Mcp Server Wazuh

Mcp Server Wazuh is an MCP server that connects Claude Desktop and other Model Context Protocol clients directly to a Wazuh SIEM deployment. Written in Rust, it interfaces with both the Wazuh Manager API and the Wazuh Indexer to transform complex SIEM security telemetry into structured data for LLM analysis. Security analysts, compliance officers, and incident responders use it to interact with their security monitoring infrastructure using natural language queries. The server enables users to inspect security alerts, review critical system vulnerabilities, and evaluate active agent health and running processes without manually issuing API requests or writing search queries. It also exposes cluster health metrics, manager logs, rules configurations, and network port data across monitored endpoints. By bridging Wazuh and AI workflows, teams can accelerate triage, investigate endpoint anomalies, review regulatory compliance benchmarks like PCI-DSS and HIPAA, and coordinate threat hunting investigations directly inside their conversational AI clients.

Category: Monitoring & Observability

Tags: security monitoring, siem, threat-detection, vulnerability-management, wazuh

Visit Mcp Server Wazuh

How to install and configure Mcp Server Wazuh

  1. Download the pre-built binary for your operating system from the repository releases page, or build it locally using cargo build --release after cloning the repository. 2. Ensure the binary has executable permissions (for example, chmod +x mcp-server-wazuh-linux-amd64). 3. Configure your MCP client, such as Claude Desktop, by editing claude_desktop_config.json. 4. Add the server configuration under mcpServers with the executable path and required environment variables: json { "mcpServers": { "wazuh": { "command": "/path/to/mcp-server-wazuh", "args": [], "env": { "WAZUH_API_HOST": "your_wazuh_manager_api_host", "WAZUH_API_PORT": "55000", "WAZUH_API_USERNAME": "your_wazuh_api_user", "WAZUH_API_PASSWORD": "your_wazuh_api_password", "WAZUH_INDEXER_HOST": "your_wazuh_indexer_host", "WAZUH_INDEXER_PORT": "9200", "WAZUH_INDEXER_USERNAME": "your_wazuh_indexer_user", "WAZUH_INDEXER_PASSWORD": "your_wazuh_indexer_password", "WAZUH_VERIFY_SSL": "false", "WAZUH_TEST_PROTOCOL": "https", "RUST_LOG": "info" } } } } 5. Restart your MCP client to load the Wazuh integration tools.

What you can do with Mcp Server Wazuh

  • Query recent security alerts and triage potential threat patterns using natural language inside your client interface. * Assess agent vulnerabilities and identify critical common vulnerabilities and exposures across endpoints to prioritize patching. * Inspect running processes and open network ports on specific Wazuh agents during digital forensics investigations. * Review Wazuh detection rules and manager logs to optimize detection accuracy and debug cluster performance issues. * Verify monitoring coverage and audit logging evidence across distributed infrastructure to support compliance gap analysis.

Key facts

  • https://github.com/gbrigandi/mcp-server-wazuh
  • Monitoring & Observability, Security & Compliance
  • security monitoring, siem, threat-detection, vulnerability-management, wazuh

Part of MCP Servers

Related MCP servers

  • MCP Node.js Debugger — MCP Node.js Debugger is an MCP server that provides runtime debugging access for running Node.js applications to AI programming tools…
  • MCP Performance Analysis Server — MCP Performance Analysis Server is an MCP server that inspects mobile application performance monitoring metrics to identify critical performance anomalies.…
  • MCP Prometheus — MCP Prometheus is an MCP server that exposes Prometheus and Mimir time-series databases to AI assistants through standardized interfaces. Written…
  • MCP Status Observer — MCP Status Observer is an MCP server that monitors the real-time operational status, component health, and incident history of major…
  • MCP Tool Poisoning Attacks — MCP Tool Poisoning Attacks is an MCP server and client demonstration environment that demonstrates security vulnerabilities and threat models involving…
  • MCP Useful Assistant — MCP Useful Assistant is an MCP server that provides AI clients with a multipurpose toolkit spanning file operations, web intelligence,…

What is Mcp Server Wazuh?

Mcp Server Wazuh is a Rust-based Model Context Protocol server that connects AI assistants to the Wazuh SIEM platform. It allows users to query security alerts, monitor agent status, inspect vulnerabilities, and review system logs through natural language interactions.

Which MCP clients work with Mcp Server Wazuh?

Mcp Server Wazuh works with any client compatible with the Model Context Protocol that supports standard input and output transport, such as Claude Desktop. It can also be built with HTTP transport support if required by your client architecture.

What are the system requirements for running this server?

Running the server requires an MCP-compatible client, a reachable Wazuh server with its API enabled (version 4.12 is recommended), and network connectivity between the machine running the MCP server, the Wazuh Manager API, and the Wazuh Indexer.

Can Mcp Server Wazuh be run using Docker?

Yes, you can pull the official container image using the command docker pull ghcr.io/gbrigandi/mcp-server-wazuh:latest and pass the necessary Wazuh API and Indexer environment variables via a configuration file.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories