
Elasticsearch
BetaSearch, ES|QL, and index discovery over your Elasticsearch data via Elastic Agent Builder.
How it works
Every agent request passes through Ferentin policy before it reaches Elasticsearch.- AI agentAsks for something
- Ferentin policies
- API key scoped privileges
- Index level authorization
- Deployment scoped endpoint
- Elasticsearch MCP serverAuthorized connection
- Governed resultMasked, logged, returned
What you can do with Elasticsearch
- Index search
- Esql generation
- Index discovery
- Custom agent tools
Overview
Elasticsearch is a distributed search and analytics engine, and the foundation of the Elastic Stack for search, observability, and security workloads. Agent Builder is Elastic's framework for exposing indexed data to AI agents as governed tools.
Ferentin integration
Ferentin connects to the Agent Builder MCP endpoint on your own Kibana deployment using an Elasticsearch API key sent with the ApiKey scheme. Because the endpoint is deployment-scoped, the server URL is supplied at install time. Elasticsearch role and index privileges on the key remain the authorization boundary.
Frequently asked about Elasticsearch
- What can AI agents do with Elasticsearch through Ferentin?
- Through Ferentin, agents can use Elasticsearch for index search, esql generation, index discovery and custom agent tools. Every call is checked against your Ferentin policies first.
- How does Ferentin secure Elasticsearch access?
- Requests through the Elasticsearch integration are covered by API key scoped privileges, index level authorization and deployment scoped endpoint. These controls are applied by Ferentin, not by Elasticsearch, so they hold across every connected agent.
- How do I connect Elasticsearch to Ferentin?
- Open the Ferentin admin console, add Elasticsearch as a new connection and authenticate with API key. You then choose which permissions and which tools your agents may use, and the connection goes live for everyone covered by your policies.
- Is the Elasticsearch integration generally available?
- The Elasticsearch integration is currently beta on Ferentin.
Related integrations
3
Datadog
Observability platform for logs, metrics, traces, monitors, incidents, security signals, and synthetic tests.

Sentry
Error tracking and performance monitoring with AI-powered root cause analysis, issue search, replays, profiles, and event analytics.

Databricks
Query the Databricks lakehouse — SQL warehouses, Unity Catalog functions, Genie spaces, and vector search.