AI-powered threat hunting and incident response MCP server for Elasticsearch/OpenSearch
io.github.thomasxm/crowdsentinel-mcp-server
https://github.com/thomasxm/CrowdSentinels-AI-MCP
STDIO
No auth required
Hosted endpoint — paste into any MCP client.
Configuration this server reads at startup.
Comma-separated Elasticsearch hosts. Supports HTTP/HTTPS, local/remote/cloud (e.g., http://localhost:9200, https://es.prod.example.com:9200)
Elastic Cloud deployment ID (alternative to ELASTICSEARCH_HOSTS for cloud deployments)
API key for authentication (recommended for production and Elastic Cloud)
Username for basic authentication (alternative to API key)
Password for basic authentication (used with ELASTICSEARCH_USERNAME)
Bearer/service token for authentication (alternative to API key)
TLS certificate verification: true (verify CA — production), false (skip — dev/test), or /path/to/ca.crt (custom CA)
Request timeout in seconds (e.g., 60 or 10.5)
Where to find authoritative docs and source for crowdsentinel-mcp-server.
Open MCP Agent Studio and connect this server to Claude, GPT, Gemini, DeepSeek and more — no install required.
Open Agent Studio