Skip to content

Elasticsearch Kibana CLI documentation

PyPi Python Versions Read the Docs License

Danger

ElasticSearch Kibana CLI relies on the availability of a /elasticsearch/_msearch API endpoint exposed through Kibana. Recent versions (v8.??) of Kibana appear to have removed this API endpoint rendering this utility no longer functional. C'est la vie, eskbcli has served well but no longer.

ElasticSearch Kibana CLI (eskbcli) provides a shell interface to query an ElasticSearch backend via the Kibana frontend which is useful in situations where the ElasticSearch backend is not otherwise accessible.

ElasticSearch Kibana CLI makes it possible to copy-paste query expressions directly from the Kibana user-interface and then easily access very large sets of result data. This makes the eskbcli useful in SecOps situations where the ability to rapidly move from a Kibana query to raw data is valued.

Configuration options are available to adjust http-headers so-as-to enable access to Kibana in situations that require complex user-authentication such as when Kibana exists behind an OAuth reverse proxy or other session- based authentication arrangement.

Install / Upgrade

user@computer:~$ pip install [--upgrade] elasticsearch-kibana-cli

Documentation

Documentation is available at elasticsearch-kibana-cli.readthedocs.io

Usage

  • Search - Execute the named search configuration.
  • Summary - Summary report for search result datafile; use "-" to pipe stdin.
  • Show - Show the named eskbcli search configuration.
  • List - List the available eskbcli search names.

Config Files

Refer to the worked example config files with descriptions and details.

Project


Copyright © 2021-2023 Nicholas de Jong