---
icon: material/creation
title: "MCP Server FAQ: drive 10x from a chat session"
description: "FAQ for the 10x MCP server: install into Claude Desktop, Claude Code, or Cursor; ask cost questions, generate Helm values, and apply filter caps from chat."
---

# MCP
The [MCP Server](https://doc.log10x.com/apps/mcp/) drives the rest of 10x from a chat session. Install it into Claude Desktop, Claude Code, or Cursor; ask cost questions, generate per-app Helm values, and apply filter caps without leaving the conversation.

<div class="grid cards" markdown>

- [:material-information-outline: **Overview**](#overview)
- [:material-cog-outline: **What it does**](#what-it-does)
- [:material-shield-check-outline: **Security**](#security)

</div>

### :material-information-outline: Overview { #overview }

??? tenx-overview "Do I need MCP to use 10x"

    **No.** Every 10x app (Reporter, Receiver, Retriever) has standalone install/deploy docs you can follow manually. MCP just makes adoption faster by knowing your environment and generating tailored configs.

    If you prefer a manual workflow, skip MCP entirely and follow each app's [Deploy page](https://doc.log10x.com/apps/).

### :material-cog-outline: What it does { #what-it-does }

??? tenx-capabilities "How does MCP know about my cluster"

    When you ask MCP to discover your environment, it reads your kubeconfig (read-only, same credentials as `kubectl get`) to identify:

    - Forwarder DaemonSets (Fluent Bit, Fluentd, Datadog Agent, OTel Collector, etc.)
    - Node counts and pod topology
    - Existing logging destinations (Splunk HEC endpoints, Elasticsearch clusters, CloudWatch log groups)

    It then proposes a deployment plan tailored to your stack. See [Tools](https://doc.log10x.com/apps/mcp/tools/) for the per-tool reference.

??? tenx-capabilities "Does MCP apply changes to my infrastructure"

    **No.** MCP is an advisor, not an actor:

    - k8s discovery is read-only (`kubectl get` equivalents only)
    - Generated configs are **files**, not applied changes. MCP writes `my-reporter.yaml`; you review and `helm install`.
    - Filter/compact suggestions are **diff-reviewable**. MCP proposes mute file entries; you commit.
    - Dependency checks call the log analyzer's API in-process when creds are in the env (read-only, never POST/PUT/DELETE), and fall back to copy-paste bash when they aren't.

    You stay the operator. MCP never writes to your cluster, your git repo, or your log analyzer.

### :material-shield-check-outline: Security { #security }

??? tenx-recovery "What data does the MCP Server see"

    - API calls to your metrics backend (pre-aggregated metrics, no log content). There is no default endpoint: unless you nominate one, the engine collects metrics in-process and forwards them nowhere. Point it at your own Prometheus, or at the optional hosted `prometheus.log10x.com`, or run air-gapped.
    - kubeconfig read access (only what `kubectl get` would surface)
    - Your log analyzer credentials (for dependency checks; read-only, local-only)

    No log content ever leaves your machine. No data is cached server-side.

??? tenx-recovery "Where does the MCP Server run"

    As a local subprocess of your AI assistant (Claude Desktop, Code, Cursor). It starts when the assistant connects to the MCP and stops when the assistant closes. No cloud hosting, no Lambda, no API Gateway.
