@elastic/input-configurations
@elastic/input-configurations — AI coding skill
| name | input-configurations |
| description | >- |
| license | Apache-2.0 |
input-configurations
When to use
Load this skill whenever tasks include:
- building, modifying, or reviewing
agent/stream/*.yml.hbstemplates for non-CEL input types - configuring request, response, pagination, cursor, or authentication blocks in HTTPJSON templates
- wiring up cloud storage inputs (AWS S3, GCS, Azure Blob, Azure EventHub)
- setting up network inputs (TCP, UDP, HTTP Endpoint, WebSocket)
- configuring file-based inputs (Filestream, Logfile, Journald, Winlog)
- enabling Federated Identity (Cloud Connectors) on an AWS integration package
When not to use
Do not use this skill as the primary guide for:
- CEL program development (
cel-programs) -- CEL program structure, state model, and mito workflow. Exception: theauth.aws/use_cloud_connectorstemplate block for Federated Identity is owned here viareferences/federated-identity-aws.md - ingest pipeline processor design (
ingest-pipelines) - field mappings and ECS compliance (
ecs-field-mappings) var_groups/provider_permissionsschema andformat_versionfloors alone (package-spec) -- use this skill for the end-to-end federation procedure that applies them
Mandatory first read
Always load references/common-input-patterns.md first. It covers patterns that apply to every input type (tags, processors passthrough, variable conventions, forwarded/publisher_pipeline.disable_host coupling). These patterns are prerequisites for all type-specific guides.
Type routing table
Detect the input type from the filename pattern in agent/stream/ or from the data stream manifest input: field, then load the matching guide.
| Input type | Filename pattern | Guide |
|---|---|---|
| HTTPJSON | httpjson.yml.hbs |
references/httpjson-guide.md |
| AWS S3 | aws-s3.yml.hbs |
references/aws-s3-guide.md |
| CloudWatch | aws-cloudwatch.yml.hbs |
references/aws-cloudwatch-guide.md |
| Azure Blob Storage | azure-blob-storage.yml.hbs |
references/azure-blob-storage-guide.md |
| Azure Event Hub | azure-eventhub.yml.hbs |
references/azure-eventhub-guide.md |
| GCS | gcs.yml.hbs |
references/gcs-guide.md |
| GCP Pub/Sub | gcp-pubsub.yml.hbs |
references/gcp-pubsub-guide.md |
| TCP | tcp.yml.hbs |
references/tcp-udp-guide.md |
| UDP | udp.yml.hbs |
references/tcp-udp-guide.md |
| HTTP Endpoint | http_endpoint.yml.hbs |
references/http-endpoint-guide.md |
| Filestream | filestream.yml.hbs |
references/filestream-logfile-guide.md |
| Logfile | log.yml.hbs |
references/filestream-logfile-guide.md |
| Journald | journald.yml.hbs |
references/journald-guide.md |
| Winlog | winlog.yml.hbs |
references/winlog-guide.md |
| WebSocket | websocket.yml.hbs |
references/websocket-guide.md |
Load only the guide for the detected input type, not all guides.
For Federated Identity tasks (any eligible input type, including cel), load
references/federated-identity-aws.md regardless of which input type is
involved.
Handoff
- For CEL program logic, hand off to the
cel-programsskill. Keep this skill loaded for Federated Identityauth.aws/use_cloud_connectorsedits oncel.yml.hbs. - For manifest schema (
var_groups,provider_permissions,format_version/ conditions floors), hand off to thepackage-specskill (references/var-groups-and-provider-permissions.md). - For pipeline issues discovered while reviewing input templates, hand off to the
ingest-pipelinesskill. - For field mapping issues found in template variable wiring, hand off to the
ecs-field-mappingsskill.
References
references/common-input-patterns.md-- tags, processors passthrough, variable conventions, review flags (applies to ALL input types)references/httpjson-guide.md-- HTTPJSON template syntax, structure, validation rules, pagination patterns, authentication, cursor persistencereferences/aws-s3-guide.md-- S3 bucket/SQS notification collectionreferences/aws-cloudwatch-guide.md-- CloudWatch log group collectionreferences/azure-blob-storage-guide.md-- Azure Blob Storage collectionreferences/azure-eventhub-guide.md-- Azure Event Hub collectionreferences/gcs-guide.md-- Google Cloud Storage collectionreferences/gcp-pubsub-guide.md-- GCP Pub/Sub collectionreferences/tcp-udp-guide.md-- TCP and UDP (syslog-style) listenersreferences/http-endpoint-guide.md-- HTTP Endpoint (webhook receiver)references/filestream-logfile-guide.md-- Filestream and legacy Logfile inputsreferences/journald-guide.md-- Journald collectionreferences/winlog-guide.md-- Windows Event Log collectionreferences/websocket-guide.md-- WebSocket streaming (may embed CEL)references/federated-identity-aws.md-- AWS Federated Identity procedure: input classification, federation vars,auth.aws/use_cloud_connectors, input gating (schema lives inpackage-spec)
Loading...
Select a file to preview
Analyzing security...
Checking scan reports and verification data.
Bill of Materials
Everything this skill can do — files, network, commands, and more.