OpenSearch Logs MCP Server
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| OPENSEARCH_DEV_PASSWORD | Yes | Password for the development OpenSearch environment | |
| OPENSEARCH_DEV_USERNAME | Yes | Username for the development OpenSearch environment | |
| OPENSEARCH_PROD_PASSWORD | Yes | Password for the production OpenSearch environment | |
| OPENSEARCH_PROD_USERNAME | Yes | Username for the production OpenSearch environment |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_logsA | Search OpenSearch logs with a free-text query. Supports Lucene query syntax. Examples: 'error AND authentication', 'status:500', 'message:timeout' |
| search_by_traceA | Search logs by OpenTelemetry trace ID to see all logs related to a specific request/transaction. |
| search_by_serviceC | Search logs filtered by service name, optionally with additional filters. |
| search_errorsC | Search for error logs, optionally filtered by service or additional query. |
| get_field_valuesB | Get the most common values for a specific field. Useful for discovering available services, log levels, or other field values. |
| search_by_fieldC | Search logs by a specific field and value. |
| get_mappingA | Get the field mapping for the index. Useful for discovering available fields and their types. |
| get_sample_logB | Get a single sample log entry to see the structure and available fields. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 8 tools
Most tools have distinct purposes, but there is some overlap between search_by_field, search_by_service, search_errors, and search_logs, which could cause confusion about which to use for specific filtering needs. However, the descriptions clarify their specialized roles, such as search_by_service for service filtering and search_errors for error-specific queries, reducing ambiguity.
All tool names follow a consistent verb_noun pattern with snake_case, such as get_field_values, search_by_trace, and search_logs. This uniformity makes the tool set predictable and easy to understand, enhancing usability for agents.
With 8 tools, the server is well-scoped for log analysis in OpenSearch, covering essential operations like discovery (get_field_values, get_mapping, get_sample_log) and various search methods. Each tool serves a clear purpose without feeling excessive or insufficient for the domain.
The tool set provides strong coverage for log querying and discovery, including field analysis, sample inspection, and multiple search types. A minor gap is the lack of tools for log management operations like deleting or exporting logs, but core workflows for analysis are well-supported.