Kibana Dashboards

作者 elasticbaa511126ba2無授權條款592 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫昨天更新

Create and manage Kibana Dashboards and Lens visualizations. Use when you need to define dashboards and visualizations declaratively, version control them, or automate their deployment.

僅含說明

Kibana Dashboards and Lens Visualizations

Create, update, and delete Kibana dashboards and standalone Lens visualizations using the Kibana 9.4+ Dashboards and Visualizations APIs. Produce minimal, diffable JSON bodies; prefer inline panel definitions over library references; and choose the correct dataset type (data view vs ES|QL) before writing metrics or chart layers.

<!-- begin-partial: preamble -->

Environment Configuration

This skill executes Elasticsearch operations through the elastic CLI. If the elastic CLI is not installed, tell the user what it is needed for. Do not guess credentials, call the HTTP API directly, or attempt other workarounds.

This skill references operations in HTTP-shorthand form (e.g., GET /, GET /_cat/indices, GET /{index}/_mapping, GET /{index}/_settings/index.mode, POST /_query). The Operations table at the end of this document maps each shorthand to the equivalent elastic CLI command — always use the CLI rather than calling the HTTP API directly.

<!-- end-partial: preamble -->

Prerequisites

Version requirement: Kibana 9.4+ (Dashboards and Visualizations APIs).

ES|QL placement:

  • Standalone library charts: PUT kbn:/api/visualizations/{id} with data_source.type: "esql".
  • ES|QL panels embedded in a dashboard: inline vis panel config with data_source.type: "esql" via PUT kbn:/api/dashboards/{id}.
  • Do not use data_source.type: "data_view_reference" or index-pattern aggregations when the user explicitly requests ES|QL — the persisted Lens state must use a text-based ES|QL datasource (textBased / esql), not a data-view count operation.

Process

  1. Verify Kibana connectivity. Call GET kbn:/api/status. If the call fails, stop and surface the error — do not guess endpoints or credentials. Read version.number to confirm the cluster meets the 9.4+ requirement.

  2. Classify the task. Decide whether the user needs a dashboard (collection of panels, optional time range), a standalone Lens visualization (library item referenced by id or used alone), or both. Determine whether a deterministic saved-object id was supplied — when given, use upsert (PUT) with that id rather than POST (which auto-generates ids).

  3. Choose the dataset type before building metrics or layers.

    User intentDatasetMetric / axis pattern
    Simple count or aggregation on a saved data viewdata_source.type: "data_view_reference" with ref_idmetrics: [{ type: "primary", operation: "count" }] (or other aggregation operations)
    Ad-hoc index patterndata_source.type: "data_view_spec" with index_pattern and time_fieldSame aggregation operation fields
    ES|QL query (explicit or complex logic)data_source.type: "esql" with querymetrics: [{ type: "primary", column: "<alias>" }] or layer axes { column: "<alias>" } — never operation: "count" on the metric

    Write the aggregation in the ES|QL query (STATS count = COUNT()), then reference the resulting column by name.

  4. Build a dashboard body when creating or updating dashboards. The request body is flat — title, panels, and optional time_range at the root. Do not wrap in { data: ... } on write. Required fields:

    • title — exact string the user requested.
    • panels — array; use [] when the user asks for an empty dashboard (do not omit the key or invent panels).
    • time_range — when the user specifies a default time filter, set { "from": "<expr>", "to": "<expr>" } (for example { "from": "now-7d", "to": "now" }). Supplying time_range persists the dashboard time filter on open (equivalent to enabling time restore in the UI).

    Upsert with a deterministic id:

    json
    {  "title": "Sales Overview",  "panels": [],  "time_range": { "from": "now-7d", "to": "now" }}

    Call PUT kbn:/api/dashboards/eval-sales-overview with the body above when the user supplies that id.

    Inline ES|QL metric panel example (inside panels):

    json
    {  "type": "vis",  "id": "total-requests",  "grid": { "x": 0, "y": 0, "w": 12, "h": 6 },  "config": {    "title": "Total Requests",    "type": "metric",    "data_source": {      "type": "esql",      "query": "FROM logs* | STATS count = COUNT()"    },    "metrics": [{ "type": "primary", "column": "count" }]  }}

    Prefer inline config properties over config.ref_id for portable dashboards. Read Dashboard API Reference [blocked] for panel types, grid layout, and copy workflows.

  5. Build a standalone Lens visualization when the user asks for a library chart. Use the Visualizations API. Upsert with PUT kbn:/api/visualizations/{id} when an id is supplied; otherwise POST kbn:/api/visualizations and report the generated id from the response.

    ES|QL metric (total count from logs):

    json
    {  "type": "metric",  "title": "Total Requests",  "data_source": {    "type": "esql",    "query": "FROM logs* | STATS count = COUNT()"  },  "metrics": [{ "type": "primary", "column": "count" }]}

    Call PUT kbn:/api/visualizations/eval-total-requests when that id is required. The API persists a Lens saved object whose datasource state uses ES|QL (textBased / esql), not an index-pattern aggregation.

    Read Lens API Reference [blocked] and Chart Types Reference [blocked] for xy, gauge, heatmap, and other chart schemas.

  6. Execute and confirm. Perform the write with PUT kbn:/api/dashboards/{id} or PUT kbn:/api/visualizations/{id} (or POST when no id is supplied). Confirm with GET kbn:/api/dashboards/{id} or GET kbn:/api/visualizations/{id}. Report the id and title back to the user — do not claim success without a successful read-back.

  7. List, export, or delete when requested. Call GET kbn:/api/dashboards or GET kbn:/api/visualizations to discover existing objects. Call DELETE kbn:/api/dashboards/{id} or DELETE kbn:/api/visualizations/{id} to remove objects. For bulk export or import of saved objects, call POST kbn:/api/saved_objects/_export or POST kbn:/api/saved_objects/_import.

Dashboard grid

Dashboards use a 48-column grid. On 16:9 screens, roughly 20–24 rows fit above the fold — target 8–12 panels in that band.

WidthColumnsHeight (rows)Use case
Full4814–16Wide time series, tables
Half2410–12Primary charts
Quarter125–6KPI metrics
Sixth84–5Dense metric rows

Grid packing: When stacking rows, set the next panel's y to the previous panel's y + h. Panels sharing a row should use the same h. Do not add markdown panels as dashboard titles — use descriptive chart titles instead.

ES|QL patterns

Time series bucket (dashboard time picker injects ?_tstart / ?_tend):

esql
FROM logs*| WHERE @timestamp <= ?_tend AND @timestamp > ?_tstart| STATS count = COUNT() BY BUCKET(@timestamp, 75, ?_tstart, ?_tend)

Set "scale": "temporal" on the x-axis for time-series xy charts. See Chart Types Reference [blocked] for axis and layer details.

Static reference values — use EVAL in the query, then reference the column:

esql
FROM logs* | STATS count = COUNT() | EVAL goal = 15000

Examples

Example JSON definitions live under assets/ [blocked]: demo-dashboard.json, dashboard-with-visualizations.json, metric-esql.json, bar-chart-esql.json, line-chart-timeseries.json.

Guidelines

  1. Match the user's id and title exactly when supplied — do not substitute auto-generated ids.
  2. Honor empty panels — when the user asks for panels: [], send an empty array; do not add placeholder panels.
  3. ES|QL when requested — use data_source.type: "esql" and column references; never satisfy an ES|QL request with operation: "count" on a data view.
  4. Minimal payloads — omit derivable defaults; let the API inject styling and metadata.
  5. Confirm writes — always read back with GET after create or update.
  6. Read references before complex charts — metric and xy schemas differ between data view and ES|QL; consult Chart Types Reference [blocked] before generating partition or table charts.

Common issues

ErrorLikely causeFix
404 on GET after PUTWrong id or spaceConfirm id and retry GET kbn:/api/dashboards/{id}
400 validationES|QL column mismatchAlign metrics[].column / layer column with STATS aliases in the query
ES|QL panel saved as data viewWrong dataset typeUse data_source.type: "esql", not data_view_reference
Empty dashboard missing time filterOmitted time_rangeInclude { "from": "now-7d", "to": "now" } when a default range is required
XY chart failureMissing layer data_sourcePut data_source inside each layer, not only at the root

Operations

As of CLI v0.3.0 the Dashboards and Visualizations APIs have dedicated elastic kb dashboards and elastic kb visualizations commands for listing, reading, updating, and deleting objects by id. The create-*-redirect commands do not accept a request body yet, so to write a new object supply an id and use the update-*-redirect (PUT) command, which carries the JSON body via --input-file. To author several objects at once, build a saved-object NDJSON and import it with post-saved-objects-import (read it back with post-saved-objects-export).

HTTP API (shorthand)elastic CLI command
GET kbn:/api/statuselastic kb system get-status
POST kbn:/api/saved_objects/_importelastic kb saved-objects post-saved-objects-import --file '<path.ndjson>' --overwrite
POST kbn:/api/saved_objects/_exportelastic kb saved-objects post-saved-objects-export --objects '[{"type":"<type>","id":"<id>"}]'
GET kbn:/api/dashboardselastic kb dashboards get-dashboards-redirect
GET kbn:/api/dashboards/{id}elastic kb dashboards get-dashboard-redirect --id '<id>'
PUT kbn:/api/dashboards/{id}elastic kb dashboards update-dashboard-redirect --id '<id>' --input-file '<path.json>'
DELETE kbn:/api/dashboards/{id}elastic kb dashboards delete-dashboard-redirect --id '<id>'
POST kbn:/api/dashboards (no id)create-dashboard-redirect takes no body yet — supply an id and use update-dashboard-redirect, or author via post-saved-objects-import (type dashboard)
GET kbn:/api/visualizationselastic kb visualizations get-visualizations-redirect
GET kbn:/api/visualizations/{id}elastic kb visualizations get-visualization-redirect --id '<id>'
PUT kbn:/api/visualizations/{id}elastic kb visualizations update-visualization-redirect --id '<id>' --input-file '<path.json>'
DELETE kbn:/api/visualizations/{id}elastic kb visualizations delete-visualization-redirect --id '<id>'
POST kbn:/api/visualizations (no id)create-visualization-redirect takes no body yet — supply an id and use update-visualization-redirect, or author via post-saved-objects-import (type lens)

來源與署名

來源:elastic/agent-skills位於skills/kibana/kibana-dashboards提交baa5111

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 elastic/agent-skills 的技能

Elasticsearch Search Relevance

elastic

Improve Elasticsearch search relevance for content and catalog indices: pin or promote results with query rules (correct rule type, criteria, and rule-query wiring) and tune organic ranking with multi_match, field boosts, and analysis grounded in the index mapping. Use when search results rank poorly, a specific document must appear first for a query, or the user asks to tune full-text matching — not for ES|QL analytics, index ingest, or cluster health.

待分類592昨天更新

Elasticsearch Query Optimization

elastic

Diagnose slow Elasticsearch Query DSL searches and propose measured fixes. Use when a search is slow, profile output shows an expensive clause, exact-match filters sit in scoring context, or leading wildcards dominate latency. Ground every recommendation in search profiling — move non-scoring clauses to filter context, eliminate leading wildcards, and re-profile to confirm improvement.

待分類592昨天更新

Elasticsearch Ingest

elastic

Load CSV and JSON files into Elasticsearch indices using the bulk API and explicit mappings when field types matter. Use when batch-importing local files, converting CSV rows or JSON arrays to NDJSON bulk format, or verifying document counts and mappings after ingest — not for Logstash pipelines, Beats, custom scripts, or index-to-index reindex.

待分類592昨天更新

Elasticsearch Index Design

elastic

依存取模式設計與審查 Elasticsearch 索引對應,涵蓋欄位型別、多欄位與分片設定。

Data & Analytics592昨天更新

Kibana Anomaly Detection

elastic

用於調查、解釋、疑難排解與設定 Elastic ML 異常偵測作業。

Data & Analytics592昨天更新

Elasticsearch Cluster Health

elastic

對非綠色 Elasticsearch 叢集進行唯讀排查,指出最可能的原因與修復建議。

DevOps & Cloud592昨天更新