Kibana
This integration enables using Elastic Security for SIEM for security operations management and searching Elastic logs. This pack is to be used in combination with the Elasticsearch v2 integration.
- Category
- Analytics & SIEM
- Pack
- CommunityElasticSearch
Configuration parameters
- url — Server URL (required)
- elastic_port — Elastic API Port
- kibana_port — Kibana API Port
- auth_type — Authorization type
- api_key_auth_credentials — API key ID
- credentials — Username
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- client_type — Client type
- timeout — Request timeout (in seconds).
Commands (32)
- kibana-alert-assign — Assigns an alert in Kibana to a user via user ID input.
- kibana-alert-note-add — Adds a note to an alert in Kibana.
- kibana-alert-rule-disable — Disables a detection alerting rule. Clears associated alerts from the active alerts page.
- kibana-alert-rule-enable — Enables a rule used for detection alerting.
- kibana-alert-status-update — Updates the status of an input alert.
- kibana-alerting-health-get — Retrieves the health status of the Kibana alerting framework.
- kibana-case-alerts-find — Returns information on the alerts of the input case in Kibana.
- kibana-case-comment-add — Adds a comment to a case in Kibana. The case ID and owner can be obtained from the "kibana-cases-find" command.
- kibana-case-comment-delete — Deletes a case comment.
- kibana-case-comments-find — Finds comments for an input case ID.
- kibana-case-delete — Deletes a case in Kibana based on case ID.
- kibana-case-file-add — Attaches a file to a case.
- kibana-case-information-get — Retrieves information for a specific case in Kibana.
- kibana-case-status-update — Updates the status of an input case.
- kibana-cases-find — Lists cases in Kibana.
- kibana-detection-alerts-list — Searches for detection alerts in Kibana.
- kibana-exception-lists-get — Retrieves a list of all exception list containers.
- kibana-rule-delete — Deletes a rule in Kibana based on the input rule ID.
- kibana-rule-details-search — Retrieves details about a detection rule in Kibana based on the input KQL filter.
- kibana-status-get — Checks the Kibana operational status.
- kibana-task-manager-health-get — Retrieves the health status of the Kibana task manager.
- kibana-upgrade-readiness-status-get — Checks the status of the cluster.
- kibana-user-by-email-get — Searches for a single user's UID in Kibana by email address filter.
- kibana-user-list-get — Searches for the list of users in Kibana and returns the users' UIDs.
- kibana-user-spaces-find — Gets the list of user spaces in Kibana.
- kibana-value-list-create — Creates a value list in Kibana.
- kibana-value-list-delete — Deletes a value list given the list ID as input.
- kibana-value-list-item-create — Creates a value list item and associates it with the specified value list.
- kibana-value-list-item-delete — Deletes a value list item, given the item ID and list ID as input.
- kibana-value-list-items-get — Displays entries in an input value list.
- kibana-value-list-items-import — Imports value list items from a TXT or CSV file.
- kibana-value-lists-get — Finds all value lists in the Kibana Detection Rules menu.