Elastic ML anomaly detection skill - investigation/RCA, score explanation,
---
name: kibana-anomaly-detection
description: Elastic ML anomaly detection skill — investigation/RCA, score explanation,
job operations (create, datafeed, start/stop, results), and troubleshooting (missing
docs, memory limits, datafeed health, lifecycle). Operates against Kibana Agent
Builder MCP tools (`ad_*`) on `.ml-anomalies-*`, `.ml-config`, `.ml-notifications-*`,
`.ml-annotations-*`. Use when answering "what broke?"/"which entity?"/RCA, "why
is score high/low?"/renormalization, "datafeed stopped"/"memory limit", or any request
to set up or configure an ML anomaly detection job.
metadata:
author: elastic
version: 0.2.0
compatibility: Kibana 8.x–9.x with Agent Builder and Workflows; Elasticsearch 8.x–9.x
with machine learning
---
# Elastic ML Anomaly Detection
Single skill covering all anomaly detection work against **Kibana Agent Builder** MCP at
`{KIBANA_URL}/api/agent_builder/mcp`. Use the **Mode Selector** below to pick the right approach for the user's question
— modes share the same tool surface and concepts.
## Platform
- Read path: ES|QL against `.ml-anomalies-*`, `.ml-config`, `.ml-notifications-*`, `.ml-annotations-*`… install to load the full skillIn any Claude conversation, say:
Install the Kibana Anomaly Detection skill
It activates automatically in your next session.
Not connected yet? Connect your AI first →
MCP endpoint
https://skillme.dev/api/mcp