# Triagic + OpenSearch: ticket investigations over your logs, errors and metrics, read-only

> OpenSearch in Triagic: Search application logs and indices. Read-only, with a credential you configure.

Source: https://triagic.com/integrations/opensearch

## What you can ask

- Check OpenSearch for errors from the checkout service in the last hour and group them by message
- In OpenSearch, did latency for the import worker change after the 16:02 deploy?
- Find every OpenSearch event that mentions request id 7f3a-…-c2 and put them in order
- Is the alert in OpenSearch for the export queue still firing, and since when?
- What did OpenSearch record for the pod that restarted at 11:31?

## What the agent can do

- `ListIndexTool`
- `IndexMappingTool`
- `SearchIndexTool`
- `GetShardsTool`
- `ClusterHealthTool`
- `CountTool`
- `MsearchTool`
- `ExplainTool`

## Connect in three steps

1. **Mint a read-only credential in OpenSearch.** Create a dedicated user or token that can only read. OPENSEARCH_SETTINGS_ALLOW_WRITE=false plus an allowlist of the eight GET-only tools; the generic API passthrough is excluded.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then OpenSearch. Fill in: Cluster URL (required); Username (required); Password (required); Region (required): The domain's own region. SigV4 signs the region into the request, so a wrong one is rejected as a bad signature rather than as a wrong address.; IAM role ARN (required): Assumed with STS before every connection. The credentials above (or the machine's own) must be allowed to sts:AssumeRole it.
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts OpenSearch locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/observability#opensearch

## Read-only, by construction

OPENSEARCH_SETTINGS_ALLOW_WRITE=false plus an allowlist of the eight GET-only tools; the generic API passthrough is excluded.

## FAQ

**Can Triagic change anything in OpenSearch?**
No. OPENSEARCH_SETTINGS_ALLOW_WRITE=false plus an allowlist of the eight GET-only tools; the generic API passthrough is excluded. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect OpenSearch?**
Cluster URL, Username, Password, Region, IAM role ARN. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does OpenSearch cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [Sentry](https://triagic.com/integrations/sentry)
- [Prometheus](https://triagic.com/integrations/prometheus)
- [Elasticsearch](https://triagic.com/integrations/elasticsearch)
- [Datadog](https://triagic.com/integrations/datadog)
