TL;DR: The cluster is fine; the index name is wrong. List the indices that actually exist and fix the name in your query. Typos and date-suffixed index patterns are the usual culprits.

```text
{"error":{"root_cause":[{"type":"index_not_found_exception","reason":"no such index [logs-2026.10.02]"}]}}
```

## Fix it

1. List the indices that exist. Use the MCP server's list-indices tool, or curl:

```bash
curl -u elastic:YOUR_PASSWORD "your-cluster/_cat/indices?v"
```

   Expected: a table of index names. Compare against the name in your query.

2. Fix the name. Common mistakes:
   - Date math: `logs-2026.10.02` vs `logs-2026-10-02` (dots vs dashes).
   - Aliases vs concrete names: query the alias, not the backing index, or vice versa.
   - Case: index names are lowercase by convention; uppercase fails.

3. If the index should exist but does not, create it or check you are pointed at the right cluster (dev vs prod URLs get mixed up).

   Expected: the search returns hits instead of the exception.

## When to use this

- Auth and connection work, but searches fail with `index_not_found_exception`.
- The index name contains a date or was typed by hand.

## When NOT to use this

- The error is 401 or 403. That is auth, not the index name.
- All indices are missing. Then you are pointed at the wrong cluster.

## Compatibility

- elastic/mcp-server-elasticsearch, any Elasticsearch client.
- Elasticsearch 7.x, 8.x.

## Why it happens

Elasticsearch treats index names as exact identifiers with no fuzzy matching. MCP agents often construct index names from dates or guess them from context, and a single wrong character produces this error instead of results. It is the search equivalent of a typo in a table name.

## Edge cases

- Wildcards (`logs-*`) avoid the exact-name problem but can hit too many indices. Prefer them for exploration, exact names for production queries.
- Data streams have a backing-index naming scheme. Query the data stream name, not the `.ds-` backing index.
- If the index was just created, allow a moment for cluster state to propagate, though this is rarely the issue.