Elasticsearch MCP server
Last verified: 2026-09
Search an Elasticsearch cluster.
Community Databases & data Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code
What it does
Elastic's MCP for a cluster: list indices, mappings, Query DSL search, ES|QL, shards. It is a query surface, not a cluster admin UI.
It sits in Databases & data: A database MCP is SQL or an API with your credentials.
Good for
- List indices and mappings before writing a query.
- Search with Query DSL for a support ticket or log pattern.
- Run ES|QL when that is how the cluster is queried.
- Check shard layout when something is yellow/red.
Tools
- list_indices — What indices exist.
- get_mappings — Field mappings for one index.
- search — Query DSL.
- esql — ES|QL.
- get_shards — Shard layout.
Config (Claude Desktop / Cursor / Windsurf)
Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets.
Windows paths look like C:\\Users\\you\\project, not /path/to.
Host-side steps →
Claude Desktop
| OS | Config file |
|---|---|
| macOS | ~/Library/Application Support/Claude/claude_desktop_config.json |
| Windows | %APPDATA%\Claude\claude_desktop_config.json
(usually C:\Users\<you>\AppData\Roaming\Claude\) |
| Linux | ~/.config/Claude/claude_desktop_config.json |
Cursor
| Scope | macOS / Linux | Windows |
|---|---|---|
| This project | .cursor/mcp.json in the repo root | |
| This user | ~/.cursor/mcp.json |
%USERPROFILE%\.cursor\mcp.json |
Windsurf
| OS | Config file |
|---|---|
| macOS / Linux | ~/.codeium/windsurf/mcp_config.json |
| Windows | %USERPROFILE%\.codeium\windsurf\mcp_config.json |
{
"mcpServers": {
"elasticsearch": {
"command": "npx",
"args": [
"-y",
"@elastic/mcp-server-elasticsearch"
],
"env": {
"ES_URL": "https://...es.io",
"ES_API_KEY": "..."
}
}
}
}
Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.
One-liner: npx -y @elastic/mcp-server-elasticsearch
Secrets it wants: ES_URL, ES_API_KEY
How to get started
- Point ES_URL at the cluster and use an API key with index privileges, not a superuser.
- Ask it to list indices, then search one index with a small size.
- Do not give it destructive cluster privileges.
Access risk
Search can return documents you forgot were indexed (PII, tokens). An overly broad key can delete indices if the cluster allows it.
When to skip it
Skip it for a SQL database or for logs you already have in Grafana/Datadog.
Instead: PostgreSQL, Grafana, Datadog.
Vs alternatives
| Server | Official? | Needs a secret? | Best for |
|---|---|---|---|
| Elasticsearch | No | Yes | Search an Elasticsearch cluster. |
| PostgreSQL | Yes | Yes | Run SQL against a Postgres database. |
| Grafana | No | Yes | Dashboards and datasources. |
| Datadog | No | Yes | Metrics, logs, and monitors. |
More in Databases & data
FAQ
Can search return secrets?
Yes. People index tokens and PII. An overly broad key can also delete indices. Use an API key with index privileges, not superuser.
Elasticsearch or Postgres?
Search/logs vs relational. If the data is already in ES, do not copy it into SQL for the model.
What env?
ES_URL and ES_API_KEY (or username/password — see the repo).
Does it admin the cluster?
It is a query surface. Do not give it destructive cluster privileges.