Read Kibana alerts, rules, and cases, then make changes as approved steps
Connect Kibana and your agent can read what your detection and observability stack is doing: alerting rules, detection engine rules, open cases, connectors, and data views. When something needs to change — a new alerting rule, a case opened for an incident, a stale rule removed — the agent shows the exact call first and waits for your approval. Luumen signs in with basic authentication.
ReadCheck Fleet PermissionsCheck the permissions for the Fleet API.
ReadGet Fleet Enrollment API KeyRetrieve details of a specific enrollment API key by its ID.
ReadGet Fleet Enrollment API KeysFetch a list of enrollment API keys.
ReadGet Fleet EPM CategoriesGet all available package categories in the Elastic Package Manager (EPM) with package counts.
ReadGet Fleet EPM Data StreamsRetrieve the list of data streams in the Elastic Package Manager.
ReadGet Fleet EPM Package DetailsRetrieves comprehensive details for a specific Fleet integration package version from the Elastic Package Manager (EPM).
ReadGet Fleet EPM Package FileRetrieves a specific file from an Elastic Package Manager (EPM) package.
ReadGet Fleet EPM PackagesFetch the list of available packages in the Elastic Package Manager.
ReadGet Installed EPM PackagesRetrieve the list of installed packages in the Elastic Package Manager.
ReadGet Fleet EPM Packages (Limited)Retrieves a limited list of package names from the Elastic Package Manager (EPM) registry.
ReadGet EPM Package StatisticsRetrieves usage statistics for a specific Fleet package in Kibana, including the number of package policies and agent policies using the package.
ReadGet Fleet Package PoliciesRetrieves a list of Fleet package policies (integration policies) in Kibana.
ReadGet Fleet Server HostFetch details of a specific Fleet server host by its item ID.
ReadGet Fleet Server HostsRetrieve the list of Fleet Server hosts.
ReadGet Index Management IndicesFetch information about indices managed by Kibana's Index Management feature.
ReadGet Node MetricsRetrieve statistics for nodes in an Elasticsearch cluster, often visualized in Kibana.
ReadGet Reporting JobsRetrieve a list of reporting jobs in Kibana.
ReadGet Saved ObjectsRetrieve a list of saved objects in Kibana based on specified criteria.
ReadGet Kibana StatusGet the current status of Kibana.
WriteDelete Alerting RuleDelete an alerting rule in Kibana. Approval by default
WriteDelete ConnectorDelete a connector in Kibana. Approval by default
WriteDelete Fleet OutputDelete a specific output configuration in Kibana Fleet. Approval by default
WriteDelete Fleet ProxyDeletes a Fleet proxy configuration by its unique identifier. Approval by default
WriteDelete ListDeletes a list. Approval by default
WriteDelete Osquery Saved QueryDelete a saved Osquery query by its saved object ID. Approval by default
WriteDelete Saved ObjectDelete a saved object in Kibana. Approval by default
WriteCreate Alerting RuleCreate a new alerting rule in Kibana. Approval by default
WriteCreate CaseCreate a new case in Kibana. Approval by default
WriteCreate Kibana ConnectorCreate a new connector in Kibana. Approval by default
WriteCreate DashboardCreate a new dashboard in Kibana. Approval by default
WriteCreate Data ViewCreate a new data view (index pattern) in Kibana. Approval by default
WriteCreate or Update Saved ObjectCreate or update a saved object in Kibana. Approval by default
One prompt, start to finish
What a governed Kibana run looks like inside Luumen.
Questions
How does LuumenAI connect to Kibana?
Authorize once with Basic auth. Luumen lists the scopes each action needs before you approve the connection, and credentials never appear in the chat.
Can LuumenAI change things in Kibana on its own?
Read actions answer immediately. Anything that writes — delete alerting rule, delete connector, delete fleet output, delete fleet proxy, and more — is shown as a plan and requires approval by default, including the 7 actions classified as destructive. Administrators configure that per tool, so you decide exactly which actions can ever run unattended.
Who gets access to the integration?
You decide. Actions are granted per agent, skill, and team, and per environment — production is not staging. Read access can be broad while writes stay narrow.
Is there an audit trail?
Every call to Kibana — read or write, approved or declined — is recorded with the actor, the input, and the result, and can be linked to the ticket or change record.