kibana-dashboards
Create and manage Kibana Dashboards and Lens visualizations. Use when you need to define dashboards and visualizations declaratively, version control them, or automate their deployment.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 12
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 a3ef1c71ebc09a01… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Kibana Dashboards and Lens Visualizations
Create, update, and delete Kibana dashboards and standalone Lens visualizations using the Kibana 9.4+ Dashboards and Visualizations APIs. Produce minimal, diffable JSON bodies; prefer inline panel definitions over library references; and choose the correct dataset type (data view vs ES|QL) before writing metrics or chart layers.
Environment Configuration
This skill executes Elasticsearch operations through the elastic CLI. If the
elastic CLI is not installed, tell the user what it is needed for. Do
not guess credentials, call the HTTP API directly, or attempt other workarounds.
This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping,
GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document
maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API
directly.
Prerequisites
Version requirement: Kibana 9.4+ (Dashboards and Visualizations APIs).
ES|QL placement:
- Standalone library charts:
PUT kbn:/api/visualizations/{id}withdata_source.type: "esql". - ES|QL panels embedded in a dashboard: inline
vispanelconfigwithdata_source.type: "esql"viaPUT kbn:/api/dashboards/{id}. - Do not use
data_source.type: "data_view_reference"or index-pattern aggregations when the user explicitly requests ES|QL — the persisted Lens state must use a text-based ES|QL datasource (textBased/esql), not a data-view count operation.
Process
-
Verify Kibana connectivity. Call
GET kbn:/api/status. If the call fails, stop and surface the error — do not guess endpoints or credentials. Readversion.numberto confirm the cluster meets the 9.4+ requirement. -
Classify the task. Decide whether the user needs a dashboard (collection of panels, optional time range), a standalone Lens visualization (library item referenced by id or used alone), or both. Determine whether a deterministic saved-object id was supplied — when given, use upsert (
PUT) with that id rather thanPOST(which auto-generates ids). -
Choose the dataset type before building metrics or layers.
User intent Dataset Metric / axis pattern Simple count or aggregation on a saved data view data_source.type: "data_view_reference"withref_idmetrics: [{ type: "primary", operation: "count" }](or other aggregation operations)Ad-hoc index pattern data_source.type: "data_view_spec"withindex_patternandtime_fieldSame aggregation operationfieldsES|QL query (explicit or complex logic) data_source.type: "esql"withquerymetrics: [{ type: "primary", column: "<alias>" }]or layer axes{ column: "<alias>" }— neveroperation: "count"on the metricWrite the aggregation in the ES|QL query (
STATS count = COUNT()), then reference the resulting column by name. -
Build a dashboard body when creating or updating dashboards. The request body is flat —
title,panels, and optionaltime_rangeat the root. Do not wrap in{ data: ... }on write. Required fields:title— exact string the user requested.panels— array; use[]when the user asks for an empty dashboard (do not omit the key or invent panels).time_range— when the user specifies a default time filter, set{ "from": "<expr>", "to": "<expr>" }(for example{ "from": "now-7d", "to": "now" }). Supplyingtime_rangepersists the dashboard time filter on open (equivalent to enabling time restore in the UI).
Upsert with a deterministic id:
{ "title": "Sales Overview", "panels": [], "time_range": { "from": "now-7d", "to": "now" } }Call
PUT kbn:/api/dashboards/eval-sales-overviewwith the body above when the user supplies that id.Inline ES|QL metric panel example (inside
panels):{ "type": "vis", "id": "total-requests", "grid": { "x": 0, "y": 0, "w": 12, "h": 6 }, "config": { "title": "Total Requests", "type": "metric", "data_source": { "type": "esql", "query": "FROM logs* | STATS count = COUNT()" }, "metrics": [{ "type": "primary", "column": "count" }] } }Prefer inline
configproperties overconfig.ref_idfor portable dashboards. Read Dashboard API Reference for panel types, grid layout, and copy workflows. -
Build a standalone Lens visualization when the user asks for a library chart. Use the Visualizations API. Upsert with
PUT kbn:/api/visualizations/{id}when an id is supplied; otherwisePOST kbn:/api/visualizationsand report the generated id from the response.ES|QL metric (total count from logs):
{ "type": "metric", "title": "Total Requests", "data_source": { "type": "esql", "query": "FROM logs* | STATS count = COUNT()" }, "metrics": [{ "type": "primary", "column": "count" }] }Call
PUT kbn:/api/visualizations/eval-total-requestswhen that id is required. The API persists a Lens saved object whose datasource state uses ES|QL (textBased/esql), not an index-pattern aggregation.Read Lens API Reference and Chart Types Reference for xy, gauge, heatmap, and other chart schemas.
-
Execute and confirm. Perform the write with
PUT kbn:/api/dashboards/{id}orPUT kbn:/api/visualizations/{id}(orPOSTwhen no id is supplied). Confirm withGET kbn:/api/dashboards/{id}orGET kbn:/api/visualizations/{id}. Report the id and title back to the user — do not claim success without a successful read-back. -
List, export, or delete when requested. Call
GET kbn:/api/dashboardsorGET kbn:/api/visualizationsto discover existing objects. CallDELETE kbn:/api/dashboards/{id}orDELETE kbn:/api/visualizations/{id}to remove objects. For bulk export or import of saved objects, callPOST kbn:/api/saved_objects/_exportorPOST kbn:/api/saved_objects/_import.
Dashboard grid
Dashboards use a 48-column grid. On 16:9 screens, roughly 20–24 rows fit above the fold — target 8–12 panels in that band.
| Width | Columns | Height (rows) | Use case |
|---|---|---|---|
| Full | 48 | 14–16 | Wide time series, tables |
| Half | 24 | 10–12 | Primary charts |
| Quarter | 12 | 5–6 | KPI metrics |
| Sixth | 8 | 4–5 | Dense metric rows |
Grid packing: When stacking rows, set the next panel's y to the previous panel's y + h. Panels sharing a row
should use the same h. Do not add markdown panels as dashboard titles — use descriptive chart titles instead.
ES|QL patterns
Time series bucket (dashboard time picker injects ?_tstart / ?_tend):
FROM logs*
| WHERE @timestamp <= ?_tend AND @timestamp > ?_tstart
| STATS count = COUNT() BY BUCKET(@timestamp, 75, ?_tstart, ?_tend)
Set "scale": "temporal" on the x-axis for time-series xy charts. See
Chart Types Reference for axis and layer details.
Static reference values — use EVAL in the query, then reference the column:
FROM logs* | STATS count = COUNT() | EVAL goal = 15000
Examples
Example JSON definitions live under assets/: demo-dashboard.json, dashboard-with-visualizations.json,
metric-esql.json, bar-chart-esql.json, line-chart-timeseries.json.
Guidelines
- Match the user's id and title exactly when supplied — do not substitute auto-generated ids.
- Honor empty panels — when the user asks for
panels: [], send an empty array; do not add placeholder panels. - ES|QL when requested — use
data_source.type: "esql"and column references; never satisfy an ES|QL request withoperation: "count"on a data view. - Minimal payloads — omit derivable defaults; let the API inject styling and metadata.
- Confirm writes — always read back with
GETafter create or update. - Read references before complex charts — metric and xy schemas differ between data view and ES|QL; consult Chart Types Reference before generating partition or table charts.
Common issues
| Error | Likely cause | Fix |
|---|---|---|
| 404 on GET after PUT | Wrong id or space | Confirm id and retry GET kbn:/api/dashboards/{id} |
| 400 validation | ES|QL column mismatch | Align metrics[].column / layer column with STATS aliases in the query |
| ES|QL panel saved as data view | Wrong dataset type | Use data_source.type: "esql", not data_view_reference |
| Empty dashboard missing time filter | Omitted time_range | Include { "from": "now-7d", "to": "now" } when a default range is required |
| XY chart failure | Missing layer data_source | Put data_source inside each layer, not only at the root |
Operations
As of CLI v0.3.0 the Dashboards and Visualizations APIs have dedicated elastic kb dashboards and
elastic kb visualizations commands for listing, reading, updating, and deleting objects by id. The create-*-redirect
commands do not accept a request body yet, so to write a new object supply an id and use the update-*-redirect (PUT)
command, which carries the JSON body via --input-file. To author several objects at once, build a saved-object NDJSON
and import it with post-saved-objects-import (read it back with post-saved-objects-export).
| HTTP API (shorthand) | elastic CLI command |
|---|---|
GET kbn:/api/status | elastic kb system get-status |
POST kbn:/api/saved_objects/_import | elastic kb saved-objects post-saved-objects-import --file '<path.ndjson>' --overwrite |
POST kbn:/api/saved_objects/_export | elastic kb saved-objects post-saved-objects-export --objects '[{"type":"<type>","id":"<id>"}]' |
GET kbn:/api/dashboards | elastic kb dashboards get-dashboards-redirect |
GET kbn:/api/dashboards/{id} | elastic kb dashboards get-dashboard-redirect --id '<id>' |
PUT kbn:/api/dashboards/{id} | elastic kb dashboards update-dashboard-redirect --id '<id>' --input-file '<path.json>' |
DELETE kbn:/api/dashboards/{id} | elastic kb dashboards delete-dashboard-redirect --id '<id>' |
POST kbn:/api/dashboards (no id) | create-dashboard-redirect takes no body yet — supply an id and use update-dashboard-redirect, or author via post-saved-objects-import (type dashboard) |
GET kbn:/api/visualizations | elastic kb visualizations get-visualizations-redirect |
GET kbn:/api/visualizations/{id} | elastic kb visualizations get-visualization-redirect --id '<id>' |
PUT kbn:/api/visualizations/{id} | elastic kb visualizations update-visualization-redirect --id '<id>' --input-file '<path.json>' |
DELETE kbn:/api/visualizations/{id} | elastic kb visualizations delete-visualization-redirect --id '<id>' |
POST kbn:/api/visualizations (no id) | create-visualization-redirect takes no body yet — supply an id and use update-visualization-redirect, or author via post-saved-objects-import (type lens) |
Files
12- SKILL.md
142d34b60814.5 KB - assets/bar-chart-esql.json
2b7a7d5c25443 B - assets/dashboard-basic.json
5f534feac2391 B - assets/dashboard-with-visualizations.json
6f9c765f943.6 KB - assets/datatable.json
9adff24d69341 B - assets/demo-dashboard.json
7ffdbc2aec6.3 KB - assets/ecommerce-analytics-dashboard.json
bb533e4ecb11.4 KB - assets/line-chart-timeseries.json
5ed86131a8632 B - assets/metric-esql.json
d641bc0356227 B - references/chart-types-reference.md
ce0f861f1213.2 KB - references/dashboard-api-reference.md
5b281eccd48.9 KB - references/lens-api-reference.md
438caf63873.2 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from elastic/agent-skills8
Onboard an Elastic Cloud organization: configure the `elastic` CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and create or revoke Cloud API keys. Use when setting up Cloud authentication or when granting, modifyi
Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS PrivateLink network security); and manage the lifecycle of Elastic Cloud Hosted deployments. Use when creating o
Create and manage Elastic ML anomaly detection jobs via the API. Use when setting up jobs on an index or data stream, configuring jobs and datafeeds, or opening, starting, or stopping them.
Explain Elasticsearch ML anomaly detection scores, model behavior, and result interpretation. Use when the user asks why a score is high or low, how the model learns, what the numbers mean, or how to troubleshoot unexpected anomaly scores.
Diagnose a non-green Elasticsearch cluster and surface the single most likely cause with remediation. Use when an operator reports yellow or red status, unassigned shards, allocation failures, or wants read-only triage before deeper investigation. Teaches replica-vs-primary impact, allocation decide
Execute ES|QL (Elasticsearch Query Language) queries, use when the user wants to query Elasticsearch data, analyze logs, aggregate metrics, explore data, or create charts and dashboards from ES|QL results.
Design and review Elasticsearch index mappings for stated access patterns: correct field types, text+keyword multi-fields, doc_values tuning, mapping-explosion avoidance, and explicit shard settings. Use when creating a new index, reviewing a mapping for storage or query performance, fixing wrong fi
Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Use when batch-importing local files, converting CSV rows or JSON arrays to NDJSON bulk format, or verifying document counts and mappings after ingest — not for Logstash pipelines, Be
Related devops skillsscan passed
Deployment workflows, CI/CD pipeline patterns, Docker containerization, health checks, rollback strategies, and production readiness checklists for web applications. Use when setting up CI/CD, containerizing an app, or checking production readiness before a release.
Configure deployment settings for /land-and-deploy.
Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext. Use when starting a Next.js project on Cloudflare, moving an existing app to Workers, choosing between vinext and OpenNext, or setting up vinext for Workers. For setup, migration, or deployment, install vinext's upstream skil
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Instruments code so production behavior is visible and diagnosable. Use when adding logging, metrics, tracing, or alerting. Use when shipping any feature that runs in production and you need evidence it works. Use when production issues are reported but you can't tell what happened from the availabl
Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil