List AI Indices Experimental

GET /api/context_engine/ai_index

Spaces method and path for this operation:

get /s/{space_id}/api/context_engine/ai_index

Refer to Spaces for more information.

Lists up to 100 AI Indices in the current space that the caller can read. The response omits an AI Index when the caller cannot read its backing index. Empty AI Indices are still included. A caller with no read privilege on any index gets a 403 response.

The space comes from the request URL (/s/{spaceId}/…) or defaults to the default space. It cannot be specified in any other way.

Returns a 404 response when Context Engine is turned off in this space (contextEngine:enabled).

For more information, refer to the Context Engine documentation.

[Required authorization] Route required privileges: contextEngine:read.

Responses

  • 200 application/json

    The AI Indices available to the caller in the current space.

    Hide response attribute Show response attribute object
    • ai_indices array[object] Required

      The AI Indices available to the caller in the current space.

      Hide ai_indices attributes Show ai_indices attributes object
      • automations array[object] Required

        Automations associated with the AI Index.

        Hide automations attributes Show automations attributes object
        • type string Required

          Value is workflow.

        • value string Required

          The workflow ID.

      • date_created string Required

        ISO 8601 timestamp of when the AI Index was created.

      • date_modified string Required

        ISO 8601 timestamp of when the AI Index was last modified.

      • description string

        Human-readable description of the AI Index.

      • dest object Required

        The data stream or index that backs the AI Index.

        Additional properties are NOT allowed.

        Hide dest attributes Show dest attributes object
        • type string Required

          The type of the backing store.

          Values are data_stream or index.

        • value string Required

          The data stream or index the AI Index is attached to.

      • feedback_analysis object

        The recurring feedback analysis, which reads agent signals and proposes improvement actions for the AI Index.

        Additional properties are NOT allowed.

        Hide feedback_analysis attributes Show feedback_analysis attributes object
        • agent_id string

          Agent Builder agent ID that runs the analysis.

        • allowed_actions array[string]

          Improvement actions the analysis may propose.

          Values are add_ki, edit_ki, remove_ki, add_workflow, edit_workflow, remove_workflow, add_source, edit_source, or remove_source.

        • enabled boolean Required

          Whether the recurring feedback analysis is desired to run.

        • schedule object

          When the analysis runs.

          Additional properties are NOT allowed.

          Hide schedule attribute Show schedule attribute object
          • interval string Required

            How often to analyze, for example 1h.

        • signal_filter string

          KQL narrowing which signals the analysis reads.

        • signal_time_range object
          Any of:
      • id string Required

        The unique identifier of the AI Index.

      • managed boolean Required

        Whether the AI Index is managed by a plugin and therefore immutable.

      • memory_enabled boolean Required

        Whether this AI Index accepts memory writes.

      • sources array[object] Required

        Additional sources that provide context for the AI Index.

        Hide sources attributes Show sources attributes object
        • type string Required

          esql for an ES|QL query, or connector for a data connector.

          Values are esql or connector.

        • value string Required

          An ES|QL query for esql, or a connector ID for connector.

      • traces array[object] Required

        Trace sources linked to this AI Index, each with its derived ES|QL query.

        Hide traces attributes Show traces attributes object
        • query string Required

          The ES|QL query derived from this trace source at read time.

        • type string Required

          elastic_agent for an Agent Builder agent, index for an index or data stream name or pattern, or esql for an ES|QL query.

          Values are elastic_agent, index, or esql.

        • value string Required

          The trace source value.

  • 403 application/json

    The caller has no read privilege on any index, so Elasticsearch rejected the request.

    Hide response attributes Show response attributes object
    • error string

      The HTTP status text.

    • message string Required

      A human-readable error message.

    • statusCode number

      The HTTP status code.

  • 404 application/json

    Context Engine is turned off in this space.

    Hide response attributes Show response attributes object
    • error string

      The HTTP status text.

    • message string Required

      A human-readable error message.

    • statusCode number

      The HTTP status code.

GET /api/context_engine/ai_index
curl \
  -X GET "https://${KIBANA_URL}/api/context_engine/ai_index" \
  -H "Authorization: ApiKey ${API_KEY}"
GET kbn:/api/context_engine/ai_index
Response examples (200)
Example response listing the AI Indices the caller can read
{
  "ai_indices": [
    {
      "automations": [],
      "date_created": "2026-09-22T12:00:00.000Z",
      "date_modified": "2026-09-22T12:00:00.000Z",
      "description": "Knowledge about customer support cases.",
      "dest": {
        "type": "data_stream",
        "value": "ai-index-ds-customer-support"
      },
      "id": "customer_support",
      "managed": false,
      "memory_enabled": true,
      "sources": [
        {
          "type": "esql",
          "value": "FROM support-cases | LIMIT 100"
        }
      ],
      "traces": []
    }
  ]
}
Response examples (403)
The caller has no read privilege on any index
{
  "error": "Forbidden",
  "message": "security_exception\n\tRoot causes:\n\t\tsecurity_exception: action [indices:data/read/msearch] is unauthorized for user [jdoe] with effective roles [support_reader], this action is granted by the index privileges [read,all]",
  "statusCode": 403
}
Response examples (404)
Context Engine is turned off in this space
{
  "error": "Not Found",
  "message": "Not Found",
  "statusCode": 404
}