Kibana Data streams API
Data stream APIs enable you to manage data streams, which are collections of indices that share the same index template and are managed as a single unit for time-series data.
Data stream APIs enable you to manage data streams, which are collections of indices that share the same index template and are managed as a single unit for time-series data.
Every API here is available over the APIs.io API and to AI agents over MCP.
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
find_apisBrowse and filter every API in the catalog.get_api_artifactsOne API's artifacts, grouped by type.get_openapiThe primary OpenAPI for this API.find_similar_apisAPIs that look like this one.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.curl "https://apis.io/api/v1/apis/kibana-data-streams-api"
curl "https://apis.io/api/v1/apis?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.
openapi: 3.2.0
info:
contact:
name: Kibana Team
description: The Kibana REST APIs enable you to manage resources such as connectors, data views, and saved objects.
title: Kibana Data streams API
version: ''
x-doc-license:
name: Attribution-NonCommercial-NoDerivatives 4.0 International
url: https://creativecommons.org/licenses/by-nc-nd/4.0/
x-feedbackLink:
label: Feedback
url: https://github.com/elastic/docs-content/issues/new?assignees=&labels=feedback%2Ccommunity&projects=&template=api-feedback.yaml&title=%5BFeedback%5D%3A+
servers:
- url: https://{kibana_url}
variables:
kibana_url:
default: localhost:5601
security:
- apiKeyAuth: []
- basicAuth: []
tags:
- name: Data Streams
description: Data stream APIs enable you to manage data streams, which are collections of indices that share the same index template and are managed as a single unit for time-series data.
x-displayName: Data streams
paths:
/api/fleet/data_streams:
get:
description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/fleet/data_streams
Refer to Spaces for more information.
List all Fleet-managed data streams with metadata including package, namespace, size, and last activity.
[Required authorization] Route required privileges: fleet-agents-all AND fleet-agent-policies-all AND fleet-settings-all.'
operationId: get-fleet-data-streams
parameters: []
responses:
'200':
content:
application/json:
examples:
getDataStreamsExample:
description: List of Fleet-managed data streams
value:
data_streams:
- dashboards:
- id: nginx-overview
title: Nginx Overview
dataset: nginx.access
index: logs-nginx.access-default
last_activity_ms: 1700000000000
namespace: default
package: nginx
package_version: 1.20.0
serviceDetails: null
size_in_bytes: 1048576
size_in_bytes_formatted: 1mb
type: logs
- dashboards: []
dataset: system.cpu
index: metrics-system.cpu-default
last_activity_ms: 1699999000000
namespace: default
package: system
package_version: 1.38.0
serviceDetails: null
size_in_bytes: 524288
size_in_bytes_formatted: 512kb
type: metrics
schema:
additionalProperties: false
type: object
properties:
data_streams:
items:
additionalProperties: false
type: object
properties:
dashboards:
items:
additionalProperties: false
type: object
properties:
id:
type: string
title:
type: string
required:
- id
- title
maxItems: 10000
type: array
dataset:
type: string
index:
type: string
last_activity_ms:
type: number
namespace:
type: string
package:
type: string
package_version:
type: string
serviceDetails:
additionalProperties: false
type:
- object
- 'null'
properties:
environment:
type: string
serviceName:
type: string
required:
- environment
- serviceName
size_in_bytes:
type: number
size_in_bytes_formatted:
anyOf:
- type: number
- type: string
type:
type: string
required:
- index
- dataset
- namespace
- type
- package
- package_version
- last_activity_ms
- size_in_bytes
- size_in_bytes_formatted
- dashboards
- serviceDetails
maxItems: 10000
type: array
required:
- data_streams
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
summary: Get data streams
tags:
- Data Streams
x-metaTags:
- content: Kibana
name: product_name
/api/fleet/epm/data_streams:
get:
description: '**Spaces method and path for this operation:**
get /s/{space_id}/api/fleet/epm/data_streams
Refer to Spaces for more information.
Get a list of data streams created by installed integration packages.
[Required authorization] Route required privileges: integrations-read OR fleet-setup OR fleet-all.'
operationId: get-fleet-epm-data-streams
parameters:
- description: Filter by data stream type
in: query
name: type
required: false
schema:
enum:
- logs
- metrics
- traces
- synthetics
- profiling
type: string
- description: Filter data streams by dataset name
in: query
name: datasetQuery
required: false
schema:
type: string
- description: Sort order, ascending or descending
in: query
name: sortOrder
required: false
schema:
default: asc
enum:
- asc
- desc
type: string
- description: When true, only return data streams that are not associated with a package
in: query
name: uncategorisedOnly
required: false
schema:
default: false
type: boolean
responses:
'200':
content:
application/json:
examples:
getDataStreamsExample:
description: List of data streams from installed packages
value:
data_streams:
- ilm_policy: logs-default
index_template: logs-system.syslog
name: logs-system.syslog-default
package: system
package_version: 1.55.0
title: System syslog logs
schema:
additionalProperties: false
type: object
properties:
items:
items:
additionalProperties: false
type: object
properties:
name:
type: string
required:
- name
maxItems: 10000
type: array
required:
- items
description: Successful response
'400':
content:
application/json:
examples:
genericErrorResponseExample:
description: Example of a generic error response
value:
error: Bad Request
message: An error message describing what went wrong
statusCode: 400
schema:
additionalProperties: false
description: Generic Error
type: object
properties:
attributes: {}
error:
type: string
errorType:
type: string
message:
type: string
statusCode:
type: number
required:
- message
- attributes
description: Bad Request
summary: Get data streams
tags:
- Data Streams
x-metaTags:
- content: Kibana
name: product_name
components:
securitySchemes:
apiKeyAuth:
description: 'These APIs use key-based authentication. You must create an API key and use the encoded value in the request header. For example: `Authorization: ApiKey base64AccessApiKey`
'
in: header
name: Authorization
type: apiKey
basicAuth:
scheme: basic
type: http
x-topics:
- title: Kibana spaces
content: "Spaces enable you to organize your dashboards and other saved objects into meaningful categories.\nYou can use the default space or create your own spaces.\n\nTo run APIs in non-default spaces, you must add `s/{space_id}/` to the path.\nFor example:\n\n```bash\ncurl -X GET \"http://${KIBANA_URL}/s/marketing/api/data_views\" \\\n -H \"Authorization: ApiKey ${API_KEY}\"\n```\n\nIf you use the Kibana console to send API requests, it automatically adds the appropriate space identifier.\n\nTo learn more, check out [Spaces](https://www.elastic.co/docs/deploy-manage/manage-spaces).\n"