Create and manage AI indices
This page is currently hidden from the documentation navigation.
The following Context Engine pages are live:
An AI index groups the sources, automations, and Knowledge Indicators (KIs) that agents retrieve as context for a defined subject. Its name and description help agents decide when that context is relevant. Create and maintain AI indices interactively in Kibana or programmatically with the Context Engine APIs. You can update or delete AI indices that you create. Managed AI indices are read-only.
Turn on the contextEngine:enabled advanced setting in the current Kibana space. You also need the All privilege for the Context Engine feature. To remove associated workflow automations when deleting an AI index, you also need permission to delete workflows. To delete its backing index and KIs, you need the delete_index index privilege on that index.
Define the purpose and boundaries of the AI index before creating it. For planning guidance, refer to Define the AI index's purpose.
Create an AI index in Kibana for an interactive setup, or use the API for programmatic provisioning.
Create a custom AI index as follows:
- Open Context from the Kibana navigation.
- Select Create AI Index.
- Enter a Name. It must start with a lowercase letter or number and can contain lowercase letters, numbers, hyphens, and underscores.
- Enter a Description that states what the AI index is for and what its KIs contain. Include example questions the KIs should help answer and any known gaps in the information.
- Optional: Under Agent traces, select the traces that you want to use as feedback about how agents use the context.
- Select Create AI index.
The AI index opens with a confirmation message. Its Sources section is empty, and its Automations section remains locked until you add at least one source.
The name also determines the generated Elasticsearch index used to store KIs. You cannot rename an AI index in the UI after creating it.
Use the create AI index API when you need to provision AI indices programmatically. The request defines the AI index ID, its Elasticsearch destination, and its initial description, sources, automations, and traces.
For example, run the following request in Console:
POST kbn:/api/context_engine/ai_index
{
"id": "support_context",
"description": "Context about support cases, including recurring issues, affected products, resolution patterns, and known gaps.",
"dest": {
"type": "index",
"value": "ai-index-idx-support_context"
},
"sources": [],
"automations": [],
"traces": []
}
The response returns "status": "created". Add sources and automations in later API requests, or include them in the create request when their definitions are already known. The API reference provides the complete request and response schemas.
View AI indices in Kibana, or retrieve their definitions with the API.
In Kibana, open Context to view the AI indices available in the current space, then select one to inspect its configuration and generated KIs.
For programmatic access, use the following APIs:
- List AI indices returns the AI indices available to the caller.
- Get an AI index returns the complete definition of one AI index.
In Kibana, you can update the description that agents and generated automation workflows use. With the API, you can update the complete AI index definition.
Keep the description aligned with the context the AI index actually contains. The description shapes generated automation workflows and helps agents decide whether the AI index is relevant.
Update it as follows:
- Open Context, then select the AI index.
- In Description, select Edit.
- Update the description, then select Save.
- Confirm that the updated description appears on the AI index page.
Use the create or update AI index API to update an AI index programmatically. The request body replaces the complete AI index record. Include its destination and every source, automation, and trace that you want to preserve.
For example, the following request updates the description of the AI index created previously:
PUT kbn:/api/context_engine/ai_index/support_context
{
"description": "Context about support cases, including recurring issues, affected products, resolution patterns, known gaps, and verified queries for current case details.",
"dest": {
"type": "index",
"value": "ai-index-idx-support_context"
},
"sources": [],
"automations": [],
"traces": []
}
Delete a custom AI index from Kibana or with the API. In either case, decide whether to preserve or delete its generated KIs and attached workflow automations.
Deleting an AI index always removes its Context Engine entry. You can also remove the generated KIs and workflow automations associated with it.
Delete an AI index as follows:
Open Context.
Open the actions menu for the AI index, then select Delete AI index.
In the confirmation dialog, select which associated resources to remove:
- Also delete the backing index
<index>and its Knowledge Indicators: selected by default. Clear it to keep the generated KIs and their Elasticsearch index. - Also delete its N automations: selected by default when the AI index has automations and you have permission to delete workflows. Otherwise, it's unavailable.
- Also delete the backing index
Select Delete AI index.
Confirm that the AI index no longer appears in Context.
If you preserve an associated resource, deleting the AI index does not delete that resource. Agents can no longer discover or retrieve from the deleted AI index through Context Engine.
You cannot edit or delete a managed AI index. Its owning Elastic integration controls its configuration and lifecycle.
Use the delete AI index API for scripted cleanup. By default, the API deletes only the Context Engine entry and preserves its Elasticsearch destination, KIs, and attached workflows. Set the cleanup parameters explicitly when you also want to delete those resources.
For example, the following request deletes the entry, its destination and KIs, and its attached workflow automations:
DELETE kbn:/api/context_engine/ai_index/support_context?delete_knowledge_indicators=true&delete_automations=true
Check the response's errors array for any resource that could not be deleted after the AI index entry was removed.