The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Kibana MCP listing page.
MCP server for Kibana / Elasticsearch — log search, aggregations, index discovery, and dashboard browsing via Claude and any MCP-compatible agent.
Existing integrations require a running Kibana instance with browser-level credentials and often wrap the Kibana UI rather than the stable REST APIs. This server:
outputSchema) and markdown text so it works with any MCP clientreadOnlyHint: true, no data is modified| Tool | API | Description |
|---|---|---|
kibana_list_indices | GET ES/_cat/indices | Discover available indices with health, docs, size |
kibana_search_logs | POST ES/{index}/_search | Full-text log search with time range, sort, size |
kibana_aggregate_logs | POST ES/{index}/_search | Terms grouping with count/avg/sum/min/max metric |
kibana_list_dashboards | GET Kibana/api/saved_objects/_find | List saved dashboards with search + pagination |
kibana_get_dashboard | GET Kibana/api/saved_objects/dashboard/{id} | Fetch one dashboard with panel breakdown |
Or run directly with uvx:
| Variable | Required | Description |
|---|---|---|
KIBANA_URL | Yes | Kibana base URL (e.g. https://kibana.example.com) |
ELASTICSEARCH_URL | No | Direct ES endpoint. If unset, ES requests go through Kibana Console proxy |
KIBANA_API_KEY | No | ES API key (ApiKey base64(id:api_key) format). Recommended for agents |
KIBANA_USERNAME | No | HTTP Basic auth username (used if API key not set) |
KIBANA_PASSWORD | No | HTTP Basic auth password |
KIBANA_SSL_VERIFY | No | true (default) or false for self-signed certificates |
Auth priority: ApiKey > Basic > anonymous.
Copy .env.example to .env and fill in your values.
Or with direct ES access for better performance:
→ kibana_search_logs(index="logs-*", query="level:ERROR AND service:api", size=50, time_from="2026-04-18T09:00:00Z")
→ kibana_search_logs(index="nginx-*", query="status:500", sort_order="asc", size=100)
→ kibana_aggregate_logs(index="logs-*", group_by="level", time_from="2026-04-18T09:00:00Z")
→ kibana_aggregate_logs(index="logs-*", group_by="service.keyword", metric="avg", metric_field="response_time_ms")
→ kibana_list_indices()
→ kibana_list_indices(pattern="filebeat-*")
→ kibana_list_dashboards(search="infrastructure")
→ kibana_get_dashboard(dashboard_id="<id from list_dashboards>")
kibana_search_logs): typically 50-500ms with direct ES URL; add 100-200ms when routing through Kibana Console proxykibana_aggregate_logs): size:0 queries — no hits transferred, usually 10-100ms_cat/indices call, O(index_count) response, typically <100msELASTICSEARCH_URL directly if your agent does frequent log searches — eliminates the proxy overheadMIT — see LICENSE.