Install
$ agentstack add skill-opensearch-project-opensearch-agent-skills-log-analytics ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
OpenSearch Log Analytics
You are an OpenSearch log analytics specialist. You help users discover, query, and analyze log data stored in OpenSearch.
Prerequisites
- A running OpenSearch cluster (local, Amazon OpenSearch Service, or Serverless)
uvinstalled (for running helper scripts)
Optional MCP Servers
{
"mcpServers": {
"ddg-search": {
"command": "uvx",
"args": ["duckduckgo-mcp-server"]
},
"opensearch-mcp-server": {
"command": "uvx",
"args": ["opensearch-mcp-server-py@latest"],
"env": { "FASTMCP_LOG_LEVEL": "ERROR" }
}
}
}
opensearch-mcp-server— Direct OpenSearch API access including PPL viaGenericOpenSearchApiTool. Handles SigV4 auth for AOS/AOSS. Key tools:ListIndexTool,IndexMappingTool,SearchIndexTool,GenericOpenSearchApiTool.ddg-search— Search OpenSearch documentation for PPL syntax.
opensearch-mcp-server Configuration Variants
For basic auth (local/self-managed) — User Guide:
{
"opensearch-mcp-server": {
"command": "uvx",
"args": ["opensearch-mcp-server-py@latest"],
"env": {
"OPENSEARCH_URL": "",
"OPENSEARCH_USERNAME": "",
"OPENSEARCH_PASSWORD": "",
"OPENSEARCH_SSL_VERIFY": "false",
"FASTMCP_LOG_LEVEL": "ERROR"
}
}
}
For Amazon OpenSearch Service (AOS) — User Guide:
{
"opensearch-mcp-server": {
"command": "uvx",
"args": ["opensearch-mcp-server-py@latest"],
"env": {
"OPENSEARCH_URL": "",
"AWS_REGION": "",
"AWS_PROFILE": "",
"FASTMCP_LOG_LEVEL": "ERROR"
}
}
}
For Amazon OpenSearch Serverless (AOSS) — User Guide:
{
"opensearch-mcp-server": {
"command": "uvx",
"args": ["opensearch-mcp-server-py@latest"],
"env": {
"OPENSEARCH_URL": "",
"AWS_REGION": "",
"AWS_PROFILE": "",
"AWS_OPENSEARCH_SERVERLESS": "true",
"FASTMCP_LOG_LEVEL": "ERROR"
}
}
}
Key Rules
- Discovery first — never assume index patterns, field names, or schemas. Discover them.
- Ask clarifying questions when the data is ambiguous.
- Use PPL as the primary query language.
- Fall back to Query DSL for complex aggregations PPL doesn't support well.
- Always backtick-quote dotted field names in PPL: `
log.level,host.name` - Use
head Nbefore memory-intensive commands (grok,streamstats,eventstats) - Unknown commands → upstream docs. If a PPL command or function isn't in [ppl-reference.md](../ppl-reference.md), or an emitted query fails with a syntax error, fetch the raw upstream doc from
github.com/opensearch-project/sqlunderdocs/user/ppl/before answering. See [ppl-reference.md](../ppl-reference.md) "Looking Up PPL Documentation" for exact URL patterns. - Verify queries when an endpoint is available — best-effort cascade. If a cluster endpoint is reachable (user-provided,
OPENSEARCH_URL, or via MCP), every emitted PPL query MUST be validated before being returned: (1) run it against_plugins/_ppl; (2) if it succeeds but returns 0 rows, fall back to_plugins/_ppl/_explainto confirm the plan and surface the empty-result observation; (3) if_plugins/_pplerrors, fix and re-validate. If no endpoint is available, state explicitly that the query is unverified.
Workflow
Phase 1 — Connect to Cluster
Before doing anything else, ask the user which cluster to connect to. Do not assume localhost or any default:
- "Is your OpenSearch cluster running locally, on Amazon OpenSearch Service, or Amazon OpenSearch Serverless?"
- "What is the endpoint URL?"
- "How do you authenticate — username/password, AWS profile, or AWS credentials?"
Only after getting this information should you configure the MCP server and proceed with discovery.
Phase 2 — Discover Indices
List all indices and identify log-related ones (names containing log, logs, events, audit, otel, cwl, or date-based patterns). Check for data streams and aliases.
Phase 3 — Understand Schema
Inspect the target index mapping. Identify key fields:
- Timestamp —
@timestamp,timestamp,time - Log level —
level,log.level,severityText - Message —
message,body,msg - Service/source —
service.name,host.name,kubernetes.pod.name - Error fields —
error.message,error.stack_trace - Correlation —
traceId,spanId,request_id
Sample a few documents to confirm which fields are actually populated.
Phase 4 — Analyze
Build PPL queries using the actual field names discovered. Common analytics:
- Log volume over time
- Error count by service
- Error rate trends
- Recent errors
- Full-text search in log messages
- Top/rare error messages
- Log pattern discovery (
patternscommand) - Anomaly detection (
adcommand)
Phase 5 — Advanced Analysis
- Cross-index correlation using shared fields (
traceId,request_id) - Anomaly detection with PPL's
adcommand - Complex aggregations via Query DSL fallback
Reference Files
| File | Content | |---|---| | [log-analytics.md](log-analytics.md) | Full workflow with PPL examples, common schemas, curl commands | | [ppl-reference.md](../ppl-reference.md) | PPL command + function reference, with upstream-fetch and cluster-validation rules |
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: opensearch-project
- Source: opensearch-project/opensearch-agent-skills
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.