Best Elastic MCP Servers
Elastic is a search company that builds self-managed and SaaS offerings for search, logging, security, observability, and analytics use cases.
Why this server?
Provides detection lookup files for enrichment in Elasticsearch, enabling efficient threat detection queries using ES|QL ENRICH.
AlicenseAqualityBmaintenanceMachine-readable detection lookups for SIEM enrichment and AI agents. Query 800+ LOLBAS and GTFOBins binaries plus process parent-child baselines — get risk levels, abuse categories, and MITRE ATT\&CK mappings without embedding data in prompts.Last updated6Apache 2.0Why this server?
Facilitates interaction with Elastic's search and analytics engine, providing capabilities for document indexing, search, index management, and cluster health monitoring.
AlicenseBqualityCmaintenanceAn MCP server that enables interaction with Elasticsearch and OpenSearch clusters for searching documents and managing indices. It provides tools for cluster health monitoring, index configuration, and general API requests.Last updated16Apache 2.0Why this server?
Connects to Elastic products, specifically Elasticsearch, enabling natural language interaction with indices, mappings, and search capabilities.
AlicenseBqualityCmaintenanceConnects to Elasticsearch databases using the Model Context Protocol, allowing users to query and interact with their Elasticsearch indices through natural language conversations.Last updated45Apache 2.0Why this server?
Provides tools for querying, summarizing, and tracing logs stored in Elasticsearch, enabling AI assistants to analyze observability data directly.
Alicense-qualityBmaintenanceAn MCP server that connects Claude (or any MCP compatible client) to your existing log infrastructure. Query, summarize, and trace logs in plain English across GCP Cloud Logging, AWS CloudWatch, Azure Log Analytics, Grafana Loki, and Elasticsearch without writing filter expressions or leaving your editor.Last updated202MITWhy this server?
Provides tools to manage and query a knowledge base within Elastic, including document ingestion, text chunking, and semantic search retrieval.
FlicenseAqualityCmaintenanceAn MCP server that indexes PDF documentation and text into Elasticsearch for semantic search and retrieval. It enables users to query knowledge bases, ingest new files, and dynamically update content through MCP-compatible clients like Claude Desktop and Cursor.Last updated41Why this server?
Provides a comprehensive set of tools for security management, search operations, index management, and cluster monitoring within an Elasticsearch instance, allowing for management of users, roles, API keys, and execution of complex queries.
FlicenseBquality-maintenanceProvides comprehensive tools for managing Elasticsearch clusters, including security management, search operations, and index administration. It enables users to monitor cluster health, handle InfoSec tasks, and execute complex queries using Elasticsearch Query DSL and ES|QL.Last updated37Why this server?
Enables searching security events, pivoting on indicators, and performing endpoint response actions like isolation and forensic collection.
Alicense-qualityCmaintenanceAn AI-powered security operations platform that integrates with SIEM, EDR, and case management systems via MCP to automate incident response and investigation workflows. It provides specialized tools for alert triage, threat intelligence enrichment, and endpoint remediation across vendor-neutral APIs.Last updated29MITWhy this server?
Converts Sigma rules to Elasticsearch Lucene queries for detection in Elasticsearch.
Alicense-qualityCmaintenanceSigma detection rule writing, validation, and pySigma-based multi-backend conversion (Splunk, Elastic, Wazuh, Kibana) via 3 MCP tools and 3 Claude Code skills, backed by a 61-rule production corpus across 11 MITRE ATT\&CK tactic categories.Last updatedMITWhy this server?
Exports audit logs to Elastic via SIEM streaming.
Flicense-qualityBmaintenanceAI-native, zero-config CI/CD. Detects 33 languages + 40 frameworks, generates pipelines, runs locally at $0 cloud cost, diagnoses failures with AI, and deploys to 20 targets.Last updated