Triagic + OpenSearch: ticket investigations over your logs, errors and metrics, read-only
Search application logs and indices. Triagic connects to OpenSearch from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of OpenSearch.
What you can ask
- Check OpenSearch for errors from the checkout service in the last hour and group them by message
- In OpenSearch, did latency for the import worker change after the 16:02 deploy?
- Find every OpenSearch event that mentions request id 7f3a-…-c2 and put them in order
- Is the alert in OpenSearch for the export queue still firing, and since when?
- What did OpenSearch record for the pod that restarted at 11:31?
What the agent can do
These are the 8 tools Triagic exposes from the OpenSearch MCP server. Anything else the server lists is dropped at connect time.
- ListIndexTool
- IndexMappingTool
- SearchIndexTool
- GetShardsTool
- ClusterHealthTool
- CountTool
- MsearchTool
- ExplainTool
Connect in three steps
- 1
Mint a read-only credential in OpenSearch
Create a dedicated user or token that can only read. OPENSEARCH_SETTINGS_ALLOW_WRITE=false plus an allowlist of the eight GET-only tools; the generic API passthrough is excluded.
- 2
Add it in the Triagic portal
Integrations, then Add shared data source, then OpenSearch.
- Cluster URL
- Username
- Password
- Region: The domain's own region. SigV4 signs the region into the request, so a wrong one is rejected as a bad signature rather than as a wrong address.
- IAM role ARN: Assumed with STS before every connection. The credentials above (or the machine's own) must be allowed to sts:AssumeRole it.
- 3
Let a desktop pick it up
Saving validates the shape of what you typed. The first desktop app to sync starts OpenSearch locally and reports running or degraded with the error text.
Field-by-field setup, TLS options and the error table: OpenSearch in the docs.
Read-only, by construction
OPENSEARCH_SETTINGS_ALLOW_WRITE=false plus an allowlist of the eight GET-only tools; the generic API passthrough is excluded.
FAQ
- Can Triagic change anything in OpenSearch?
- No. OPENSEARCH_SETTINGS_ALLOW_WRITE=false plus an allowlist of the eight GET-only tools; the generic API passthrough is excluded. Give it a read-only credential as well, so the guarantee does not rest on one layer.
- What do I need to connect OpenSearch?
- Cluster URL, Username, Password, Region, IAM role ARN. The desktop app on a member's machine starts the connection; the portal never holds a live process.
- Does OpenSearch cost extra?
- No. Every connector is included in the seat price. Start a 14-day trial without a card.
Related integrations
- SentryPull issues, events, and stack traces. Works with Sentry-compatible backends (GlitchTip).
- PrometheusQuery metrics and alerting rules.
- ElasticsearchSearch application logs and documents, inspect mappings and shards. The bundled tools are read-only.
- DatadogRead monitors, logs, metrics, and incidents. Write tools stay disabled.
Try it on your own OpenSearch
No card. Install the desktop app, connect OpenSearch read-only, and triage a real ticket this afternoon.