before executing.\n\n## Tool Reference\n\n### Data Views\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_data_views` | List all data views (index patterns) available in Kibana | Read |\n\n### Alerting\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_alert_types` | Get available rule types with license requirements and configuration options | Read |\n| `kibana_get_alerting_rules` | List alerting rules with pagination and filtering | Read |\n| `kibana_delete_alerting_rules` | Delete an alerting rule by ID | Write |\n\n### Actions & Connectors\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_action_types` | Get available connector types (Slack, Email, Webhook, ServiceNow, etc.) | Read |\n| `kibana_get_connectors` | List all configured connectors | Read |\n| `kibana_delete_connectors` | Delete a connector by ID | Write |\n\n### Cases\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_cases` | List cases with optional filtering by status, assignee, or severity | Read |\n\n### Saved Objects\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_saved_objects` | Delete a saved object (visualization or dashboard) by ID | Write |\n\n### Security Detection Engine\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_detection_engine_rules_find` | List detection engine rules with KQL filtering and sorting | Read |\n\n### Alerts\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_find_alerts` | Find and aggregate detection alerts with optional query filtering | Read |\n\n### Endpoint Exceptions\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_endpoint_list_items` | List Elastic Endpoint exception list items with filtering | Read |\n\n### Entity Store\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_entity_store_engines` | Get entity store engine configurations and status | Read |\n| `kibana_get_entity_store_entities_list` | List entity records (users, hosts, services) with paging and filtering | Read |\n| `kibana_get_entity_store_status` | Get Entity Store status and configured engines | Read |\n\n### Fleet\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_agent_policies` | List Fleet agent policies with filtering and enrollment counts | Read |\n| `kibana_get_fleet_agents_available_versions` | Get available Elastic Agent versions | Read |\n| `kibana_get_fleet_agents_setup_status` | Check Fleet setup readiness and missing requirements | Read |\n| `kibana_get_fleet_check_permissions` | Verify user permissions for Fleet API operations | Read |\n| `kibana_get_fleet_enrollment_api_keys` | List enrollment API keys for agent authentication | Read |\n| `kibana_get_fleet_enrollment_api_key` | Get details of a specific enrollment API key by ID | Read |\n| `kibana_delete_fleet_output` | Delete a Fleet output configuration by ID | Write |\n| `kibana_delete_fleet_proxy` | Delete a Fleet proxy configuration by ID | Write |\n\n### Fleet EPM (Elastic Package Manager)\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_epm_categories` | Get available package categories with counts | Read |\n| `kibana_get_fleet_epm_packages` | List available Fleet integration packages | Read |\n| `kibana_get_fleet_epm_packages_installed` | List installed Fleet packages | Read |\n| `kibana_get_fleet_epm_package_details` | Get detailed package information including data streams and assets | Read |\n| `kibana_get_fleet_epm_package_stats` | Get usage statistics for a specific Fleet package | Read |\n| `kibana_get_fleet_epm_package_file` | Get a specific file from an EPM package (manifest, README, changelog) | Read |\n| `kibana_get_fleet_epm_data_streams` | List available data streams with filtering | Read |\n\n### Lists\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_list` | Delete a list by ID | Write |\n\n### Osquery\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_osquery_saved_queries` | Delete an Osquery saved query by saved object ID | Write |\n\n## Code Examples\n\n### List data views\n\n```bash\nclawlink_call_tool --tool \"kibana_get_data_views\" \\\n  --params '{}'\n```\n\n### Get alert types\n\n```bash\nclawlink_call_tool --tool \"kibana_get_alert_types\" \\\n  --params '{}'\n```\n\n### List cases\n\n```bash\nclawlink_call_tool --tool \"kibana_get_cases\" \\\n  --params '{}'\n```\n\n### Get detection engine rules\n\n```bash\nclawlink_call_tool --tool \"kibana_get_detection_engine_rules_find\" \\\n  --params '{\"page\": 1, \"per_page\": 25}'\n```\n\n### Get Fleet agent policies\n\n```bash\nclawlink_call_tool --tool \"kibana_get_fleet_agent_policies\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Kibana is connected.\n2. Call `clawlink_list_tools --integration kibana` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `kibana`.\n5. If no Kibana tools appear, direct the user to https://claw-link.dev/dashboard?add=kibana.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                     │\n│                                                             │\n│  Example: List data views → Get index fields → Query data  │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call          │\n│                                                             │\n│  Example: Preview rule delete → User approves → Execute     │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- Alert types include Elasticsearch query alerts, index threshold alerts, machine learning anomaly detection, and security detection rules.\n- Connector types (action types) include Slack, Email, Webhook, ServiceNow, and more — each with different license requirements.\n- Fleet agent policies define configuration for groups of Elastic Agents including which integrations are enabled.\n- Entity store aggregates and manages entity data (users, hosts, services) from various sources.\n- Endpoint exception list contains security exceptions applied to Elastic Endpoint agents.\n- Osquery saved queries require the saved_object_id (UUID format), not the custom id field.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration kibana`. |\n| Missing connection | Kibana is not connected. Direct the user to https://claw-link.dev/dashboard?add=kibana. |\n| Permission error | The authenticated user lacks permission for this operation. Check Kibana roles. |\n| Fleet not ready | Fleet is not properly configured. Check setup status first. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Fleet Not Ready\n\n1. Check Fleet setup status:\n   ```bash\n   clawlink_call_tool --tool \"kibana_get_fleet_agents_setup_status\" --params '{}'\n   ```\n2. Review missing prerequisites and address them before managing agents or policies.\n3. Verify Elasticsearch connection and license status.\n\n## Resources\n\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html)\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)\n- [Elastic Security Solution](https://www.elastic.co/security)\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [New Relic Observability](https://clawhub.ai/hith3sh/new-relic-observability) — For New Relic monitoring and alerting\n- [Make Automation](https://clawhub.ai/hith3sh/make-automation) — For Make.com workflow automation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"kibana-observability\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1780981143682\n}\n\nFile v1.0.4:skill-card.md\n\n## Description: <br>\nManage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, operators, and security teams use this skill to connect an agent to a user's Kibana environment for observability, alerting, Fleet, case, and Elastic Security workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can read sensitive Kibana security and observability data from the connected instance. <br>\nMitigation: Review the Kibana account permissions before use and connect an account with only the access needed for the intended workflow. <br>\nRisk: The skill can perform destructive Kibana actions such as deleting rules, saved objects, connectors, lists, or Fleet-related resources after confirmation. <br>\nMitigation: Confirm the target resource and intended effect before write actions, and preview unfamiliar or high-impact operations before execution. <br>\nRisk: Fleet and detection engine changes can affect deployed Elastic Agents and security monitoring. <br>\nMitigation: Validate the current Fleet or detection rule state first, then apply changes only after explicit user approval. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/hith3sh/kibana-observability) <br>\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html) <br>\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html) <br>\n- [Elastic Security Solution](https://www.elastic.co/security) <br>\n- [ClawLink OpenClaw Documentation](https://docs.claw-link.dev/openclaw) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and tool call examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May guide read and write operations through ClawLink tools connected to the user's Kibana instance.] <br>\n\n## Skill Version(s): <br>\n1.0.4 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 3 files, 6086 bytes\n\nFiles: skill-card.md (2470b), SKILL.md (15353b), _meta.json (139b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: kibana-observability\ndescription: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n---\n\n# Kibana\n\n![Kibana](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/kibana.svg)\n\nManage Elastic Kibana for observability, security, and infrastructure monitoring. Query data views, manage alerting rules, handle detection engine rules, manage Fleet agent policies, and work with cases and security alerts.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure Kibana API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Kibana |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│  Kibana REST API │\n│   (User Chat)   │     │   (OAuth)    │     │   (v8.x)        │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin  │                       │\n         │  2. Pair Device   │                       │\n         │  3. Connect Kibana │                      │\n         │                   │  4. Secure Token      │\n         │                   │  5. Proxy Requests    │\n         │                   │                       │\n         ▼                   ▼                       ▼\n   ┌──────────┐      ┌──────────┐           ┌──────────┐\n   │  SKILL   │      │ Dashboard│           │  Kibana  │\n   │  File    │      │ Auth     │           │ Stack   │\n   └──────────┘      └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Kibana again.\"\n\n## Quick Start\n\n```bash\n# List data views\nclawlink_call_tool --tool \"kibana_get_data_views\" --params '{}'\n\n# Get alert types\nclawlink_call_tool --tool \"kibana_get_alert_types\" --params '{}'\n\n# List cases\nclawlink_call_tool --tool \"kibana_get_cases\" --params '{}'\n```\n\n## Authentication\n\nAll Kibana tool calls are authenticated automatically by ClawLink using the user's connected Kibana instance.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Kibana API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=kibana and connect Kibana (requires an active Kibana instance).\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `kibana` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration kibana\n```\n\n**Response:** Returns the live tool catalog for Kibana.\n\n### Reconnect\n\nIf Kibana tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=kibana\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration kibana`\n\n## Security & Permissions\n\n- Access is scoped to the connected Kibana instance only.\n- **All write operations require explicit user confirmation.** Before executing any alerting, case, or Fleet action, confirm the target resource and intended effect with the user.\n- Destructive actions (delete rule, delete saved object, delete connector) are marked as high-impact and must be confirmed.\n- Fleet agent policy changes affect deployed agents — confirm before executing.\n- Detection engine rule changes affect security monitoring — confirm before executing.\n\n## Tool Reference\n\n### Data Views\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_data_views` | List all data views (index patterns) available in Kibana | Read |\n\n### Alerting\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_alert_types` | Get available rule types with license requirements and configuration options | Read |\n| `kibana_get_alerting_rules` | List alerting rules with pagination and filtering | Read |\n| `kibana_delete_alerting_rules` | Delete an alerting rule by ID | Write |\n\n### Actions & Connectors\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_action_types` | Get available connector types (Slack, Email, Webhook, ServiceNow, etc.) | Read |\n| `kibana_get_connectors` | List all configured connectors | Read |\n| `kibana_delete_connectors` | Delete a connector by ID | Write |\n\n### Cases\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_cases` | List cases with optional filtering by status, assignee, or severity | Read |\n\n### Saved Objects\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_saved_objects` | Delete a saved object (visualization or dashboard) by ID | Write |\n\n### Security Detection Engine\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_detection_engine_rules_find` | List detection engine rules with KQL filtering and sorting | Read |\n\n### Alerts\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_find_alerts` | Find and aggregate detection alerts with optional query filtering | Read |\n\n### Endpoint Exceptions\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_endpoint_list_items` | List Elastic Endpoint exception list items with filtering | Read |\n\n### Entity Store\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_entity_store_engines` | Get entity store engine configurations and status | Read |\n| `kibana_get_entity_store_entities_list` | List entity records (users, hosts, services) with paging and filtering | Read |\n| `kibana_get_entity_store_status` | Get Entity Store status and configured engines | Read |\n\n### Fleet\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_agent_policies` | List Fleet agent policies with filtering and enrollment counts | Read |\n| `kibana_get_fleet_agents_available_versions` | Get available Elastic Agent versions | Read |\n| `kibana_get_fleet_agents_setup_status` | Check Fleet setup readiness and missing requirements | Read |\n| `kibana_get_fleet_check_permissions` | Verify user permissions for Fleet API operations | Read |\n| `kibana_get_fleet_enrollment_api_keys` | List enrollment API keys for agent authentication | Read |\n| `kibana_get_fleet_enrollment_api_key` | Get details of a specific enrollment API key by ID | Read |\n| `kibana_delete_fleet_output` | Delete a Fleet output configuration by ID | Write |\n| `kibana_delete_fleet_proxy` | Delete a Fleet proxy configuration by ID | Write |\n\n### Fleet EPM (Elastic Package Manager)\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_epm_categories` | Get available package categories with counts | Read |\n| `kibana_get_fleet_epm_packages` | List available Fleet integration packages | Read |\n| `kibana_get_fleet_epm_packages_installed` | List installed Fleet packages | Read |\n| `kibana_get_fleet_epm_package_details` | Get detailed package information including data streams and assets | Read |\n| `kibana_get_fleet_epm_package_stats` | Get usage statistics for a specific Fleet package | Read |\n| `kibana_get_fleet_epm_package_file` | Get a specific file from an EPM package (manifest, README, changelog) | Read |\n| `kibana_get_fleet_epm_data_streams` | List available data streams with filtering | Read |\n\n### Lists\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_list` | Delete a list by ID | Write |\n\n### Osquery\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_osquery_saved_queries` | Delete an Osquery saved query by saved object ID | Write |\n\n## Code Examples\n\n### List data views\n\n```bash\nclawlink_call_tool --tool \"kibana_get_data_views\" \\\n  --params '{}'\n```\n\n### Get alert types\n\n```bash\nclawlink_call_tool --tool \"kibana_get_alert_types\" \\\n  --params '{}'\n```\n\n### List cases\n\n```bash\nclawlink_call_tool --tool \"kibana_get_cases\" \\\n  --params '{}'\n```\n\n### Get detection engine rules\n\n```bash\nclawlink_call_tool --tool \"kibana_get_detection_engine_rules_find\" \\\n  --params '{\"page\": 1, \"per_page\": 25}'\n```\n\n### Get Fleet agent policies\n\n```bash\nclawlink_call_tool --tool \"kibana_get_fleet_agent_policies\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Kibana is connected.\n2. Call `clawlink_list_tools --integration kibana` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `kibana`.\n5. If no Kibana tools appear, direct the user to https://claw-link.dev/dashboard?add=kibana.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                     │\n│                                                             │\n│  Example: List data views → Get index fields → Query data  │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call          │\n│                                                             │\n│  Example: Preview rule delete → User approves → Execute     │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- Alert types include Elasticsearch query alerts, index threshold alerts, machine learning anomaly detection, and security detection rules.\n- Connector types (action types) include Slack, Email, Webhook, ServiceNow, and more — each with different license requirements.\n- Fleet agent policies define configuration for groups of Elastic Agents including which integrations are enabled.\n- Entity store aggregates and manages entity data (users, hosts, services) from various sources.\n- Endpoint exception list contains security exceptions applied to Elastic Endpoint agents.\n- Osquery saved queries require the saved_object_id (UUID format), not the custom id field.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration kibana`. |\n| Missing connection | Kibana is not connected. Direct the user to https://claw-link.dev/dashboard?add=kibana. |\n| Permission error | The authenticated user lacks permission for this operation. Check Kibana roles. |\n| Fleet not ready | Fleet is not properly configured. Check setup status first. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Fleet Not Ready\n\n1. Check Fleet setup status:\n   ```bash\n   clawlink_call_tool --tool \"kibana_get_fleet_agents_setup_status\" --params '{}'\n   ```\n2. Review missing prerequisites and address them before managing agents or policies.\n3. Verify Elasticsearch connection and license status.\n\n## Resources\n\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html)\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)\n- [Elastic Security Solution](https://www.elastic.co/security)\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [New Relic Observability](https://clawhub.ai/hith3sh/new-relic-observability) — For New Relic monitoring and alerting\n- [Make Automation](https://clawhub.ai/hith3sh/make-automation) — For Make.com workflow automation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"kibana-observability\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1780936732813\n}\n\nFile v1.0.1:skill-card.md\n\n## Description: <br>\nManage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nObservability and security engineers use this skill to work with a connected Kibana instance through ClawLink, including data views, alerting, detection rules, Fleet policies, cases, and security alerts. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can guide sensitive Kibana administrative actions, including write or delete operations for alerting, saved objects, connectors, Fleet resources, lists, and Osquery saved queries. <br>\nMitigation: Use a least-privilege Kibana account and confirm the target resource and intended effect before any write or delete action. <br>\nRisk: The skill depends on ClawLink-managed OAuth credentials for a connected Kibana instance. <br>\nMitigation: Install only if you trust ClawLink for this connection flow and verify the active Kibana integration before making tool calls. <br>\n\n\n## Reference(s): <br>\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html) <br>\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html) <br>\n- [Elastic Security Solution](https://www.elastic.co/security) <br>\n- [ClawLink OpenClaw Documentation](https://docs.claw-link.dev/openclaw) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and tool-call guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires a connected Kibana instance and ClawLink-managed authentication; write or delete actions should be previewed and confirmed before execution.] <br>\n\n## Skill Version(s): <br>\n1.0.1 (source: server-resolved release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.1: 3 files, 6074 bytes\n\nFiles: skill-card.md (2535b), SKILL.md (15244b), _meta.json (139b)\n\nFile v0.1.1:SKILL.md\n\n---\nname: kibana-observability\ndescription: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n---\n\n# Kibana\n\nManage Elastic Kibana for observability, security, and infrastructure monitoring. Query data views, manage alerting rules, handle detection engine rules, manage Fleet agent policies, and work with cases and security alerts.\n\nThis skill uses [ClawLink](https://claw-link.dev) for hosted connection flows and credentials so you do not need to configure Kibana API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Kibana |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│  Kibana REST API │\n│   (User Chat)   │     │   (OAuth)    │     │   (v8.x)        │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin  │                       │\n         │  2. Pair Device   │                       │\n         │  3. Connect Kibana │                      │\n         │                   │  4. Secure Token      │\n         │                   │  5. Proxy Requests    │\n         │                   │                       │\n         ▼                   ▼                       ▼\n   ┌──────────┐      ┌──────────┐           ┌──────────┐\n   │  SKILL   │      │ Dashboard│           │  Kibana  │\n   │  File    │      │ Auth     │           │ Stack   │\n   └──────────┘      └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Kibana again.\"\n\n## Quick Start\n\n```bash\n# List data views\nclawlink_call_tool --tool \"kibana_get_data_views\" --params '{}'\n\n# Get alert types\nclawlink_call_tool --tool \"kibana_get_alert_types\" --params '{}'\n\n# List cases\nclawlink_call_tool --tool \"kibana_get_cases\" --params '{}'\n```\n\n## Authentication\n\nAll Kibana tool calls are authenticated automatically by ClawLink using the user's connected Kibana instance.\n\n**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Kibana API request on the user's behalf.\n\n### Getting Connected\n\n1. Install the ClawLink plugin (see Install above).\n2. Pair the plugin with `clawlink_begin_pairing` if it is not configured yet.\n3. Open https://claw-link.dev/dashboard?add=kibana and connect Kibana (requires an active Kibana instance).\n4. Call `clawlink_list_integrations` to verify the connection is active.\n\n## Connection Management\n\n### List Connections\n\n```bash\nclawlink_list_integrations\n```\n\n**Response:** Returns all connected integrations. Look for `kibana` in the list.\n\n### Verify Connection\n\n```bash\nclawlink_list_tools --integration kibana\n```\n\n**Response:** Returns the live tool catalog for Kibana.\n\n### Reconnect\n\nIf Kibana tools are missing or the connection shows an error:\n\n1. Direct the user to https://claw-link.dev/dashboard?add=kibana\n2. After they confirm, call `clawlink_list_integrations` to verify\n3. Then call `clawlink_list_tools --integration kibana`\n\n## Security & Permissions\n\n- Access is scoped to the connected Kibana instance only.\n- **All write operations require explicit user confirmation.** Before executing any alerting, case, or Fleet action, confirm the target resource and intended effect with the user.\n- Destructive actions (delete rule, delete saved object, delete connector) are marked as high-impact and must be confirmed.\n- Fleet agent policy changes affect deployed agents — confirm before executing.\n- Detection engine rule changes affect security monitoring — confirm before executing.\n\n## Tool Reference\n\n### Data Views\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_data_views` | List all data views (index patterns) available in Kibana | Read |\n\n### Alerting\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_alert_types` | Get available rule types with license requirements and configuration options | Read |\n| `kibana_get_alerting_rules` | List alerting rules with pagination and filtering | Read |\n| `kibana_delete_alerting_rules` | Delete an alerting rule by ID | Write |\n\n### Actions & Connectors\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_action_types` | Get available connector types (Slack, Email, Webhook, ServiceNow, etc.) | Read |\n| `kibana_get_connectors` | List all configured connectors | Read |\n| `kibana_delete_connectors` | Delete a connector by ID | Write |\n\n### Cases\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_cases` | List cases with optional filtering by status, assignee, or severity | Read |\n\n### Saved Objects\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_saved_objects` | Delete a saved object (visualization or dashboard) by ID | Write |\n\n### Security Detection Engine\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_detection_engine_rules_find` | List detection engine rules with KQL filtering and sorting | Read |\n\n### Alerts\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_find_alerts` | Find and aggregate detection alerts with optional query filtering | Read |\n\n### Endpoint Exceptions\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_endpoint_list_items` | List Elastic Endpoint exception list items with filtering | Read |\n\n### Entity Store\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_entity_store_engines` | Get entity store engine configurations and status | Read |\n| `kibana_get_entity_store_entities_list` | List entity records (users, hosts, services) with paging and filtering | Read |\n| `kibana_get_entity_store_status` | Get Entity Store status and configured engines | Read |\n\n### Fleet\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_agent_policies` | List Fleet agent policies with filtering and enrollment counts | Read |\n| `kibana_get_fleet_agents_available_versions` | Get available Elastic Agent versions | Read |\n| `kibana_get_fleet_agents_setup_status` | Check Fleet setup readiness and missing requirements | Read |\n| `kibana_get_fleet_check_permissions` | Verify user permissions for Fleet API operations | Read |\n| `kibana_get_fleet_enrollment_api_keys` | List enrollment API keys for agent authentication | Read |\n| `kibana_get_fleet_enrollment_api_key` | Get details of a specific enrollment API key by ID | Read |\n| `kibana_delete_fleet_output` | Delete a Fleet output configuration by ID | Write |\n| `kibana_delete_fleet_proxy` | Delete a Fleet proxy configuration by ID | Write |\n\n### Fleet EPM (Elastic Package Manager)\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_get_fleet_epm_categories` | Get available package categories with counts | Read |\n| `kibana_get_fleet_epm_packages` | List available Fleet integration packages | Read |\n| `kibana_get_fleet_epm_packages_installed` | List installed Fleet packages | Read |\n| `kibana_get_fleet_epm_package_details` | Get detailed package information including data streams and assets | Read |\n| `kibana_get_fleet_epm_package_stats` | Get usage statistics for a specific Fleet package | Read |\n| `kibana_get_fleet_epm_package_file` | Get a specific file from an EPM package (manifest, README, changelog) | Read |\n| `kibana_get_fleet_epm_data_streams` | List available data streams with filtering | Read |\n\n### Lists\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_list` | Delete a list by ID | Write |\n\n### Osquery\n\n| Tool | Description | Mode |\n|------|-------------|------|\n| `kibana_delete_osquery_saved_queries` | Delete an Osquery saved query by saved object ID | Write |\n\n## Code Examples\n\n### List data views\n\n```bash\nclawlink_call_tool --tool \"kibana_get_data_views\" \\\n  --params '{}'\n```\n\n### Get alert types\n\n```bash\nclawlink_call_tool --tool \"kibana_get_alert_types\" \\\n  --params '{}'\n```\n\n### List cases\n\n```bash\nclawlink_call_tool --tool \"kibana_get_cases\" \\\n  --params '{}'\n```\n\n### Get detection engine rules\n\n```bash\nclawlink_call_tool --tool \"kibana_get_detection_engine_rules_find\" \\\n  --params '{\"page\": 1, \"per_page\": 25}'\n```\n\n### Get Fleet agent policies\n\n```bash\nclawlink_call_tool --tool \"kibana_get_fleet_agent_policies\" \\\n  --params '{}'\n```\n\n## Discovery Workflow\n\n1. Call `clawlink_list_integrations` to confirm Kibana is connected.\n2. Call `clawlink_list_tools --integration kibana` to see the live catalog.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `kibana`.\n5. If no Kibana tools appear, direct the user to https://claw-link.dev/dashboard?add=kibana.\n\n## Execution Workflow\n\n```\n┌─────────────────────────────────────────────────────────────┐\n│  READ OPERATIONS (Safe)                                     │\n│  list → get → search → describe → call                     │\n│                                                             │\n│  Example: List data views → Get index fields → Query data  │\n└─────────────────────────────────────────────────────────────┘\n                              │\n                              ▼\n┌─────────────────────────────────────────────────────────────┐\n│  WRITE OPERATIONS (Require Confirmation)                     │\n│  list → get → describe → preview → confirm → call          │\n│                                                             │\n│  Example: Preview rule delete → User approves → Execute     │\n└─────────────────────────────────────────────────────────────┘\n```\n\n1. For unfamiliar tools, ambiguous requests, or any write action, call `clawlink_describe_tool` first.\n2. Use the returned guidance, schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups` to shape the call.\n3. Prefer read, list, search, and get operations before writes when that reduces ambiguity.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first.\n5. Execute with `clawlink_call_tool`. Pass confirmation only after the preview matches the user's intent.\n6. If the tool call fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## Notes\n\n- Alert types include Elasticsearch query alerts, index threshold alerts, machine learning anomaly detection, and security detection rules.\n- Connector types (action types) include Slack, Email, Webhook, ServiceNow, and more — each with different license requirements.\n- Fleet agent policies define configuration for groups of Elastic Agents including which integrations are enabled.\n- Entity store aggregates and manages entity data (users, hosts, services) from various sources.\n- Endpoint exception list contains security exceptions applied to Elastic Endpoint agents.\n- Osquery saved queries require the saved_object_id (UUID format), not the custom id field.\n\n## Error Handling\n\n| Status / Error | Meaning |\n|----------------|---------|\n| Tool not found | The tool name does not exist in the current catalog. Verify with `clawlink_list_tools --integration kibana`. |\n| Missing connection | Kibana is not connected. Direct the user to https://claw-link.dev/dashboard?add=kibana. |\n| Permission error | The authenticated user lacks permission for this operation. Check Kibana roles. |\n| Fleet not ready | Fleet is not properly configured. Check setup status first. |\n| Write rejected | User did not confirm a write action. Always confirm before executing writes. |\n\n### Troubleshooting: Tools Not Visible\n\n1. Check that the ClawLink plugin is installed:\n   ```bash\n   openclaw plugins list\n   ```\n2. If the plugin is installed but tools are missing, tell the user to send `/new` as a standalone message to reload the catalog.\n3. If a fresh chat does not help, run:\n   ```bash\n   openclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\n   openclaw gateway restart\n   ```\n4. After restart, tell the user to send `/new` again and retry.\n\n### Troubleshooting: Fleet Not Ready\n\n1. Check Fleet setup status:\n   ```bash\n   clawlink_call_tool --tool \"kibana_get_fleet_agents_setup_status\" --params '{}'\n   ```\n2. Review missing prerequisites and address them before managing agents or policies.\n3. Verify Elasticsearch connection and license status.\n\n## Resources\n\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html)\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)\n- [Elastic Security Solution](https://www.elastic.co/security)\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n\n## Related Skills\n\n- [New Relic Observability](https://clawhub.ai/hith3sh/new-relic-observability) — For New Relic monitoring and alerting\n- [Make Automation](https://clawhub.ai/hith3sh/make-automation) — For Make.com workflow automation\n\n---\n\n**Powered by [ClawLink](https://claw-link.dev)** — an integration hub for OpenClaw\n\n![ClawLink Logo](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/logo/link_logo_black_small.png)\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"kibana-observability\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1780839140525\n}\n\nFile v0.1.1:skill-card.md\n\n## Description: <br>\nManage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nObservability, security, and infrastructure teams use this skill to inspect Kibana data views, alerting rules, detection rules, cases, security alerts, entity data, and Fleet configuration through a connected Kibana instance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill uses connected Kibana credentials and can access sensitive observability and security data. <br>\nMitigation: Review the connected Kibana account permissions before use and limit access to the intended Kibana instance. <br>\nRisk: Some supported actions can delete or change alerting rules, saved objects, connectors, Fleet outputs, Fleet proxies, lists, or saved queries. <br>\nMitigation: Require explicit user confirmation for write and destructive actions, and preview the target resource and intended effect before execution. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/hith3sh/kibana-observability) <br>\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html) <br>\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html) <br>\n- [Elastic Security Solution](https://www.elastic.co/security) <br>\n- [ClawLink Documentation](https://docs.claw-link.dev/openclaw) <br>\n- [ClawLink Verification](https://claw-link.dev/verify) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and tool-call guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include Kibana read results, connection troubleshooting, and confirmation-gated write-operation guidance.] <br>\n\n## Skill Version(s): <br>\n0.1.1 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.0: 3 files, 3546 bytes\n\nFiles: skill-card.md (2563b), SKILL.md (4932b), _meta.json (139b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: kibana-observability\ndescription: Work with Kibana saved objects, dashboards, spaces, alerts, cases, and Elastic observability data - powered by ClawLink.\n---\n\n# Kibana\n\nWork with Kibana from chat - manage saved objects, dashboards, spaces, alerts, cases, and observability data.\n\nPowered by [ClawLink](https://claw-link.dev), an integration hub for OpenClaw that handles hosted connection flows and credentials so you don't need to configure Kibana API access yourself.\n\n## Quick start\n\n1. Install the verified ClawLink plugin: `openclaw plugins install clawhub:clawlink-plugin`\n2. Start a fresh OpenClaw chat if the plugin was just installed and ClawLink tools are not visible yet\n3. If ClawLink is not configured, call `clawlink_begin_pairing`\n4. Tell the user to open the returned pairing URL, sign in to ClawLink if needed, and approve the device\n5. After the user confirms approval, call `clawlink_get_pairing_status`\n6. Tell the user to connect Kibana at [claw-link.dev/dashboard?add=kibana](https://claw-link.dev/dashboard?add=kibana)\n7. When the user confirms Kibana is connected, call `clawlink_list_integrations` and then `clawlink_list_tools` with the `kibana` integration slug\n\n## Setup details\n\n### Installing the plugin\n\nIf the ClawLink plugin is not installed yet, tell the user to run:\n\n```\nopenclaw plugins install clawhub:clawlink-plugin\n```\n\nIf the current chat started before the plugin was installed and ClawLink tools are still unavailable, tell the user to start a fresh chat so OpenClaw reloads the plugin tool catalog.\n\n### Pairing ClawLink\n\nIf ClawLink reports that the plugin is not configured, the plugin has not been paired with the user's ClawLink account yet.\n\n1. Call `clawlink_begin_pairing`.\n2. Tell the user to open the returned pairing URL in their browser.\n3. The user signs in to ClawLink if needed and approves the OpenClaw device.\n4. After the user confirms approval, call `clawlink_get_pairing_status` to finish local setup.\n\nThe resulting device credential is stored locally in OpenClaw's plugin config and is only sent to `claw-link.dev`. The user should not paste raw credentials into chat.\n\n### Connecting Kibana\n\nTell the user to open https://claw-link.dev/dashboard?add=kibana and connect Kibana there. The page opens the add-connection panel filtered to Kibana. ClawLink's hosted page runs the provider connection flow. When they confirm it is done, call `clawlink_list_integrations` to verify, then call `clawlink_list_tools` with integration `kibana`.\n\n## Using Kibana tools\n\nClawLink provides tools dynamically based on what the user has connected. You do not need to know tool names or schemas in advance.\n\n### Discovery\n\n1. Call `clawlink_list_integrations` to confirm Kibana is connected.\n2. Call `clawlink_list_tools` with integration `kibana`.\n3. Treat the returned list as the source of truth. Do not guess or assume what tools exist.\n4. If the user describes a capability but the exact tool is unclear, call `clawlink_search_tools` with a short query and integration `kibana`.\n5. If no Kibana tools appear, direct the user to https://claw-link.dev/dashboard?add=kibana.\n\n### Execution\n\n1. Call `clawlink_describe_tool` before using an unfamiliar tool, before any write, or when the request is ambiguous.\n2. Use the returned schema, `whenToUse`, `askBefore`, `safeDefaults`, `examples`, and `followups`.\n3. Prefer read, list, search, and get operations before writes.\n4. For writes or anything marked as requiring confirmation, call `clawlink_preview_tool` first, then confirm with the user.\n5. Execute with `clawlink_call_tool`.\n6. If it fails, report the real error. Do not invent results or restate the failure as a missing capability unless the live catalog supports that conclusion.\n\n## What you can do\n\nTypical Kibana tasks (actual availability depends on the user's connected account, permissions, scopes, and current ClawLink tool catalog):\n\n- List and inspect saved objects\n- Review dashboards, spaces, and cases\n- Create or update saved objects after confirmation\n- Inspect alerts and observability data when available\n- Manage Kibana resources supported by the live catalog\n\n## Rules\n\n- Always use ClawLink tools for Kibana. Do not ask the user for separate Kibana credentials.\n- Do not claim a capability is missing without checking the live ClawLink catalog in the current turn.\n- Do not invent slash commands or ask the user to paste raw credentials.\n- Ask for confirmation before destructive, external-facing, or bulk write actions.\n- If Kibana is not connected, direct the user to https://claw-link.dev/dashboard?add=kibana.\n- Never echo or repeat the user's ClawLink credential.\n\n## Resources\n\n- ClawLink: https://claw-link.dev\n- ClawLink Docs: https://docs.claw-link.dev/openclaw\n- ClawLink Verification: https://claw-link.dev/verify\n- ClawLink Source: https://github.com/hith3sh/clawlink\n- Kibana API: https://www.elastic.co/docs/api/doc/kibana\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"kibana-observability\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1778958830214\n}\n\nFile v0.1.0:skill-card.md\n\n## Description: <br>\nWork with Kibana saved objects, dashboards, spaces, alerts, cases, and Elastic observability data - powered by ClawLink. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[hith3sh](https://clawhub.ai/user/hith3sh) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, operators, and observability teams use this skill to connect OpenClaw to Kibana through ClawLink, discover available Kibana tools, and manage saved objects, dashboards, spaces, alerts, cases, and observability data with confirmation for sensitive actions. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Kibana write, destructive, external-facing, or bulk actions can change connected resources. <br>\nMitigation: Use ClawLink discovery and preview flows, then get explicit user confirmation before allowing those actions to run. <br>\nRisk: Credential exposure could occur if users paste raw Kibana or ClawLink credentials into chat. <br>\nMitigation: Use the ClawLink pairing and hosted connection flow, and do not request, echo, or store raw credentials in chat. <br>\nRisk: Available Kibana capabilities depend on the connected account, permissions, scopes, and current ClawLink tool catalog. <br>\nMitigation: Treat the live ClawLink catalog as authoritative and avoid claiming a capability exists or is missing until it is checked in the current session. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/hith3sh/kibana-observability) <br>\n- [ClawLink](https://claw-link.dev) <br>\n- [ClawLink OpenClaw Docs](https://docs.claw-link.dev/openclaw) <br>\n- [ClawLink Source](https://github.com/hith3sh/clawlink) <br>\n- [Kibana API Documentation](https://www.elastic.co/docs/api/doc/kibana) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and tool-use guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May guide agents to call ClawLink tools for discovery, previews, confirmations, and execution based on the live Kibana catalog.] <br>\n\n## Skill Version(s): <br>\n0.1.0 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: Kibana Owner: hith3sh Summary: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent polic... Tags: latest:1.0.6 Version history: v1.0.6 | 2026-06-09T07:12:18.090Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│  Kibana REST API │\n│   (User Chat)   │     │   (OAuth)    │     │   (v8.x)        │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin  │                       │\n         │  2. Pair Device   │                       │\n         │  3. Connect Kibana │                      │\n         │                   │  4. Secure Token      │\n         │                   │  5. Proxy Requests    │\n         │                   │                       │\n         ▼                   ▼                       ▼\n   ┌──────────┐      ┌──────────┐           ┌──────────┐\n   │  SKILL   │      │ Dashboard│           │  Kibana  │\n   │  File    │      │ Auth     │           │ Stack   │\n   └──────────┘      └──────────┘           └──────────┘"},{"language":"bash","snippet":"openclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart"},{"language":"bash","snippet":"# List data views\nclawlink_call_tool --tool \"kibana_get_data_views\" --params '{}'\n\n# Get alert types\nclawlink_call_tool --tool \"kibana_get_alert_types\" --params '{}'\n\n# List cases\nclawlink_call_tool --tool \"kibana_get_cases\" --params '{}'"},{"language":"bash","snippet":"clawlink_list_integrations"},{"language":"bash","snippet":"clawlink_list_tools --integration kibana"},{"language":"bash","snippet":"clawlink_call_tool --tool \"kibana_get_data_views\" \\\n  --params '{}'"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: kibana-observability\ndescription: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n---\n\n# Kibana\n\n![Kibana](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/brand-logos/kibana.svg?v=2)\n\nManage Elastic Kibana for observability, security, and infrastructure monitoring. Query data views, manage alerting rules, handle detection engine rules, manage Fleet agent policies, and work with cases and security alerts.\n\nThis skill uses [ClawLink](https://claw-link.dev/?utm_source=clawhub&utm_medium=referral&utm_content=kibana-observability) for hosted connection flows and credentials so you do not need to configure Kibana API access yourself.\n\n### Setup in 3 Steps\n\n| Step 1: Install | Step 2: Pair Account | Step 3: Connect Kibana |\n|:---:|:---:|:---:|\n| ![Install](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/pairing/initialstep_1.gif) | ![Pair](https://raw.githubusercontent.com/ClawLink-HQ/clawlink/main/public/images/approve_process.gif) | *App-specific connection GIF coming soon* |\n\n## How It Works\n\n```\n┌─────────────────┐     ┌──────────────┐     ┌──────────────────┐\n│   OpenClaw      │────▶│   ClawLink   │────▶│  Kibana REST API │\n│   (User Chat)   │     │   (OAuth)    │     │   (v8.x)        │\n└─────────────────┘     └──────────────┘     └──────────────────┘\n         │                       │                       │\n         │  1. Install Plugin  │                       │\n         │  2. Pair Device   │                       │\n         │  3. Connect Kibana │                      │\n         │                   │  4. Secure Token      │\n         │                   │  5. Proxy Requests    │\n         │                   │                       │\n         ▼                   ▼                       ▼\n   ┌──────────┐      ┌──────────┐           ┌──────────┐\n   │  SKILL   │      │ Dashboard│           │  Kibana  │\n   │  File    │      │ Auth     │           │ Stack   │\n   └──────────┘      └──────────┘           └──────────┘\n```\n\n## Install\n\nInstall the verified ClawLink plugin from ClawHub. After the user confirms, complete the full setup so ClawLink tools are visible in the next OpenClaw chat.\n\n```bash\nopenclaw plugins install clawhub:clawlink-plugin\nopenclaw config set tools.alsoAllow '[\"clawlink-plugin\"]' --strict-json\nopenclaw gateway restart\n```\n\nThen tell the user: \"OpenClaw has been restarted. Send `/new` as a standalone message to start a fresh chat, then ask for Kibana again.\"\n\n## Quick Start\n\n```bash\n# List data views\nclawlink_call_tool --tool \"kibana_get_data_views\" --params '{}'\n\n# Get alert types\nclawlink_call_tool --tool \"kibana_get_alert_types\" --params '{}'\n\n# List cases\nclawlink_call_tool --tool \"kibana_get_cases\" --params '{}'\n```\n\n## Authentication\n\nAll Kibana tool calls are authenticated automatically by C"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn713pxvayh8fjhb503zjb8yxh815j54\",\n  \"slug\": \"kibana-observability\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1780989138090\n}"},{"path":"skill-card.md","content":"## Description:\n\nManage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent policies, manage cases, and interact with the Elastic Security solution.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[hith3sh](https://clawhub.ai/user/hith3sh)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers, site reliability engineers, and security operations teams use this skill to inspect and manage Kibana observability and security resources through ClawLink-connected Kibana tools.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill requires enabling an unpinned third-party ClawLink plugin that handles Kibana credentials.\n\nMitigation: Install only if the publisher is trusted, verify the plugin source and version where possible, and use a dedicated Kibana identity with least-privilege access.\n\nRisk: Kibana write operations can delete or modify alerting rules, connectors, saved objects, Fleet outputs, Fleet proxies, lists, and security monitoring resources.\n\nMitigation: Review tool previews carefully and approve delete, Fleet, and security changes only after the target resource and intended effect match the user's request.\n\n## Reference(s):\n\n- [Kibana Documentation](https://www.elastic.co/guide/en/kibana/current/index.html)\n- [Elastic Fleet Documentation](https://www.elastic.co/guide/en/fleet/current/fleet-overview.html)\n- [Elastic Security Solution](https://www.elastic.co/security)\n- [ClawLink OpenClaw Documentation](https://docs.claw-link.dev/openclaw)\n- [ClawLink Kibana Connection](https://claw-link.dev/dashboard?add=kibana)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Shell commands, Configuration instructions, API calls, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and JSON parameters]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes confirmation guidance for write and destructive Kibana operations.]\n\n## Skill Version(s):\n\n1.0.6 (source: server-resolved release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent polic... Skill: Kibana Owner: hith3sh Summary: Manage Elastic Kibana for observability and security operations. Query data views, manage alerting rules and detection engine rules, handle Fleet agent polic... Tags: latest:1.0.6 Version history: v1.0.6 | 2026-06-09T07:12:18.090Z | user Add UTM attribution tags (utm_source=clawhub) to ClawLink branding links so visits from this skill page are tracked as a distinct traffic source","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1024,"uniquenessScore":52,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T12:33:44.688Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T12:33:44.688Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T19:20:19.068Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}