{"_id":"@craftpipe/loglens-mcp","name":"@craftpipe/loglens-mcp","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@craftpipe/loglens-mcp","version":"1.0.0","description":"Log analysis MCP server — query, search, and analyze logs across Datadog, Grafana Loki, AWS CloudWatch, and Logtail for AI coding agents","type":"module","main":"dist/index.js","bin":{"loglens-mcp":"dist/index.js"},"scripts":{"build":"tsc","dev":"tsx src/index.ts","test":"vitest run","test:watch":"vitest","typecheck":"tsc --noEmit","clean":"rm -rf dist"},"dependencies":{"@modelcontextprotocol/sdk":"^1.12.0","better-sqlite3":"^12.9.0","zod":"^4.3.6"},"devDependencies":{"@types/better-sqlite3":"^7.6.0","@types/node":"^25.6.0","tsx":"^4.7.2","typescript":"^6.0.2","vitest":"^4.1.4"},"engines":{"node":">=18.0.0"},"keywords":["mcp","developer-tools","craftpipe","ai-tools","logging","datadog","grafana","cloudwatch","observability","log-analysis"],"license":"MIT","gitHead":"3b78d69cb453b94811fd487bd6f0cf420c4c814f","_id":"@craftpipe/loglens-mcp@1.0.0","_nodeVersion":"20.19.6","_npmVersion":"11.8.0","dist":{"integrity":"sha512-Hirnf+btdQRLA+WZlbhTZJXJafQhZ2W0Rv8DU1Yxgh7bLL2AWIEi5FTqCp4N5V+cO5vTKazgWZt/dPKFyJDD3w==","shasum":"f8e8c00427603c921cf19c2b327324b29d18a75d","tarball":"https://registry.npmjs.org/@craftpipe/loglens-mcp/-/loglens-mcp-1.0.0.tgz","fileCount":70,"unpackedSize":334089,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDdHWXRvATJgn7iVzjfFDl1xyfCGGYMejmYqg/o1M2z0AIhAOA8tT6hAUNLeY4e1bl36Rb+lJW+bjz8BTjGKrJXq+vj"}]},"_npmUser":{"name":"craftpipe","email":"info@heijnesdigital.com"},"directories":{},"maintainers":[{"name":"craftpipe","email":"info@heijnesdigital.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/loglens-mcp_1.0.0_1776261725386_0.1937818035257497"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-15T14:02:05.283Z","1.0.0":"2026-04-15T14:02:05.517Z","modified":"2026-04-15T14:02:05.782Z"},"maintainers":[{"name":"craftpipe","email":"info@heijnesdigital.com"}],"description":"Log analysis MCP server — query, search, and analyze logs across Datadog, Grafana Loki, AWS CloudWatch, and Logtail for AI coding agents","keywords":["mcp","developer-tools","craftpipe","ai-tools","logging","datadog","grafana","cloudwatch","observability","log-analysis"],"license":"MIT","readme":"<div align=\"center\">\r\n\r\n<img src=\".github/assets/banner.svg\" alt=\"LogLens MCP\" width=\"800\">\r\n\r\n<br/>\r\n<br/>\r\n\r\n[![npm version](https://img.shields.io/npm/v/loglens-mcp?style=flat-square&color=22c55e&label=npm)](https://npmjs.com/package/loglens-mcp)\r\n[![License: MIT](https://img.shields.io/badge/License-MIT-22c55e.svg?style=flat-square)](LICENSE)\r\n[![Tests](https://img.shields.io/badge/tests-280%20passing-brightgreen?style=flat-square)]()\r\n[![TypeScript](https://img.shields.io/badge/TypeScript-5.4+-3178c6?style=flat-square&logo=typescript&logoColor=white)]()\r\n[![Node](https://img.shields.io/badge/Node.js-20+-339933?style=flat-square&logo=node.js&logoColor=white)]()\r\n[![MCP](https://img.shields.io/badge/MCP-compatible-22c55e?style=flat-square)]()\r\n\r\n**Ask your logs anything.**\r\n<br/>\r\nQuery, search, and analyze logs across Logtail, Grafana Loki, Datadog, AWS CloudWatch, New Relic, and Elasticsearch — directly from Claude, Cursor, or any MCP-compatible AI agent.\r\n\r\n[Quick Start](#quick-start) · [Tools](#tools) · [Pro Features](#pro-features) · [Providers](#supported-providers)\r\n\r\n</div>\r\n\r\n```mermaid\r\ngraph LR\r\n    A[\"AI Agent\"] -->|MCP Protocol| B[\"LogLens MCP\"]\r\n    B --> C[\"Logtail / Better Stack\"]\r\n    B --> D[\"Grafana Loki\"]\r\n    B --> E[\"Datadog\"]\r\n    B --> F[\"AWS CloudWatch\"]\r\n    B --> G[\"New Relic\"]\r\n    B --> H[\"Elasticsearch\"]\r\n    style B fill:#0d1117,stroke:#22c55e,stroke-width:2px,color:#22c55e\r\n    style A fill:#1f2937,stroke:#22c55e,color:#f0f6fc\r\n```\r\n\r\n---\r\n\r\n## Quick Start\r\n\r\n```bash\r\nnpx loglens-mcp\r\n```\r\n\r\n### Claude Desktop\r\n\r\nAdd to `claude_desktop_config.json`:\r\n\r\n```json\r\n{\r\n  \"mcpServers\": {\r\n    \"loglens\": {\r\n      \"command\": \"npx\",\r\n      \"args\": [\"-y\", \"loglens-mcp\"],\r\n      \"env\": {\r\n        \"LOGTAIL_TOKEN\": \"your-source-token\"\r\n      }\r\n    }\r\n  }\r\n}\r\n```\r\n\r\n### Cursor / Windsurf\r\n\r\nSame JSON format in your MCP settings.\r\n\r\n---\r\n\r\n## Tools\r\n\r\n### Free (7 tools)\r\n\r\n| Tool | Description |\r\n|:-----|:------------|\r\n| **`query_logs`** | Search logs by service, level, time range, and free-text pattern. Paginated results with metadata |\r\n| **`error_summary`** | Group and rank unique errors — deduplicated by pattern, with count, affected services, and sample trace |\r\n| **`log_stats`** | Aggregate statistics: count by level, top 10 errors, volume by hour, busiest services |\r\n| **`tail_logs`** | Most recent N log lines for a service, with optional level filter |\r\n| **`search_patterns`** | Regex pattern search across logs — find request IDs, user IDs, transaction refs |\r\n| **`log_context`** | Surrounding context for a specific log entry — N lines before and after, across services |\r\n| **`service_map`** | All services with log volume, error rate, last activity, and health status |\r\n\r\n### Pro (6 tools)\r\n\r\n| Tool | Description |\r\n|:-----|:------------|\r\n| **`anomaly_detection`** | Statistical anomaly detection — volume spikes, error spikes, new error types, service silence |\r\n| **`trace_correlation`** | Follow a request across services via trace ID — reconstruct path with timing per hop |\r\n| **`log_diff`** | Compare log patterns between two time windows — new errors, disappeared warnings, volume changes |\r\n| **`alert_rules`** | List and validate alert rules from your provider — dry-run against a time range |\r\n| **`retention_report`** | Storage volume, estimated cost, retention policies, oldest logs per index |\r\n| **`export_report`** | Structured incident report combining queries, errors, and anomalies — JSON or markdown |\r\n\r\n---\r\n\r\n## Free vs Pro\r\n\r\n| Feature | Free | Pro |\r\n|:--------|:----:|:---:|\r\n| Log querying & tailing | ✓ | ✓ |\r\n| Error grouping & ranking | ✓ | ✓ |\r\n| Aggregate statistics | ✓ | ✓ |\r\n| Regex pattern search | ✓ | ✓ |\r\n| Log context (before/after) | ✓ | ✓ |\r\n| Service map | ✓ | ✓ |\r\n| Anomaly detection | | ✓ |\r\n| Trace correlation | | ✓ |\r\n| Log diff (pre/post deploy) | | ✓ |\r\n| Alert rule validation | | ✓ |\r\n| Retention & cost report | | ✓ |\r\n| Incident export | | ✓ |\r\n\r\n**Get Pro:** Set `PRO_LICENSE` to unlock premium tools.\r\n→ [craftpipe.dev/pricing](https://craftpipe.dev/pricing)\r\n\r\n---\r\n\r\n## Supported Providers\r\n\r\n<table>\r\n<tr>\r\n<th>Feature</th>\r\n<th align=\"center\">Logtail</th>\r\n<th align=\"center\">Grafana Loki</th>\r\n<th align=\"center\">Datadog</th>\r\n<th align=\"center\">CloudWatch</th>\r\n<th align=\"center\">New Relic</th>\r\n<th align=\"center\">Elasticsearch</th>\r\n</tr>\r\n<tr><td>Log querying</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td></tr>\r\n<tr><td>Error summary</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td></tr>\r\n<tr><td>Statistics</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td></tr>\r\n<tr><td>Trace correlation</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td><td align=\"center\">&#9989;</td></tr>\r\n<tr><td>Auth method</td><td align=\"center\">Bearer token</td><td align=\"center\">Optional token</td><td align=\"center\">API + App key</td><td align=\"center\">AWS credentials</td><td align=\"center\">Api-Key header</td><td align=\"center\">API key / Basic</td></tr>\r\n<tr><td>Rate limits</td><td align=\"center\">Generous</td><td align=\"center\">None (self-hosted)</td><td align=\"center\">300 req/hr</td><td align=\"center\">Varies by tier</td><td align=\"center\">Varies by tier</td><td align=\"center\">None (self-hosted)</td></tr>\r\n</table>\r\n\r\n> **Note:** CloudWatch Logs Insights costs $0.005/GB scanned. LogLens includes this warning in responses.\r\n\r\n### Credentials\r\n\r\n```bash\r\n# Logtail / Better Stack\r\nexport LOGTAIL_TOKEN=...           # Source token from betterstack.com\r\n\r\n# Grafana Loki\r\nexport LOKI_URL=http://loki:3100   # Or Grafana Cloud URL\r\nexport LOKI_TOKEN=...              # Optional for Grafana Cloud\r\n\r\n# Datadog\r\nexport DD_API_KEY=...\r\nexport DD_APP_KEY=...\r\nexport DD_SITE=datadoghq.com       # Optional, default: datadoghq.com\r\n\r\n# AWS CloudWatch\r\nexport AWS_ACCESS_KEY_ID=...\r\nexport AWS_SECRET_ACCESS_KEY=...\r\nexport AWS_REGION=us-east-1\r\n\r\n# New Relic\r\nexport NEWRELIC_API_KEY=...\r\nexport NEWRELIC_ACCOUNT_ID=...\r\n\r\n# Elasticsearch\r\nexport ELASTICSEARCH_URL=http://localhost:9200\r\nexport ELASTICSEARCH_API_KEY=...       # Or use basic auth:\r\nexport ELASTICSEARCH_USER=...\r\nexport ELASTICSEARCH_PASSWORD=...\r\nexport ELASTICSEARCH_INDEX=logs-*      # Optional, default: logs-*\r\n\r\n# Pro license\r\nexport PRO_LICENSE=CPK-...         # From craftpipe.dev/pricing\r\n```\r\n\r\n---\r\n\r\n## Security\r\n\r\n- **Read-only** — LogLens only queries logs, never writes or deletes\r\n- **Credentials** — read from environment variables, never stored\r\n- **Audit trail** — every tool call logged to `~/.loglens/audit.db` (SQLite, 90-day retention)\r\n\r\n---\r\n\r\n## License\r\n\r\nMIT — see [LICENSE](LICENSE)\r\n\r\n---\r\n\r\n*Built with AI by [Craftpipe](https://github.com/Craftpipe)*\r\n","readmeFilename":"README.md","_rev":"1-6d4d2be4c503174b98066dcff3b8f4eb"}