Streams

Kibana Streams is a centralized UI for managing Elasticsearch data streams: retention, field extraction, routing into child streams, and data quality. This library maps to Streams through two ingest targets.

Kibana Streams This library What it means
Classic stream [DataStream<T>] You own templates. Bootstrap creates component + data stream templates.
Wired stream [WiredStream<T>] Elasticsearch manages templates and lifecycle. Bulk goes to a managed endpoint.

Classic streams work with existing {type}-{dataset}-{namespace} data streams. Wired streams are the managed ingest path (Elastic Stack 9.2+ / serverless preview) that supports hierarchical inheritance and cascading configuration.

Mermaid diagram
Use case Attribute Guide
Append-only logs/metrics with local mappings [DataStream<T>] Data streams
LogsDB storage mode [DataStream<T>(DataStreamMode = LogsDb)] LogsDB
Managed wired ingest (serverless / Streams) [WiredStream<T>] Wired streams
ECS documents from ecs-dotnet [WiredStream<T>(IngestEndpoint = LogsEcs)] ECS and OTel endpoints

Once documents land in Streams, Kibana features operate on them. The .NET library does not author Streamlang or extract knowledge indicators — those are configured in Kibana (or via the Streams API).

See Downstream Streams features for how document shape affects Streamlang, significant events, and knowledge indicators.