Skip to content

Elasticsearch Kibana CLI documentation

PyPi Python Versions Read the Docs License


ElasticSearch Kibana CLI relies on the availability of a /elasticsearch/_msearch API endpoint exposed through Kibana. Recent versions (v8.??) of Kibana appear to have removed this API endpoint rendering this utility no longer functional. C'est la vie, eskbcli has served well but no longer.

ElasticSearch Kibana CLI (eskbcli) provides a shell interface to query an ElasticSearch backend via the Kibana frontend which is useful in situations where the ElasticSearch backend is not otherwise accessible.

ElasticSearch Kibana CLI makes it possible to copy-paste query expressions directly from the Kibana user-interface and then easily access very large sets of result data. This makes the eskbcli useful in SecOps situations where the ability to rapidly move from a Kibana query to raw data is valued.

Configuration options are available to adjust http-headers so-as-to enable access to Kibana in situations that require complex user-authentication such as when Kibana exists behind an OAuth reverse proxy or other session- based authentication arrangement.

Install / Upgrade

user@computer:~$ pip install [--upgrade] elasticsearch-kibana-cli


Documentation is available at


  • Search - Execute the named search configuration.
  • Summary - Summary report for search result datafile; use "-" to pipe stdin.
  • Show - Show the named eskbcli search configuration.
  • List - List the available eskbcli search names.

Config Files

Refer to the worked example config files with descriptions and details.


Copyright © 2021-2023 Nicholas de Jong