Elasticsearch MCP Server
The official Elasticsearch MCP server connects AI agents to your Elasticsearch cluster to explore and query data directly in natural language. Agents can list indices, read field mappings, run full Query DSL searches, execute ES|QL queries, and inspect shard information across the cluster.
Install Elasticsearch
- Published by
- Official (vendor)
- Transport
- Remote (HTTP)
- Authentication
- API key
Claude Desktop, Claude Code and Cursor
Add this to the mcpServers object in your client's
config file, then restart the client.
{
"mcpServers": {
"elasticsearch": {
"type": "http",
"url": "{KIBANA_URL}/api/agent_builder/mcp"
}
}
}
VS Code uses a different key — show that config
Identical entry, filed under servers rather than
mcpServers. Put it in
.vscode/mcp.json for one workspace.
{
"servers": {
"elasticsearch": {
"type": "http",
"url": "{KIBANA_URL}/api/agent_builder/mcp"
}
}
}
Before it will answer
Read this before copying a config from anywhere else: the standalone elastic/mcp-server-elasticsearch Docker server is DEPRECATED and now receives critical security updates only. It has been superseded by the Agent Builder MCP endpoint shown here, available in Elastic 9.2.0+ and on Elasticsearch Serverless. Most directories still list the retired Docker config. Replace {KIBANA_URL} with your own Kibana endpoint; a non-default space becomes {KIBANA_URL}/s/{SPACE_NAME}/api/agent_builder/mcp. Elastic documents API-key auth for machine-to-machine use and OAuth 2.1 for interactive clients.
Tools
esql
Execute an ES|QL query against the Elasticsearch cluster.
get_mappings
Get the field mappings for a specific Elasticsearch index.
get_shards
Get shard information for all or specific indices.
list_indices
List all of the available indices in the Elasticsearch cluster.
search
Perform an Elasticsearch search using Query DSL syntax.