Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use for false positives, exceptions, new coverage, noisy rules, or rule management via Kibana API.
---
name: security-detection-rule-management
description: >
Create, tune, and manage Elastic Security detection rules (SIEM and Endpoint). Use
for false positives, exceptions, new coverage, noisy rules, or rule management via
Kibana API.
compatibility: >
Requires Node.js 22+, network access to Kibana and Elasticsearch. Environment variables:
KIBANA_URL plus KIBANA_API_KEY or KIBANA_USERNAME/KIBANA_PASSWORD; ELASTICSEARCH_URL
or ELASTICSEARCH_CLOUD_ID plus ELASTICSEARCH_API_KEY or ELASTICSEARCH_USERNAME/ELASTICSEARCH_PASSWORD.
metadata:
author: elastic
version: 0.1.0
---
# Detection Rule Management
Create new detection rules for emerging threats and coverage gaps, and tune existing rules to reduce false positives.
All operations use the Kibana Detection Engine API via `rule-manager.js`.
## Execution rules
- Start executing tools immediately — do not read SKILL.md, browse the workspace, or list files first.
- Report tool output faithfully. Copy rule IDs, names, alert counts, exception IDs, and error messages exactly as
returned by the API. Do not abbreviate rule UUIDs, invent rule names, or round alert counts.… install to load the full skillIn any Claude conversation, say:
Install the Security Detection Rule Management skill
It activates automatically in your next session.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp