Closed-loop incident response: connect AWS DevOps Agent to OpenSearch
DevOps & Developer Productivity Blog
This article demonstrates how to connect AWS DevOps Agent to Amazon OpenSearch Service using the Model Context Protocol (MCP) to automate incident investigation and root cause analysis from alert detection.
- AWS DevOps Agent queries OpenSearch logs and traces automatically when alerts fire, eliminating manual investigation delays
- Three hosting paths for the MCP server: self-managed ECS with NLB, Amazon Bedrock AgentCore, or built-in OpenSearch 3.3+ endpoint
- Configure fine-grained access control (FGAC) role mapping to scope agent access to observability indices only
- Lambda webhook forwarder transforms OpenSearch alerts to DevOps Agent Event Channel with HMAC-SHA256 signing
- Agent correlates logs, traces, CloudTrail, and CloudWatch to deliver automated root cause analysis
- Closed-loop architecture eliminates manual investigation steps that can take minutes to hours for cascading failures
By connecting OpenSearch alerting to AWS DevOps Agent through MCP, organizations can automate incident response and reduce mean time to resolution for observability data already stored in their domain.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2026
2026
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.