Best Elastic MCP Servers
Elastic is a search company that builds self-managed and SaaS offerings for search, logging, security, observability, and analytics use cases.
Why this server?
Connects to Elastic products, specifically Elasticsearch, enabling natural language interaction with indices, mappings, and search capabilities.
AlicenseBqualityDmaintenanceConnects to Elasticsearch databases using the Model Context Protocol, allowing users to query and interact with their Elasticsearch indices through natural language conversations.45 npmApache 2.0Why this server?
Facilitates interaction with Elastic's search and analytics engine, providing capabilities for document indexing, search, index management, and cluster health monitoring.
AlicenseBqualityDmaintenanceAn MCP server that enables interaction with Elasticsearch and OpenSearch clusters for searching documents and managing indices. It provides tools for cluster health monitoring, index configuration, and general API requests.16Apache 2.0Why this server?
Provides detection lookup files for enrichment in Elasticsearch, enabling efficient threat detection queries using ES|QL ENRICH.
AlicenseAqualityCmaintenanceMachine-readable detection lookups for SIEM enrichment and AI agents. Query 800+ LOLBAS and GTFOBins binaries plus process parent-child baselines — get risk levels, abuse categories, and MITRE ATT\&CK mappings without embedding data in prompts.6Apache 2.0Why this server?
Converts Sigma rules to Elasticsearch Lucene queries for detection in Elasticsearch.
AlicenseAqualityAmaintenanceSigma detection rule writing, validation, and pySigma-based multi-backend conversion (Splunk, Elastic, Wazuh, Kibana) via 3 MCP tools and 3 Claude Code skills, backed by a 61-rule production corpus across 11 MITRE ATT\&CK tactic categories.32MITWhy this server?
Provides integration with the Elastic Stack to enable read-only log search, aggregation, and analysis across Elasticsearch and Kibana.
AlicenseAqualityDmaintenanceA read-only MCP server that gives AI assistants natural language access to Elasticsearch/Kibana logs for querying and analysis.71MITWhy this server?
Provides access to Elastic UI (EUI), enabling selection and guidance for log search, observability, and data-dense telemetry dashboards.
AlicenseAqualityBmaintenanceEnables AI coding agents to discover, compare, select, and enforce design systems and component libraries, with installation guidance, component APIs, and strict adherence directives to prevent default substitutions.10MITWhy this server?
Flags dependencies whose licences flipped, such as Elastic's 7.11 change, with the exact version where each flip happened.
FlicenseAqualityBmaintenance40 regulation-and-deadline linters (CRA/CSAF, PCI DSS 6.4.3, WCAG 2.1 AA, DORA, NIS2, EU AI Act, KSeF, NF-e) that AI agents call over MCP. Free checks on the open file; licence key unlocks workspace scan and CI exit code.3-Why this server?
Provides tools for querying, summarizing, and tracing logs stored in Elasticsearch, enabling AI assistants to analyze observability data directly.
AlicenseNot gradedqualityCmaintenanceAn MCP server that connects Claude (or any MCP compatible client) to your existing log infrastructure. Query, summarize, and trace logs in plain English across GCP Cloud Logging, AWS CloudWatch, Azure Log Analytics, Grafana Loki, and Elasticsearch without writing filter expressions or leaving your editor.3 npm3MITWhy this server?
Integrates with Elastic detection rules and the Elastic Stack, providing conversion of Sigma rules to KQL, querying Elastic detection content, and using Elastic Common Schema mappings for detection engineering.
FlicenseBqualityBmaintenanceEnables detection engineers to search, build, validate, and correlate detection rules across multiple SIEM formats using MITRE ATT&CK, Atomic Red Team, and threat intelligence.129-