Elasticsearch
Elasticsearch is where many teams keep logs and searchable operational data. Antimetal queries indices and cluster state to find the documents behind a failure.
What Antimetal does with Elasticsearch
- Search indices for the events behind an alert
- Inspect cluster and index health
- Run aggregations to quantify what changed
- Explore log data stored outside your APM tool
Connecting Elasticsearch
Go to Integrations in the Antimetal dashboard and find Elasticsearch.
Click Connect and follow the prompt. Depending on the tool this is either an OAuth handoff or a read-only credential you generate in Elasticsearch and paste into Antimetal.
Once Elasticsearch shows as connected, Antimetal begins pulling from it during investigations. No further configuration is required.
Permissions and access
Antimetal connects over MCP with read-only access and performs no write operations. The exact scopes depend on the credential you issue in the vendor tool — grant read access only.
All tenant data is processed in isolated environments. See security and compliance for details.
Need help?
Contact us via Slack or at support@antimetal.com.
