Suggest a server AI tools directory →

Elasticsearch MCP server

Last verified: 2026-09

Search an Elasticsearch cluster.

Community Databases & data Needs a secret Claude Desktop, Cursor, Windsurf, Claude Code, VS Code

What it does

Elastic's MCP for a cluster: list indices, mappings, Query DSL search, ES|QL, shards. It is a query surface, not a cluster admin UI.

It sits in Databases & data: A database MCP is SQL or an API with your credentials.

Good for

  • List indices and mappings before writing a query.
  • Search with Query DSL for a support ticket or log pattern.
  • Run ES|QL when that is how the cluster is queried.
  • Check shard layout when something is yellow/red.

Tools

  • list_indices — What indices exist.
  • get_mappings — Field mappings for one index.
  • search — Query DSL.
  • esql — ES|QL.
  • get_shards — Shard layout.

Config (Claude Desktop / Cursor / Windsurf)

Paste the JSON below. Same mcpServers shape. Replace placeholder paths and secrets. Windows paths look like C:\\Users\\you\\project, not /path/to. Host-side steps →

Claude Desktop

OSConfig file
macOS~/Library/Application Support/Claude/claude_desktop_config.json
Windows%APPDATA%\Claude\claude_desktop_config.json (usually C:\Users\<you>\AppData\Roaming\Claude\)
Linux~/.config/Claude/claude_desktop_config.json

Cursor

ScopemacOS / LinuxWindows
This project.cursor/mcp.json in the repo root
This user~/.cursor/mcp.json %USERPROFILE%\.cursor\mcp.json

Windsurf

OSConfig file
macOS / Linux~/.codeium/windsurf/mcp_config.json
Windows%USERPROFILE%\.codeium\windsurf\mcp_config.json
{
  "mcpServers": {
    "elasticsearch": {
      "command": "npx",
      "args": [
        "-y",
        "@elastic/mcp-server-elasticsearch"
      ],
      "env": {
        "ES_URL": "https://...es.io",
        "ES_API_KEY": "..."
      }
    }
  }
}

Windsurf remote MCP: use serverUrl instead of url if the block below is HTTP.

One-liner: npx -y @elastic/mcp-server-elasticsearch

Secrets it wants: ES_URL, ES_API_KEY

Source repo →

How to get started

  1. Point ES_URL at the cluster and use an API key with index privileges, not a superuser.
  2. Ask it to list indices, then search one index with a small size.
  3. Do not give it destructive cluster privileges.

Access risk

Search can return documents you forgot were indexed (PII, tokens). An overly broad key can delete indices if the cluster allows it.

When to skip it

Skip it for a SQL database or for logs you already have in Grafana/Datadog.

Instead: PostgreSQL, Grafana, Datadog.

Vs alternatives

ServerOfficial?Needs a secret?Best for
ElasticsearchNoYesSearch an Elasticsearch cluster.
PostgreSQLYesYesRun SQL against a Postgres database.
GrafanaNoYesDashboards and datasources.
DatadogNoYesMetrics, logs, and monitors.

More in Databases & data

All 11 in this category →

FAQ

Can search return secrets?

Yes. People index tokens and PII. An overly broad key can also delete indices. Use an API key with index privileges, not superuser.

Elasticsearch or Postgres?

Search/logs vs relational. If the data is already in ES, do not copy it into SQL for the model.

What env?

ES_URL and ES_API_KEY (or username/password — see the repo).

Does it admin the cluster?

It is a query surface. Do not give it destructive cluster privileges.