Grafana Cloud MCP(クラウドベースの監視・分析ツール用プラグイン)サーバーに接続し、自然な言葉での質問や監視分析(システムの稼働状況を調べること)を効果的に行うための機能です。セットアップ、OAuth認可(アクセス権限の付与)、ツールの種類、読み書きアクセス権限の範囲、コンテキストウィンドウ(AIが扱える情報量)管理のベストプラクティスをカバーしています。 **次のような場合に使用:** - Grafana Cloud MCPのセットアップを行いたい - Grafana Assistant(Grafana付属の質問機能)に質問を送りたい - メトリクス(数値データ)、ログ、トレース(処理の流れ)、プロファイル(性能データ)、ダッシュボード(情報表示画面)、アラート、インシデント(障害事象)を調査したい - どのツールを使うべきかについて相談したい - アクセス権限の範囲を理解したい
Connect to and use the Grafana Cloud MCP server effectively, including natural-language Grafana Assistant questions and observability investigations. Covers setup, OAuth authorization, tool categories, read/write access scopes, and best practices for context window management. Use when the user wants to set up Grafana Cloud MCP, ask Grafana Assistant a question, investigate metrics, logs, traces, profiles, dashboards, alerts, or incidents, needs guidance on which tool to use, or wants to understand access scopes.
Grafana Cloud の 60 以上のツールを提供するホスト型 MCP サーバーで、ストリーム式の HTTP 通信と OAuth 2.1 認可に対応しています。
grafana-assistant-app.cloud-mcp:access 権限が必要です(Editor ロール以上は既定で権限を持ちます)Cloud MCP サーバーは https://mcp.grafana.com/mcp 経由でストリーム式 HTTP 通信で接続します。ローカルのインストールや環境変数は不要です。
認可時に、付与する権限を選択できます:
組織の管理者は既定で書き込みアクセス権を付与できます。同意画面で書き込みアクセスが無効になっている場合、ユーザーは Assistant Admin ロールが必要です。
search_dashboards — クエリ文字列でダッシュボードを検索search_folders — クエリ文字列でフォルダを検索generate_deeplink — ダッシュボード、パネル、クエリ機能のディープリンク URL を生成get_dashboard_by_uid — UID によってダッシュボードの完全な JSON を取得get_dashboard_summary — 完全な JSON を含まない簡潔な概要を取得(推奨)get_dashboard_property — JSONPath で特定部分を抽出get_dashboard_panel_queries — パネルクエリをテンプレート変数の置換付きで取得update_dashboard — ダッシュボードを作成または更新(書き込み)create_folder — Grafana フォルダを作成(書き込み)list_datasources — 設定済みのすべてのデータソースを表示(型でのフィルタリング可)get_datasource — UID または名前で詳細情報を取得list_prometheus_metric_names — 正規表現フィルターで利用可能なメトリクスを検出list_prometheus_metric_metadata — 現在スクレイプ中のメトリクスのメタデータを表示list_prometheus_label_names — ラベル名を表示(系列セレクター指定可)list_prometheus_label_values — 特定ラベルの値を取得query_prometheus — PromQL のインスタント照会または範囲照会を実行query_prometheus_histogram — ヒストグラムのパーセンタイル(分布の百分位数)を照会list_loki_label_names — ログの利用可能なラベル名を表示list_loki_label_values — 特定ラベルのユニークな値を取得query_loki_logs — LogQL クエリでログエントリまたはメトリック値を取得query_loki_stats — ログストリームの統計情報を取得query_loki_patterns — ログ内の共通パターンを検出・分析Tempo データソースを持つ場合、Cloud MCP サーバーは TraceQL クエリと属性検出を含む Tempo データソースのツールをプロキシします。
list_pyroscope_label_names — プロファイルの利用可能なラベル名を表示list_pyroscope_label_values — 特定ラベルの値を表示list_pyroscope_profile_types — 利用可能なプロファイルタイプを表示query_pyroscope — Pyroscope からプロファイルまたはメトリクスを照会list_clickhouse_tables — メタデータ付きで利用可能なテーブルを表示describe_clickhouse_table — テーブルのカラムスキーマを取得query_clickhouse — ClickHouse データソースに対して SQL クエリを実行list_cloudwatch_namespaces — 利用可能な AWS ネームスペースを表示list_cloudwatch_metrics — ネームスペースのメトリクスを表示list_cloudwatch_dimensions — メトリクスのディメンション(属性)を表示query_cloudwatch — AWS CloudWatch メトリクスを照会query_elasticsearch — Lucene または Query DSL での検索を実行alerting_manage_rules — アラートルールの表示、フィルタリング、作成、更新(読み取り / 書き込み)alerting_manage_routing — ルーティング設定、通知ポリシー、連絡先を表示(読み取り)get_annotations — ダッシュボード UID、時間範囲、タグでフィルタリングしたアノテーション(注釈)を取得get_annotation_tags — アノテーションのタグを取得(フィルタリング可)create_annotation — 新しいアノテーションを作成(書き込み)update_annotation — 既存アノテーションを更新(書き込み)list_incidents — インシデント(事象)を表示(ステータスでのフィルタリング可)get_incident — ID によってインシデントの詳細を取得create_incident — 新しいインシデントを作成(書き込み)add_activity_to_incident — インシデントのタイムラインにメモを追加(書き込み)list_oncall_schedules — OnCall スケジュールを表示(チームでのフィルタリング可)get_oncall_shift — シフト(当番)の詳細情報を取得get_current_oncall_users — スケジュールで現在当番中のユーザーを取得list_oncall_teams — OnCall チームを表示list_oncall_users — OnCall ユーザーを表示(フィルタリング可)list_alert_groups — アラートグループをフィルタリング付きで表示get_alert_group — ID で特定のアラートグループを取得list_sift_investigations — Sift の調査案件を表示get_sift_investigation — UUID で Sift の調査案件を取得get_sift_analysis — 調査案件から特定の分析結果を取得find_error_pattern_logs — Loki ログでエラーパターンの急増箇所を検索(書き込み)find_slow_requests — Tempo データソースで遅いリクエストを検索(書き込み)ask_assistant — Grafana Assistant にプロンプトを送信して完全な回答を取得(書き込み)get_assertions — エンティティのアサーション(状態確認)サマリーを取得get_panel_image — ダッシュボードパネルを PNG 画像としてレンダリングdescribe_infrastructure — サービスグループの事前構築サマリーを取得get_query_examples — データソース型の例題クエリを取得ask_assistant を使用して Grafana Assistant に調査を計画させ、根拠のある回答を得てください。ask_assistant は書き込みスコープで、grafana:write が必要です。ask_assistant は使用できません。この場合は対応する読み取り専用ツール(例:describe_infrastructure、get_assertions、query_prometheus、query_loki_logs、list_incidents)を使用し、自然言語アシスタント機能には書き込みスコープが必要であることをユーザーに伝えてください。再度認可する際に書き込みアクセスが付与されるのは、ユーザーが Assistant Admin ロールまたは grafana-assistant-app.cloud-mcp.scope:write 権限を持つ場合のみです。それ以外は Grafana 組織の管理者による許可が必要です。ask_assistant 経由ではなく対応するツールを直接呼び出してください。get_dashboard_by_uid ではなく get_dashboard_summary を使用してください。get_dashboard_property を使用してください。search_dashboards を使用してダッシュボードを検出してください。generate_deeplink でクリック可能な URL を提供してください。list_datasources、list_prometheus_metric_names)を使用してください。update_dashboard、create_incident、alerting_manage_rules)は避けてください。grafana-assistant-app.cloud-mcp:access 権限が必要です。Editor 以上は既定で権限を持ち、その他のロールには明示的に権限を付与できます。grafana:write スコープが必要です。そのスコープを付与することは Grafana RBAC で制御されており、ユーザーは Assistant Admin ロールまたは grafana-assistant-app.cloud-mcp.scope:write 権限を持つ必要があります。読み取り専用アクセスでは不要です。Hosted MCP server providing 60+ Grafana Cloud tools via Streamable HTTP transport with OAuth 2.1 authorization.
grafana-assistant-app.cloud-mcp:access permission (Editor role or higher has this by default)The Cloud MCP server connects via https://mcp.grafana.com/mcp using Streamable HTTP transport. No local installation or environment variables are required.
When authorizing, you choose which permissions to grant:
Organization Admins can grant write access by default. If write access is disabled on the consent page, the user needs the Assistant Admin role.
search_dashboards — search for dashboards by query stringsearch_folders — search for folders by query stringgenerate_deeplink — generate deeplink URLs for dashboards, panels, and Explore queriesget_dashboard_by_uid — retrieve the complete dashboard JSON by UIDget_dashboard_summary — compact summary without full JSON (preferred)get_dashboard_property — extract specific parts via JSONPathget_dashboard_panel_queries — retrieve panel queries with template variable substitutionupdate_dashboard — create or update a dashboard (Write)create_folder — create a Grafana folder (Write)list_datasources — list all configured data sources with optional type filteringget_datasource — get detailed information by UID or namelist_prometheus_metric_names — discover available metrics with regex filteringlist_prometheus_metric_metadata — list metadata about currently scraped metricslist_prometheus_label_names — list label names with optional series selectorlist_prometheus_label_values — get values for a specific labelquery_prometheus — execute PromQL instant or range queriesquery_prometheus_histogram — query histogram percentileslist_loki_label_names — list available label names in logslist_loki_label_values — get unique values for a specific labelquery_loki_logs — execute LogQL queries for log entries or metric valuesquery_loki_stats — get statistics about log streamsquery_loki_patterns — detect and analyze common log patternsIf you have Tempo data sources, the Cloud MCP server proxies tools from the Tempo data source, including TraceQL queries and attribute discovery.
list_pyroscope_label_names — list available label names in profileslist_pyroscope_label_values — list values for a specific labellist_pyroscope_profile_types — list available profile typesquery_pyroscope — query profiles or metrics from Pyroscopelist_clickhouse_tables — list available tables with metadatadescribe_clickhouse_table — get column schema for a tablequery_clickhouse — execute SQL queries against ClickHouse datasourceslist_cloudwatch_namespaces — list available AWS namespaceslist_cloudwatch_metrics — list metrics for a namespacelist_cloudwatch_dimensions — list dimension keys for a metricquery_cloudwatch — query AWS CloudWatch metricsquery_elasticsearch — execute Lucene or Query DSL searchesalerting_manage_rules — list, filter, create, and update alert rules (Read / Write)alerting_manage_routing — view routing configuration, notification policies, contact points (Read)get_annotations — fetch annotations filtered by dashboard UID, time range, or tagsget_annotation_tags — get annotation tags with optional filteringcreate_annotation — create a new annotation (Write)update_annotation — update an existing annotation (Write)list_incidents — list incidents with optional status filteringget_incident — get full incident details by IDcreate_incident — create a new incident (Write)add_activity_to_incident — add a note to an incident's timeline (Write)list_oncall_schedules — list OnCall schedules with optional team filteringget_oncall_shift — get detailed shift informationget_current_oncall_users — get users currently on-call for a schedulelist_oncall_teams — list OnCall teamslist_oncall_users — list OnCall users with optional filteringlist_alert_groups — list alert groups with filteringget_alert_group — get a specific alert group by IDlist_sift_investigations — list Sift investigationsget_sift_investigation — retrieve a Sift investigation by UUIDget_sift_analysis — retrieve a specific analysis from an investigationfind_error_pattern_logs — search Loki logs for elevated error patterns (Write)find_slow_requests — search Tempo datasources for slow requests (Write)ask_assistant — send a prompt to Grafana Assistant and get the full reply (Write)get_assertions — get assertion summary for an entityget_panel_image — render a dashboard panel as a PNG imagedescribe_infrastructure — retrieve pre-built summaries of service groupsget_query_examples — get example queries for datasource typesask_assistant to let Grafana Assistant plan the investigation and return a grounded reply. ask_assistant is write-scoped and requires grafana:write.ask_assistant is unavailable. Fall back to the appropriate read-only tools (for example describe_infrastructure, get_assertions, query_prometheus, query_loki_logs, list_incidents) and tell the user that the natural-language Assistant tool needs write scope. Re-authorizing only grants write if the user has the Assistant Admin role or the grafana-assistant-app.cloud-mcp.scope:write permission; otherwise a Grafana organization administrator must grant it first.ask_assistant.get_dashboard_summary instead of get_dashboard_by_uid to avoid consuming context with full dashboard JSON.get_dashboard_property with JSONPath to extract only the specific parts you need.search_dashboards to discover dashboards before retrieving by UID.generate_deeplink to provide clickable URLs rather than describing navigation steps.list_datasources, list_prometheus_metric_names) before writing queries.update_dashboard, create_incident, alerting_manage_rules) unless explicitly asked by the user.grafana-assistant-app.cloud-mcp:access permission. Editor and higher have this by default; other roles can be granted it explicitly.grafana:write OAuth scope, granted during OAuth consent. Granting that scope is itself gated by Grafana RBAC: the user needs the Assistant Admin role or the grafana-assistant-app.cloud-mcp.scope:write permission to authorize a write-scoped connection. Read-only access does not require it.原文・著作権は Anthropic および各プラグイン作者に帰属します。日本語訳は Claude API による自動翻訳です。