Mcp Server Wazuh is an MCP server that connects Claude Desktop and other Model Context Protocol clients directly to a Wazuh SIEM deployment. Written in Rust, it interfaces with both the Wazuh Manager API and the Wazuh Indexer to transform complex SIEM security telemetry into structured data for LLM analysis. Security analysts, compliance officers, and incident responders use it to interact with their security monitoring infrastructure using natural language queries. The server enables users to inspect security alerts, review critical system vulnerabilities, and evaluate active agent health and running processes without manually issuing API requests or writing search queries. It also exposes cluster health metrics, manager logs, rules configurations, and network port data across monitored endpoints. By bridging Wazuh and AI workflows, teams can accelerate triage, investigate endpoint anomalies, review regulatory compliance benchmarks like PCI-DSS and HIPAA, and coordinate threat hunting investigations directly inside their conversational AI clients.
Category: Monitoring & Observability
Tags: security monitoring, siem, threat-detection, vulnerability-management, wazuh
cargo build --release after cloning the repository. 2. Ensure the binary has executable permissions (for example, chmod +x mcp-server-wazuh-linux-amd64). 3. Configure your MCP client, such as Claude Desktop, by editing claude_desktop_config.json. 4. Add the server configuration under mcpServers with the executable path and required environment variables: json { "mcpServers": { "wazuh": { "command": "/path/to/mcp-server-wazuh", "args": [], "env": { "WAZUH_API_HOST": "your_wazuh_manager_api_host", "WAZUH_API_PORT": "55000", "WAZUH_API_USERNAME": "your_wazuh_api_user", "WAZUH_API_PASSWORD": "your_wazuh_api_password", "WAZUH_INDEXER_HOST": "your_wazuh_indexer_host", "WAZUH_INDEXER_PORT": "9200", "WAZUH_INDEXER_USERNAME": "your_wazuh_indexer_user", "WAZUH_INDEXER_PASSWORD": "your_wazuh_indexer_password", "WAZUH_VERIFY_SSL": "false", "WAZUH_TEST_PROTOCOL": "https", "RUST_LOG": "info" } } } } 5. Restart your MCP client to load the Wazuh integration tools.Part of MCP Servers
Mcp Server Wazuh is a Rust-based Model Context Protocol server that connects AI assistants to the Wazuh SIEM platform. It allows users to query security alerts, monitor agent status, inspect vulnerabilities, and review system logs through natural language interactions.
Mcp Server Wazuh works with any client compatible with the Model Context Protocol that supports standard input and output transport, such as Claude Desktop. It can also be built with HTTP transport support if required by your client architecture.
Running the server requires an MCP-compatible client, a reachable Wazuh server with its API enabled (version 4.12 is recommended), and network connectivity between the machine running the MCP server, the Wazuh Manager API, and the Wazuh Indexer.
Yes, you can pull the official container image using the command docker pull ghcr.io/gbrigandi/mcp-server-wazuh:latest and pass the necessary Wazuh API and Indexer environment variables via a configuration file.