Elasticsearch Kibana CLI (eskbcli)
ElasticSearch Kibana CLI (eskbcli
) provides a shell interface to query
an ElasticSearch backend via the Kibana frontend which is useful in
situations where the ElasticSearch backend is not otherwise accessible.
ElasticSearch Kibana CLI makes it possible to copy-paste query expressions
directly from the Kibana user-interface and then easily access very large
sets of result data. This makes the eskbcli
useful in SecOps situations
where the ability to rapidly move from a Kibana query to raw data is
valued.
Configuration options are available to adjust http-headers so-as-to enable
access to Kibana in situations that require complex user-authentication
such as when Kibana exists behind an OAuth reverse proxy or other session-
based authentication arrangement.
Install / Upgrade
user@computer:~$ pip install [--upgrade] elasticsearch-kibana-cli
Documentation
Documentation is available at https://elasticsearch-kibana-cli.readthedocs.io
Usage
- search - Execute the named search configuration.
- summary - Summary report for search result datafile; use "-" to pipe stdin.
- show - Show the named eskbcli search configuration.
- list - List the available eskbcli search names.
Config files
Refer to the worked example config files
with descriptions and details.
Project
Copyright © 2021 Nicholas de Jong