Home icon

Closed-loop incident response: connect AWS DevOps Agent to OpenSearch

DevOps & Developer Productivity Blog



This article demonstrates how to connect AWS DevOps Agent to Amazon OpenSearch Service using the Model Context Protocol (MCP) to automate incident investigation and root cause analysis from alert detection.

  • AWS DevOps Agent queries OpenSearch logs and traces automatically when alerts fire, eliminating manual investigation delays
  • Three hosting paths for the MCP server: self-managed ECS with NLB, Amazon Bedrock AgentCore, or built-in OpenSearch 3.3+ endpoint
  • Configure fine-grained access control (FGAC) role mapping to scope agent access to observability indices only
  • Lambda webhook forwarder transforms OpenSearch alerts to DevOps Agent Event Channel with HMAC-SHA256 signing
  • Agent correlates logs, traces, CloudTrail, and CloudWatch to deliver automated root cause analysis
  • Closed-loop architecture eliminates manual investigation steps that can take minutes to hours for cascading failures

By connecting OpenSearch alerting to AWS DevOps Agent through MCP, organizations can automate incident response and reduce mean time to resolution for observability data already stored in their domain.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Sep 28
2026
How Property Finder automated incident management with AWS DevOps Agent
Sep 11
2026
AWS DevOps Agent adds bidirectional Slack communication for investigations
Apr 21
2026
Automated network incident response with AWS DevOps Agent
Jul 15
2026
Amazon OpenSearch Service now supports the Agent Toolkit for AWS with a curated skill

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.