Elasticsearch MCP Server
Elasticsearch/OpenSearch MCP Server
Überblick
Eine Implementierung eines Model Context Protocol (MCP)-Servers, der die Interaktion mit Elasticsearch und OpenSearch ermöglicht. Dieser Server ermöglicht das Durchsuchen von Dokumenten, das Analysieren von Indizes und die Verwaltung des Clusters über eine Reihe von Tools.
Related MCP server: Elasticsearch MCP Server
Demo
https://github.com/user-attachments/assets/f7409e31-fac4-4321-9c94-b0ff2ea7ff15
Funktionen
Allgemeine Operationen
general_api_request: Führt eine allgemeine HTTP-API-Anfrage aus. Verwenden Sie dieses Tool für jede Elasticsearch/OpenSearch-API, für die kein dediziertes Tool vorhanden ist.
Index-Operationen
list_indices: Listet alle Indizes auf.get_index: Gibt Informationen (Mappings, Einstellungen, Aliase) über einen oder mehrere Indizes zurück.create_index: Erstellt einen neuen Index.delete_index: Löscht einen Index.create_data_stream: Erstellt einen neuen Data Stream (erfordert eine passende Index-Vorlage).get_data_stream: Ruft Informationen über einen oder mehrere Data Streams ab.delete_data_stream: Löscht einen oder mehrere Data Streams und ihre zugrunde liegenden Indizes.
Dokument-Operationen
search_documents: Durchsucht Dokumente.index_document: Erstellt oder aktualisiert ein Dokument im Index.get_document: Ruft ein Dokument anhand der ID ab.delete_document: Löscht ein Dokument anhand der ID.delete_by_query: Löscht Dokumente, die der angegebenen Abfrage entsprechen.
Cluster-Operationen
get_cluster_health: Gibt grundlegende Informationen über den Zustand des Clusters zurück.get_cluster_stats: Gibt eine Übersicht über die Cluster-Statistiken zurück.
Alias-Operationen
list_aliases: Listet alle Aliase auf.get_alias: Ruft Alias-Informationen für einen bestimmten Index ab.put_alias: Erstellt oder aktualisiert einen Alias für einen bestimmten Index.delete_alias: Löscht einen Alias für einen bestimmten Index.
Analyzer-Operationen
analyze_text: Analysiert Text mit einem angegebenen Analyzer oder einer benutzerdefinierten Analyse-Kette. Nützlich zum Debuggen von Suchabfragen und zum Verständnis, wie Text tokenisiert wird.
Umgebungsvariablen konfigurieren
Der MCP-Server unterstützt die folgenden Umgebungsvariablen:
Basisauthentifizierung (Benutzername/Passwort)
ELASTICSEARCH_USERNAME: Benutzername für die BasisauthentifizierungELASTICSEARCH_PASSWORD: Passwort für die BasisauthentifizierungOPENSEARCH_USERNAME: Benutzername für die OpenSearch-BasisauthentifizierungOPENSEARCH_PASSWORD: Passwort für die OpenSearch-Basisauthentifizierung
API-Key-Authentifizierung (nur Elasticsearch) – Empfohlen
ELASTICSEARCH_API_KEY: API-Key für die Elasticsearch- oder Elastic Cloud-Authentifizierung.
Verbindungseinstellungen
ELASTICSEARCH_HOSTS/OPENSEARCH_HOSTS: Kommagetrennte Liste von Hosts (Standard:https://localhost:9200)ELASTICSEARCH_CLUSTERS/OPENSEARCH_CLUSTERS: Inline-JSON-Objekt für benannte Cluster-Konfigurationen. Wenn gesetzt, können Tools mit dem optionalen Parameterclusterauf einen bestimmten Cluster abzielen.ELASTICSEARCH_CLUSTERS_FILE/OPENSEARCH_CLUSTERS_FILE: Pfad zu einer JSON-Datei mit dem Cluster-Objekt. Empfohlen, wenn die Konfiguration in eine andere JSON-Datei eingebettet ist (z. B. die MCP-Client-Konfiguration), da dies das Escaping von JSON-in-JSON vermeidet. Hat Vorrang vor der Inline-Variablen, wenn beide gesetzt sind.DEFAULT_CLUSTER: Standard-Clustername, der verwendet wird, wenn eine Multi-Cluster-Konfiguration festgelegt ist und ein Tool-Aufrufclusterweglässt (standardmäßig der erste konfigurierte Cluster).VERIFY_CERTS: Ob SSL-Zertifikate überprüft werden sollen (Standard:false)REQUEST_TIMEOUT: Anfrage-Timeout in Sekunden (optional, verwendet den Client-Standard, wenn nicht gesetzt)
Multi-Cluster-Konfiguration
Standardmäßig verwendet der Server einen einzelnen Elasticsearch-Cluster aus ELASTICSEARCH_HOSTS, ELASTICSEARCH_USERNAME, ELASTICSEARCH_PASSWORD und ELASTICSEARCH_API_KEY oder einen einzelnen OpenSearch-Cluster aus OPENSEARCH_HOSTS, OPENSEARCH_USERNAME und OPENSEARCH_PASSWORD. Um mehrere benannte Cluster zu konfigurieren, setzen Sie ELASTICSEARCH_CLUSTERS (oder OPENSEARCH_CLUSTERS) auf ein JSON-Objekt innerhalb der MCP-Server-Konfiguration. Da der Wert ein JSON-String ist, der in eine andere JSON-Datei eingebettet ist, müssen die inneren Anführungszeichen escaped werden:
{
"mcpServers": {
"elasticsearch-mcp-server": {
"command": "uvx",
"args": [
"elasticsearch-mcp-server"
],
"env": {
"ELASTICSEARCH_CLUSTERS": "{\"prod\": {\"hosts\": [\"https://prod-es:9200\"], \"api_key\": \"<PROD_API_KEY>\", \"verify_certs\": true}, \"staging\": {\"hosts\": [\"https://staging-es:9200\"], \"username\": \"elastic\", \"password\": \"<STAGING_PASSWORD>\"}}",
"DEFAULT_CLUSTER": "prod"
}
}
}
}Für bessere Lesbarkeit können Sie stattdessen ELASTICSEARCH_CLUSTERS_FILE (oder OPENSEARCH_CLUSTERS_FILE) auf eine eigenständige JSON-Datei verweisen lassen. Der Wert ist nur ein Pfad, sodass das Escaping von JSON-in-JSON vermieden wird:
{
"mcpServers": {
"elasticsearch-mcp-server": {
"command": "uvx",
"args": [
"elasticsearch-mcp-server"
],
"env": {
"ELASTICSEARCH_CLUSTERS_FILE": "/etc/mcp/es-clusters.json",
"DEFAULT_CLUSTER": "prod"
}
}
}
}/etc/mcp/es-clusters.json:
{
"prod": {
"hosts": ["https://prod-es:9200"],
"api_key": "<PROD_API_KEY>",
"verify_certs": true
},
"staging": {
"hosts": ["https://staging-es:9200"],
"username": "elastic",
"password": "<STAGING_PASSWORD>"
}
}Jedes Tool akzeptiert einen optionalen Parameter cluster. Wenn dieser weggelassen wird, verwendet der Server DEFAULT_CLUSTER. Wenn DEFAULT_CLUSTER nicht gesetzt ist, wird der erste Cluster im JSON-Objekt als Standard verwendet. Ein Tool-Aufruf, der auf einen bestimmten Cluster abzielt, sieht wie folgt aus:
{
"cluster": "staging",
"index": "logs-*",
"body": {
"query": {
"match_all": {}
}
}
}MCP-Server-Authentifizierung (nur HTTP-Transports)
Wenn der MCP-Server mit HTTP-basierten Transports (SSE oder Streamable HTTP) ausgeführt wird, können Sie die Bearer-Token-Authentifizierung aktivieren, um den Server vor unbefugtem Zugriff zu schützen.
MCP_API_KEY: API-Key für die MCP-Server-Authentifizierung. Clients müssen den HeaderAuthorization: Bearer <MCP_API_KEY>einfügen.
Wichtige Sicherheitshinweise:
Die Authentifizierung ist nur für HTTP-Transports (
sse,streamable-http) anwendbar. Derstdio-Transport verwendet lokale Prozesskommunikation und erfordert keine Authentifizierung.Wenn
MCP_API_KEYnicht gesetzt ist, ist der MCP-Server ohne Authentifizierung zugänglich. Dies ist ein Sicherheitsrisiko, wenn der Server über ein Netzwerk bereitgestellt wird.Für Produktionsbereitstellungen mit HTTP-Transports immer
MCP_API_KEYsetzen.
# Generate a secure API key (example using openssl)
export MCP_API_KEY=$(openssl rand -base64 32)
# Or set a custom API key
export MCP_API_KEY="your-secure-api-key-here"Hochrisiko-Operationen deaktivieren
DISABLE_HIGH_RISK_OPERATIONS: Setzen Sie auftrue, um alle Schreiboperationen zu deaktivieren (Standard:false)DISABLE_OPERATIONS: Kommagetrennte Liste spezifischer Operationen, die deaktiviert werden sollen (optional, verwendet die Standard-Schreiboperationsliste, wenn nicht gesetzt)
Wenn DISABLE_HIGH_RISK_OPERATIONS auf true gesetzt ist, werden alle MCP-Tools, die Schreiboperationen ausführen, vollständig vor dem MCP-Client ausgeblendet. In diesem Modus sind die folgenden MCP-Tools standardmäßig deaktiviert.
Index-Operationen:
create_indexdelete_index
Dokument-Operationen:
index_documentdelete_documentdelete_by_query
Data-Stream-Operationen:
create_data_streamdelete_data_stream
Alias-Operationen:
put_aliasdelete_alias
Allgemeine API-Operationen:
general_api_request
Optional können Sie eine kommagetrennte Liste von Operationen angeben, die in der Umgebungsvariable DISABLE_OPERATIONS deaktiviert werden sollen.
# Disable High-Risk Operations
export DISABLE_HIGH_RISK_OPERATIONS=true
# Disable specific operations only
export DISABLE_OPERATIONS="delete_index,delete_document,delete_by_query"GCF-Antwortkodierung (optional)
Sie können sich dafür entscheiden, die Tool-Ergebnis-Payloads als GCF (Graph Compact Format) zu serialisieren, ein tokenoptimiertes Drahtformat, im Inhaltsblock, den das Modell liest. Elasticsearch gibt große, gleichförmige Datensätze zurück (Suchtreffer, Aggregations-Buckets, Mappings), die Form, die GCF am besten komprimiert: Bei repräsentativen Antworten sind das ~39 % weniger Tokens als kompaktes JSON (40 % bei Suchtreffern), verlustfrei.
export RESPONSE_FORMAT=gcfstructuredContent bleibt unverändert erhalten, sodass das deklarierte Ausgabeschema eines Tools weiterhin validiert wird und jeder Nicht-Modell-Client weiterhin JSON erhält; nur der modellbezogene Textblock wird neu kodiert. Die Kodierung ist ausfallsicher: Jeder Fehler, einschließlich eines Werts außerhalb des kanonischen int64-Zahlenbereichs von GCF (den GCF ablehnt, anstatt ihn stillschweigend zu approximieren), lässt das ursprüngliche JSON-Ergebnis unverändert, sodass ein Tool-Aufruf niemals aufgrund der Kodierung verworfen wird. Das Standardverhalten bleibt unverändert, wenn RESPONSE_FORMAT nicht gesetzt ist.
Reproduzieren Sie den Token-Vergleich: uv run --with tiktoken python benchmarks/gcf_benchmark.py.
Elasticsearch/OpenSearch-Cluster starten
Starten Sie den Elasticsearch/OpenSearch-Cluster mit Docker Compose:
# For Elasticsearch
docker-compose -f docker-compose-elasticsearch.yml up -d
# For OpenSearch
docker-compose -f docker-compose-opensearch.yml up -dDer Standard-Benutzername für Elasticsearch ist elastic und das Passwort ist test123. Der Standard-Benutzername für OpenSearch ist admin und das Passwort ist admin.
Sie können auf Kibana/OpenSearch Dashboards über http://localhost:5601 zugreifen.
Stdio
Option 1: Mit uvx
Die Verwendung von uvx installiert das Paket automatisch von PyPI, ohne dass das Repository lokal geklont werden muss. Fügen Sie die folgende Konfiguration zur Konfigurationsdatei claude_desktop_config.json hinzu.
// For Elasticsearch with username/password
{
"mcpServers": {
"elasticsearch-mcp-server": {
"command": "uvx",
"args": [
"elasticsearch-mcp-server"
],
"env": {
"ELASTICSEARCH_HOSTS": "https://localhost:9200",
"ELASTICSEARCH_USERNAME": "elastic",
"ELASTICSEARCH_PASSWORD": "test123"
}
}
}
}
// For Elasticsearch with API key
{
"mcpServers": {
"elasticsearch-mcp-server": {
"command": "uvx",
"args": [
"elasticsearch-mcp-server"
],
"env": {
"ELASTICSEARCH_HOSTS": "https://localhost:9200",
"ELASTICSEARCH_API_KEY": "<YOUR_ELASTICSEARCH_API_KEY>"
}
}
}
}
// For OpenSearch
{
"mcpServers": {
"opensearch-mcp-server": {
"command": "uvx",
"args": [
"opensearch-mcp-server"
],
"env": {
"OPENSEARCH_HOSTS": "https://localhost:9200",
"OPENSEARCH_USERNAME": "admin",
"OPENSEARCH_PASSWORD": "admin"
}
}
}
}Option 2: Mit uv und lokaler Entwicklung
Die Verwendung von uv erfordert das lokale Klonen des Repositorys und die Angabe des Pfads zum Quellcode. Fügen Sie die folgende Konfiguration zur Konfigurationsdatei claude_desktop_config.json von Claude Desktop hinzu.
// For Elasticsearch with username/password
{
"mcpServers": {
"elasticsearch-mcp-server": {
"command": "uv",
"args": [
"--directory",
"path/to/elasticsearch-mcp-server",
"run",
"elasticsearch-mcp-server"
],
"env": {
"ELASTICSEARCH_HOSTS": "https://localhost:9200",
"ELASTICSEARCH_USERNAME": "elastic",
"ELASTICSEARCH_PASSWORD": "test123"
}
}
}
}
// For Elasticsearch with API key
{
"mcpServers": {
"elasticsearch-mcp-server": {
"command": "uv",
"args": [
"--directory",
"path/to/elasticsearch-mcp-server",
"run",
"elasticsearch-mcp-server"
],
"env": {
"ELASTICSEARCH_HOSTS": "https://localhost:9200",
"ELASTICSEARCH_API_KEY": "<YOUR_ELASTICSEARCH_API_KEY>"
}
}
}
}
// For OpenSearch
{
"mcpServers": {
"opensearch-mcp-server": {
"command": "uv",
"args": [
"--directory",
"path/to/elasticsearch-mcp-server",
"run",
"opensearch-mcp-server"
],
"env": {
"OPENSEARCH_HOSTS": "https://localhost:9200",
"OPENSEARCH_USERNAME": "admin",
"OPENSEARCH_PASSWORD": "admin"
}
}
}
}SSE
Option 1: Mit uvx
# export environment variables (with username/password)
export ELASTICSEARCH_HOSTS="https://localhost:9200"
export ELASTICSEARCH_USERNAME="elastic"
export ELASTICSEARCH_PASSWORD="test123"
# OR export environment variables (with API key)
export ELASTICSEARCH_HOSTS="https://localhost:9200"
export ELASTICSEARCH_API_KEY="<YOUR_ELASTICSEARCH_API_KEY>"
# By default, the SSE MCP server will serve on http://127.0.0.1:8000/sse
uvx elasticsearch-mcp-server --transport sse
# The host, port, and path can be specified using the --host, --port, and --path options
uvx elasticsearch-mcp-server --transport sse --host 0.0.0.0 --port 8000 --path /sseOption 2: Mit uv
# By default, the SSE MCP server will serve on http://127.0.0.1:8000/sse
uv run src/server.py elasticsearch-mcp-server --transport sse
# The host, port, and path can be specified using the --host, --port, and --path options
uv run src/server.py elasticsearch-mcp-server --transport sse --host 0.0.0.0 --port 8000 --path /sseStreamable HTTP
Option 1: Mit uvx
# export environment variables (with username/password)
export ELASTICSEARCH_HOSTS="https://localhost:9200"
export ELASTICSEARCH_USERNAME="elastic"
export ELASTICSEARCH_PASSWORD="test123"
# OR export environment variables (with API key)
export ELASTICSEARCH_HOSTS="https://localhost:9200"
export ELASTICSEARCH_API_KEY="<YOUR_ELASTICSEARCH_API_KEY>"
# By default, the Streamable HTTP MCP server will serve on http://127.0.0.1:8000/mcp
uvx elasticsearch-mcp-server --transport streamable-http
# The host, port, and path can be specified using the --host, --port, and --path options
uvx elasticsearch-mcp-server --transport streamable-http --host 0.0.0.0 --port 8000 --path /mcpOption 2: Mit uv
# By default, the Streamable HTTP MCP server will serve on http://127.0.0.1:8000/mcp
uv run src/server.py elasticsearch-mcp-server --transport streamable-http
# The host, port, and path can be specified using the --host, --port, and --path options
uv run src/server.py elasticsearch-mcp-server --transport streamable-http --host 0.0.0.0 --port 8000 --path /mcpKompatibilität
Der MCP-Server ist mit Elasticsearch 7.x, 8.x und 9.x kompatibel. Standardmäßig verwendet er den Elasticsearch-8.x-Client (ohne Suffix).
MCP-Server | Elasticsearch |
elasticsearch-mcp-server-es7 | Elasticsearch 7.x |
elasticsearch-mcp-server | Elasticsearch 8.x |
elasticsearch-mcp-server-es9 | Elasticsearch 9.x |
opensearch-mcp-server | OpenSearch 1.x, 2.x, 3.x |
Um den Elasticsearch-7.x-Client zu verwenden, führen Sie die Variante elasticsearch-mcp-server-es7 aus. Für Elasticsearch 9.x verwenden Sie elasticsearch-mcp-server-es9. Zum Beispiel:
uvx elasticsearch-mcp-server-es7Wenn Sie verschiedene Elasticsearch-Varianten (z. B. 7.x oder 9.x) lokal ausführen möchten, aktualisieren Sie einfach die Abhängigkeit elasticsearch in pyproject.toml und starten Sie den Server mit:
uv run src/server.py elasticsearch-mcp-serverKubernetes-Bereitstellung
Das Docker-Image wird unter ghcr.io/cr7258/elasticsearch-mcp-server veröffentlicht und das Helm-Chart ist als OCI-Artefakt im Repository oci://ghcr.io/cr7258/charts/elasticsearch-mcp-server verfügbar.
Vollständige Installationsanweisungen, Konfigurationsreferenz und Verwendungsbeispiele finden Sie in der Helm-Chart-README.
Lizenz
Dieses Projekt ist unter der Apache License Version 2.0 lizenziert – siehe die Datei LICENSE für Details.
Available Tools
20 toolsanalyze_textB
Analyze text to see how it would be tokenized.
Use this tool to understand how Elasticsearch/OpenSearch tokenizes and transforms text using analyzers. This is essential for debugging search queries and understanding why certain documents match or don't match.
| Name | Required | Description | Default |
|---|---|---|---|
| text | Yes | The text to analyze | |
| index | No | Index name to use its configured analyzer. If not specified, uses cluster-level analysis with built-in analyzers only. | |
| filter | No | List of token filters to apply (e.g., ['lowercase', 'stop']). Used with 'tokenizer' for custom analysis chain. | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. | |
| explain | No | If True, returns detailed information about each token including all token attributes and filter transformations. Useful for debugging complex analyzer chains. | |
| analyzer | No | Name of the analyzer to use (e.g., 'standard', 'korean', 'korean_search'). If index is specified, you can use custom analyzers defined in that index. | |
| tokenizer | No | Tokenizer to use for custom analysis chain. Cannot be used together with 'analyzer'. | |
| attributes | No | List of token attributes to return when explain=True (e.g., ['keyword', 'type']). If not specified, all attributes are returned. | |
| char_filter | No | List of character filters to apply before tokenization. Used with 'tokenizer' for custom analysis chain. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden. 'Analyze' implies a non-destructive read operation, and the debugging framing reinforces that, but the description discloses nothing about permissions, whether it touches cluster state, rate limits, or side effects. Adequate but not rich.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The first sentence is front-loaded and effective, but the next two sentences restate the same idea ('understand how ... tokenizes', 'understanding why ... match') with noticeable redundancy and without adding new information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a read-only analysis tool with a 100%-covered schema and an output schema that handles return values, the description covers purpose and primary use case well. The main gap is the absence of alternative-routing guidance, which matters given the large sibling set.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so every one of the 9 parameters is already documented in the schema. The description adds no parameter-level meaning beyond what the schema provides (the analyzer/tokenizer/index relationships and defaults all live in the schema), so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource ('analyze text to see how it would be tokenized') and clarifies the domain (Elasticsearch/OpenSearch analyzers). It is clear enough to distinguish from mutating siblings, but it never names a sibling or explicitly scopes itself against the read/index tools around it.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives a use case – debugging search queries and understanding why documents match or don't match – which implies when to reach for it. However, there are no explicit when-not conditions, no named alternatives (e.g., search_documents for actually running queries), and no prerequisites.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
create_data_streamB
Create a new data stream.
This creates a new data stream with the specified name. The data stream must have a matching index template before creation.
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Name of the data stream to create | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full behavioral burden, and it does disclose the key precondition that an index template must pre-exist. Beyond that it says nothing about required permissions, failure behavior, or whether creation is idempotent, so the disclosure is thin.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The first and second sentences are redundant ('Create a new data stream' vs 'This creates a new data stream with the specified name'), with no additional information in the second. The prerequisite sentence is the only one that earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the parameter schema is fully described. The remaining gap is behavioral/usage context — failure modes and differentiation from sibling creation tools — which leaves it only minimally viable.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100% with both parameters documented (name, optional cluster), so the schema does the heavy lifting. The description adds no syntax or format meaning beyond what the schema already states; baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Create a new data stream'), so the operation is unambiguous. However, it does nothing to distinguish itself from siblings like create_index or index_document, and the second sentence merely restates the first.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
It gives one real precondition ('must have a matching index template before creation'), which is useful context. But it offers no guidance on when to choose this over create_index or how it relates to the data-stream siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
create_indexC
Create a new index.
| Name | Required | Description | Default |
|---|---|---|---|
| body | No | Optional index configuration including mappings and settings | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden for a mutating operation. It does not disclose what happens if the index already exists, whether creation requires specific privileges, or whether the operation is idempotent; 'Create' is all the agent gets.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
At a single short sentence it is certainly concise and front-loaded, with zero wasted words. But it is under-specified rather than tightly scoped, so the brevity reflects a gap rather than efficiency.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists and all three parameters are documented, so return values and inputs need not be explained. What is missing is behavioral context for a mutation tool with no annotations: conflict/error behavior and permissions.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%: index name, optional body (mappings/settings), and optional cluster are all documented in the schema itself. The description adds nothing beyond the schema, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb and resource ('Create a new index'), which is unambiguous on its own. However, it offers no differentiation from siblings such as create_data_stream or index_document, which also create search-related resources.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no guidance on when to use this tool versus alternatives like create_data_stream, nor any mention of prerequisites or exclusions. The agent must infer usage entirely from the tool name.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_aliasC
Delete an alias for a specific index.
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Name of the alias | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It does not state that this is a destructive mutation, that it only removes the alias pointer (leaving index data intact), or what happens if the alias/index pair does not exist.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with zero filler. It is efficient, though its terseness is part of why behavioral coverage is thin.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists so return values need not be explained, but for a destructive operation with no annotations the description should at least clarify that only the alias mapping is removed, not indexed data. That key disambiguation is missing.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so all three parameters (name, index, cluster) are already documented in the schema. The description adds no format, default, or constraint detail beyond it, so baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Delete an alias') plus the scope 'for a specific index'. This separates it from put_alias, get_alias and list_aliases, though it does not explicitly name any sibling.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no guidance on when to delete an alias versus reassigning one with put_alias, nor any prerequisite or warning condition. The agent must infer usage entirely from the name.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_by_queryC
Deletes documents matching the provided query.
| Name | Required | Description | Default |
|---|---|---|---|
| body | Yes | Query to match documents for deletion | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden. It says 'deletes' but omits whether the operation is irreversible, what permissions it requires, whether it is transactional, and how many documents may be affected. For a destructive bulk operation this is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single short sentence with no filler or redundancy. However, its brevity comes at the cost of omitting useful behavioral context, so it is concise but not maximally informative.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The output schema exists, so return values need not be described. But for a destructive, potentially bulk-mutating tool with no annotations, the definition should disclose safety-relevant behavior such as irreversibility and permissions; it does not.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so all three parameters are already documented in the schema. The description adds no syntax or format details beyond what the schema provides, making the baseline 3 appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource: deletes documents matching a query. It implies bulk deletion rather than single-document deletion, but does not explicitly contrast itself with the sibling delete_document, so it stops short of full sibling differentiation.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description only restates the purpose. It gives no guidance on when to use delete_by_query versus delete_document or search_documents, and no prerequisites or warnings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_data_streamA
Delete one or more data streams.
Permanently deletes the specified data streams and all their backing indices.
| Name | Required | Description | Default |
|---|---|---|---|
| name | Yes | Name of the data stream(s) to delete. Can be a comma-separated list or wildcard pattern. | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations present, the description carries the full burden, and it does disclose the two most important traits: the deletion is permanent and it cascades to all backing indices. It stops short of covering permission requirements, what happens to in-use or partially-matched streams, or whether the default cluster target matters.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two short sentences, front-loaded with the action and followed by the consequence. No filler, no repetition of the title, and every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be described, and both parameters are fully documented in the schema. The destructive cascade is covered, leaving only operational details (permissions, behavior on missing/in-use streams) unaddressed for a mutation tool with no annotations.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents both 'name' (comma-separated/wildcard) and 'cluster' (default fallback). The description's 'one or more' only loosely echoes the wildcard capability and adds no syntax or default details beyond the schema, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb and resource ('Delete ... data streams'), which cleanly separates it from sibling delete_index and delete_document by the resource noun alone. It also clarifies scope ('one or more'), but never explicitly names a sibling or contrasts with delete_index, so it falls short of the 5 benchmark.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives no when-to-use guidance, no prerequisites, and no pointer to alternatives such as delete_index or general_api_request. The only implied context is that this is for data streams, which the name already conveys.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_documentC
Delete a document by ID.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | Document ID | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It does not state that deletion is destructive/irreversible, whether a missing ID errors or is silently ignored, whether the change is immediately visible (refresh), or whether the operation is idempotent.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single short sentence with the key selector front-loaded and no wasted words. It is efficient, though it is arguably terse rather than genuinely information-dense.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, return values needn't be explained, but for a destructive operation with zero annotations the description omits the safety and failure-mode context an agent needs. The absence of any alternatives guidance leaves a real gap for a 3-parameter delete tool.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so all three parameters (id, index, cluster) are already documented in the schema, establishing a baseline of 3. The description adds only the 'by ID' selector and gives no extra semantics such as cluster/index routing behavior.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Delete) and resource (document) plus the selector ('by ID'), which distinguishes it from the index-level delete_index. It does not, however, differentiate from the sibling delete_by_query, which is the closest alternative.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no when-to-use guidance, no mention of prerequisites, and no routing to alternatives such as delete_by_query for bulk/conditional deletion. The agent must infer the choice from the name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
delete_indexC
Delete an index.
| Name | Required | Description | Default |
|---|---|---|---|
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It does not state whether deletion is irreversible, what happens to indexed documents, whether it requires a stopped index or specific permissions, or how errors are surfaced. For a destructive operation with zero annotation coverage, this is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single, front-loaded sentence with zero waste. It is precise, if sparse, and earns its place without padding. Slight deduction for being too terse to be fully helpful.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is a destructive operation with no annotations and only a bare description. Even with an output schema covering return values and a fully documented parameter schema, the description omits critical context: irreversibility, side effects, permissions, and failure modes. An agent cannot safely invoke this on description alone.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and both parameters are documented in the schema (index name, optional cluster with default). The description adds nothing beyond the schema, so baseline 3 applies — adequate but no extra value.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource ('Delete an index'), so the purpose is unambiguous. But it offers no differentiation from siblings like delete_document, delete_alias, or delete_data_stream — it merely relies on the name. Minimum viable.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No when-to-use guidance, no prerequisites, no mention of alternatives. The agent gets no signal about how this differs from delete_by_query or other delete siblings.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
general_api_requestA
Perform a general HTTP API request. Use this tool for any Elasticsearch/OpenSearch API that does not have a dedicated tool.
| Name | Required | Description | Default |
|---|---|---|---|
| body | No | Request body | |
| path | Yes | API endpoint path | |
| method | Yes | HTTP method (GET, POST, PUT, DELETE, etc.) | |
| params | No | Query parameters | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden. It says nothing about permissions/auth, whether destructive methods (DELETE/PUT) are permitted, side effects on indices or data, error/response behavior, or rate limits — significant omissions for an unrestricted pass-through tool capable of writes and deletes.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two tight sentences, zero padding, and the purpose plus its differentiator are front-loaded. Nothing here is redundant or misplaced.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
This is a high-blast-radius, high-complexity catch-all with no annotations and no output schema, so the description should warn about write/delete risk, auth, and expected responses. It omits all of that, leaving the agent under-informed about the consequences of an arbitrary request.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so method, path, body, params, and cluster are all documented in the schema. The description adds no syntax, path-format, or cluster-selection detail beyond what the schema already states; baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a concrete action (perform an HTTP API request) and scopes it to Elasticsearch/OpenSearch APIs lacking a dedicated tool. The second sentence positively differentiates it from the many siblings (create_index, search_documents, etc.), so an agent can route without opening any schema.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
Explicitly says when to use it: any API with no dedicated tool. That implicitly and clearly defines when NOT to use it — prefer the named siblings. This is exactly the fallback routing guidance an agent needs.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_aliasC
Get alias information for a specific index.
| Name | Required | Description | Default |
|---|---|---|---|
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. 'Get' implies a read operation, but the description does not state permissions, rate limits, or whether it returns all aliases for the index or a single alias.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, front-loaded sentence with no wasted words. It is appropriately sized for a simple getter, though its brevity leaves gaps in usage and behavioral context.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the input schema fully covers parameters. However, with no annotations and no routing to alternatives such as list_aliases, the description remains incomplete regarding when and how to use this tool versus siblings.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both parameters are already documented in the schema. The description adds no additional meaning beyond what the schema provides, making the baseline score of 3 appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Get') and resource ('alias information') scoped to a specific index. It is clear enough to understand the operation, but it does not differentiate this tool from sibling list_aliases or get_index.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives no explicit when-to-use guidance, no prerequisites, and no alternatives. It merely restates the purpose, leaving the agent to infer the appropriate context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_cluster_healthC
Returns basic information about the health of the cluster.
| Name | Required | Description | Default |
|---|---|---|---|
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It says "basic information" but doesn't clarify that it's read-only, doesn't list what health indicators are included, and doesn't mention whether it causes side effects. For a health-check tool with no annotations, this is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single efficient sentence that is front-loaded with the verb and resource. It is concise but lacks additional structure that could provide context.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With no annotations, an output schema present, and one fully documented parameter, the description covers the basic purpose. However, it doesn't explain what "health" entails or how it differs from sibling stats tools, leaving the agent with insufficient behavioral context.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, and the schema already documents the optional cluster parameter and its default behavior. The description adds no parameter information, so this is a baseline case.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Returns) and resource (health of the cluster), so the agent knows this is a read-only health check. It is inferable from the name and doesn't collide with siblings like get_cluster_stats, but it doesn't explicitly differentiate itself from that sibling.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no guidance on when to use this tool versus alternatives such as get_cluster_stats or general_api_request. The purpose is implied by the name, but no explicit use context or exclusions are provided.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_cluster_statsB
Returns high-level overview of cluster statistics.
| Name | Required | Description | Default |
|---|---|---|---|
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden, yet it only says it returns an overview. It omits permission requirements, whether the call is read-only/safe, cost or rate considerations, and what 'statistics' actually encompass.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
One short, front-loaded sentence with no filler or repetition. For a zero-required-parameter read tool this is an appropriately sized description.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the single parameter is fully documented. But the total absence of annotations plus an unaddressed near-duplicate sibling (get_cluster_health) leaves the definition only minimally sufficient.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% and the single optional 'cluster' parameter is already documented as defaulting to the default cluster, so the description adds nothing beyond structured data. Baseline 3 applies when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description names a specific verb and resource ('Returns ... cluster statistics') and scopes it as a 'high-level overview,' so the agent knows it is an aggregate/summary read. However, it does nothing to separate this from the close sibling get_cluster_health, which an agent could easily confuse it with.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no statement of when to use this tool, no prerequisites, and no mention of alternatives such as get_cluster_health or general_api_request. The agent must guess the intended context from the name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_data_streamC
Get information about one or more data streams.
Retrieves configuration, mappings, settings, and other information about the specified data streams.
| Name | Required | Description | Default |
|---|---|---|---|
| name | No | Name of the data stream(s) to retrieve. Can be a comma-separated list or wildcard pattern. If not provided, retrieves all data streams. | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full disclosure burden. 'Retrieves' implies a read-only operation but never states it, and there is nothing about permissions, error behavior for missing streams, or result size. The list of returned fields ('configuration, mappings, settings') is the only added behavioral content.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is brief and front-loaded, but the second sentence largely restates the first with a field list rather than adding new information. No wasted words beyond that redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the input schema is complete. However, with zero annotations the description should carry basic safety/usage context for the read operation and does not, leaving an agent to infer read-only semantics and when to prefer this over sibling lookup tools.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both 'name' (comma-separated list or wildcard, all if omitted) and 'cluster' are already fully documented in the schema. The description adds nothing about parameter semantics, which is acceptable at the 100% coverage baseline.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb ('Get') and resource ('data streams') plus the cardinality ('one or more'), so an agent immediately knows this is a read of data-stream metadata. It does not explicitly differentiate itself from siblings like get_index or create_data_stream, relying on the verb to carry that distinction.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no when-to-use guidance, no mention of prerequisites, and no named alternative (e.g., get_index for indices, delete_data_stream for removal). The only usage signal is the implicit 'retrieve info' framing, which the agent must infer.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_documentC
Get a document by ID.
| Name | Required | Description | Default |
|---|---|---|---|
| id | Yes | Document ID | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. 'Get' implies a read, but the description says nothing about behavior on a missing document (error vs empty), permissions, or whether the result is a point-in-time snapshot; an output schema exists, which covers return values but not behavior.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with zero waste, correctly leading with verb and resource. It is appropriately sized given the rich schema and existing output schema.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema and full parameter documentation, the definition is minimally sufficient for a simple read tool. The remaining gap is behavioral context (error semantics, cluster fallback implications) that neither annotations nor the description supply.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the schema already documents id, index, and the optional cluster default. The description adds only 'by ID', which is redundant with the schema; baseline 3 applies when the schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Get) and resource (document) and adds the lookup key ('by ID'), which distinguishes it from search_documents. It does not, however, reference any sibling tool or explain how it differs from them.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No when-to-use guidance, no statement of when to prefer search_documents or get_index instead, and no prerequisites such as whether the index must exist. Usage must be inferred from the name alone.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_indexB
Returns information (mappings, settings, aliases) about one or more indices.
| Name | Required | Description | Default |
|---|---|---|---|
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It says what information is returned but omits behavioral details: whether it requires read permissions, whether it works on missing indices (throws vs returns empty), and it doesn't mention that it's a read-only operation with no side effects.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single, efficient sentence that front-loads the return types. No filler or redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, the description needn't detail return values, but for a read-only tool with no annotations it should still disclose permission requirements and behavior on missing indices. The lack of any behavioral context leaves gaps.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so both parameters are already documented in the schema. The description adds 'one or more indices' (implying the index param could accept multiple, though schema shows a single string), which is a minor addition. Baseline 3 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (Returns) and resource (indices) and lists the info types (mappings, settings, aliases). It is distinguishable from siblings like create_index or list_indices, but it doesn't explicitly name alternatives for retrieving index metadata.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this tool versus siblings such as list_indices, get_alias, or get_data_stream. The description only says what it returns, not when to call it or for what purpose.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
index_documentC
Creates or updates a document in the index.
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | Optional document ID | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. | |
| document | Yes | Document data |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden. It discloses upsert behavior ('creates or updates'), but omits permissions, overwrite/conflict semantics tied to the optional id, index existence prerequisites, and any side effects.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
It is a single front-loaded sentence with no wasted words. However, its extreme brevity is undersized for a mutation tool with optional id and cluster semantics.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The output schema covers return values and the 100% schema coverage documents parameters, so the description need not repeat those. Still, missing usage guidance and mutation behavior details leave meaningful gaps for an upsert tool with no annotations.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and every parameter is documented in the schema. The description adds no parameter meaning beyond what the schema already provides, so the baseline of 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (creates or updates) and resource (a document in the index), making the core operation clear. It does not differentiate the tool from sibling document tools like get_document or search_documents.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides no when-to-use guidance, no alternatives, and no conditions such as requiring an existing index or using the optional id to update instead of create. Sibling tools are not mentioned at all.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_aliasesB
List all aliases.
| Name | Required | Description | Default |
|---|---|---|---|
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden, and 'List' at least implies a non-mutating read. However, it says nothing about required permissions, cluster scoping behavior when the cluster arg is omitted, or result size, so the behavioral profile remains thin.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single front-loaded sentence with zero filler. It is efficiently structured, though its brevity borders on under-specification rather than optimal conciseness.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is simple, takes no required parameters, and has an output schema so return values need not be explained. Still, the description leaves the cluster-scoping behavior and the distinction from get_alias unaddressed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100% and the single 'cluster' parameter is fully documented in the schema, including the default-cluster fallback. The description adds nothing about it, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb (List) and resource (aliases) with an explicit 'all' scope, so the operation is unambiguous. It does not distinguish itself from the sibling get_alias, which fetches a single alias, so an agent gets no routing signal beyond the name.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No when-to-use guidance, no prerequisites, and no mention of the alternative get_alias for single-alias lookups. The agent must infer the choice purely from the tool name.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_indicesC
List all indices.
| Name | Required | Description | Default |
|---|---|---|---|
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. "List" implies a safe read, but the description says nothing about permissions, pagination, result size limits, or whether it spans all clusters. For a tool with zero annotation coverage this is a notable gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single short sentence that is front-loaded and wastes no words, but it is under-specified rather than genuinely concise. There is nothing to trim, yet nothing extra is provided either.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists, so return values need not be explained, and the lone parameter is documented. But with no annotations and no usage context, the description is only minimally complete for an agent deciding between this and its many siblings.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, and the single optional 'cluster' parameter is fully documented in the schema (default cluster if omitted). The description adds no parameter meaning beyond that, so the baseline of 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a clear verb+resource ("List all indices"), which distinguishes it from get_index (single index) and list_aliases (different resource). However, it offers no explicit sibling differentiation or scope detail beyond the plural noun.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this versus get_index or search_documents, and no mention of prerequisites or contexts. The agent must infer usage entirely from the name.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
put_aliasC
Create or update an alias for a specific index.
| Name | Required | Description | Default |
|---|---|---|---|
| body | Yes | Alias configuration | |
| name | Yes | Name of the alias | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden of behavioral disclosure. It doesn't mention whether this operation is idempotent, what permissions are required, whether it overwrites existing aliases, or any side effects. For a mutation tool with zero annotation coverage, this is a significant gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Single sentence, front-loaded with the action and resource. Zero waste, appropriately sized.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a mutation tool with no annotations and an output schema that may cover returns, the description is incomplete. It lacks usage context, behavioral details like idempotency or side effects, and any prerequisites (e.g., index must exist). Given the complexity of a 4-parameter tool with a nested object, more context is needed.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so all parameters are documented in the schema. The description adds no additional parameter meaning beyond what the schema provides. Baseline 3 is appropriate when schema does the heavy lifting.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a specific verb+resource: 'Create or update an alias' for 'a specific index'. This clearly distinguishes from list_aliases, get_alias, and delete_alias. However, it doesn't explicitly differentiate from other alias tools beyond the verb.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance on when to use this tool versus alternatives like list_aliases or get_alias. The description only states what it does, not when it should be invoked or what conditions apply.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_documentsC
Search for documents.
| Name | Required | Description | Default |
|---|---|---|---|
| body | Yes | Search query | |
| index | Yes | Name of the index | |
| cluster | No | Optional cluster name. Uses the default cluster if omitted. |
Output Schema
| Name | Required | Description |
|---|---|---|
No output parameters | ||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full behavioral burden, yet it discloses nothing about pagination, query DSL expectations, or that this is a non-mutating read. Only the verb 'Search' weakly implies a read operation; permissions, limits, and result behavior are all unstated.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
A single short sentence is efficient and front-loaded, but it is under-specified rather than genuinely concise. There is no wasted text, yet almost no information is conveyed.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
An output schema exists so return values need not be explained, but this is a nested-object search tool with two required params and zero annotations, and the description supplies none of the missing behavioral or usage context. It is inadequate for the tool's complexity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the parameters (index, body, cluster) are already documented in the schema. The description adds no additional meaning about the query body structure or cluster selection, so the baseline 3 applies.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
States a clear verb and resource ('Search for documents'), but adds no scope or qualifier to distinguish it from siblings like get_document or delete_by_query. An agent cannot tell from the description alone which index/query semantics apply or how it differs from other document operations.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
There is no when-to-use guidance, no mention of alternatives (e.g., get_document for ID lookup), and no prerequisites such as needing an existing index. The agent must infer everything from the name.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
20 tool updates
v2.1.4- Changed
analyze_text10 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / analyzer / descriptionAdded value: +"Name of the analyzer to use (e.g., 'standard', 'korean',\n 'korean_search'). If index is specified, you can use\n custom analyzers defined in that index." - added
Input schema / properties / attributes / descriptionAdded value: +"List of token attributes to return when explain=True\n (e.g., ['keyword', 'type']). If not specified, all\n attributes are returned." - added
Input schema / properties / char_filter / descriptionAdded value: +"List of character filters to apply before tokenization.\n Used with 'tokenizer' for custom analysis chain." - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / explain / descriptionAdded value: +"If True, returns detailed information about each token\n including all token attributes and filter transformations.\n Useful for debugging complex analyzer chains." - added
Input schema / properties / filter / descriptionAdded value: +"List of token filters to apply (e.g., ['lowercase', 'stop']).\n Used with 'tokenizer' for custom analysis chain." - added
Input schema / properties / index / descriptionAdded value: +"Index name to use its configured analyzer. If not specified,\n uses cluster-level analysis with built-in analyzers only." - added
Input schema / properties / text / descriptionAdded value: +"The text to analyze" - added
Input schema / properties / tokenizer / descriptionAdded value: +"Tokenizer to use for custom analysis chain. Cannot be\n used together with 'analyzer'."
- Changed
create_data_stream3 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / name / descriptionAdded value: +"Name of the data stream to create"
- Changed
create_index4 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / body / descriptionAdded value: +"Optional index configuration including mappings and settings" - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
delete_alias4 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index" - added
Input schema / properties / name / descriptionAdded value: +"Name of the alias"
- Changed
delete_by_query4 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / body / descriptionAdded value: +"Query to match documents for deletion" - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
delete_data_stream3 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / name / descriptionAdded value: +"Name of the data stream(s) to delete.\n Can be a comma-separated list or wildcard pattern."
- Changed
delete_document4 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / id / descriptionAdded value: +"Document ID" - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
delete_index3 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
general_api_request6 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / body / descriptionAdded value: +"Request body" - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / method / descriptionAdded value: +"HTTP method (GET, POST, PUT, DELETE, etc.)" - added
Input schema / properties / params / descriptionAdded value: +"Query parameters" - added
Input schema / properties / path / descriptionAdded value: +"API endpoint path"
- Changed
get_alias3 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
get_cluster_health2 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted."
- Changed
get_cluster_stats2 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted."
- Changed
get_data_stream3 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / name / descriptionAdded value: +"Name of the data stream(s) to retrieve.\n Can be a comma-separated list or wildcard pattern.\n If not provided, retrieves all data streams."
- Changed
get_document4 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / id / descriptionAdded value: +"Document ID" - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
get_index3 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
index_document5 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / document / descriptionAdded value: +"Document data" - added
Input schema / properties / id / descriptionAdded value: +"Optional document ID" - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
- Changed
list_aliases2 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted."
- Changed
list_indices2 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted."
- Changed
put_alias5 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / body / descriptionAdded value: +"Alias configuration" - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index" - added
Input schema / properties / name / descriptionAdded value: +"Name of the alias"
- Changed
search_documents4 fields changed- added
Input schema / additionalPropertiesAdded value: +false - added
Input schema / properties / body / descriptionAdded value: +"Search query" - added
Input schema / properties / cluster / descriptionAdded value: +"Optional cluster name. Uses the default cluster if omitted." - added
Input schema / properties / index / descriptionAdded value: +"Name of the index"
20 tool updates
v2.1.2- Added
analyze_text - Added
create_data_stream - Added
create_index - Added
delete_alias - Added
delete_by_query - Added
delete_data_stream - Added
delete_document - Added
delete_index - Added
general_api_request - Added
get_alias - Added
get_cluster_health - Added
get_cluster_stats - Added
get_data_stream - Added
get_document - Added
get_index - Added
index_document - Added
list_aliases - Added
list_indices - Added
put_alias - Added
search_documents
19 tool updates
v2.1.1- Removed
create_data_stream - Removed
create_index - Removed
delete_alias - Removed
delete_by_query - Removed
delete_data_stream - Removed
delete_document - Removed
delete_index - Removed
general_api_request - Removed
get_alias - Removed
get_cluster_health - Removed
get_cluster_stats - Removed
get_data_stream - Removed
get_document - Removed
get_index - Removed
index_document - Removed
list_aliases - Removed
list_indices - Removed
put_alias - Removed
search_documents
3 tool updates
v1.0.0- Added
create_data_stream - Added
delete_data_stream - Added
get_data_stream
16 tool updates
- First observed
create_index - First observed
delete_alias - First observed
delete_by_query - First observed
delete_document - First observed
delete_index - First observed
general_api_request - First observed
get_alias - First observed
get_cluster_health - First observed
get_cluster_stats - First observed
get_document - First observed
get_index - First observed
index_document - First observed
list_aliases - First observed
list_indices - First observed
put_alias - First observed
search_documents
TDQS
Scored across 20 tools
Each tool targets a clearly distinct resource and action (index, document, alias, data stream, cluster, analysis, or generic API). Overlaps like get_index vs list_indices and get_alias vs list_aliases are cleanly separated by specificity. The general_api_request fallback is explicitly scoped to APIs without dedicated tools, so it does not create real misselection risk.
Tools follow a consistent snake_case verb_noun convention (create_index, delete_document, get_cluster_health, put_alias, etc.). The only minor exception is general_api_request, but it still fits the overall readable naming style. There is no mixing of camelCase or conflicting verb patterns.
At 20 tools, the surface is slightly heavy by the usual 3–15 guideline, but Elasticsearch is a broad domain and each tool covers a meaningful resource area. The set avoids extreme bloat and does not include redundant operations.
Core CRUD and lifecycle coverage exists for indices, documents, aliases, data streams, and cluster inspection, with search and text analysis included. Notable gaps remain—such as dedicated index template management (required for data streams), bulk operations, and update-by-query—but the general_api_request tool provides a workaround for any missing API.
Maintenance
Related MCP Connectors
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
A Model Context Protocol server for Wix AI tools
- mcpOAuthcom.gibsonai
GibsonAI MCP server: manage your databases with natural language
Related MCP Servers
- FlicenseNot gradedqualityDmaintenanceA Model Context Protocol server that enables LLMs to interact with Elasticsearch clusters, allowing them to manage indices and execute search queries using natural language.2-
- AlicenseBqualityDmaintenanceConnects to Elasticsearch databases using the Model Context Protocol, allowing users to query and interact with their Elasticsearch indices through natural language conversations.419 npmApache 2.0
- FlicenseBqualityDmaintenanceConnects to Elasticsearch clusters through the Model Context Protocol, enabling natural language querying and management of Elasticsearch data. Provides tools to search indices, list available indices, and retrieve index mappings.3-
- AlicenseBqualityDmaintenanceEnables interaction with Elasticsearch clusters for health checks, index management, document CRUD operations, and search via natural language.1011 npmMIT