Wazuh Mcp Server

Wazuh Mcp Server is an MCP server that integrates security monitoring and telemetry data from the Wazuh platform with local large language model clients. It connects directly to Wazuh security infrastructure to expose security events, host compliance status, vulnerability reports, and active intrusion detections to AI agents. Security analysts, system administrators, and DevSecOps engineers use this server to query and analyze threat intelligence within their AI workspace. By exposing Wazuh SIEM capabilities through the Model Context Protocol, the integration enables AI assistants to inspect security alerts, summarize incident logs, track compliance drift, and assist in incident response workflows. Users can ask conversational questions about their security environment, check agent health across monitored endpoints, and review threat detections without manually navigating through separate Wazuh dashboards. This bridge centralizes security operations by providing immediate access to real-time endpoint observability directly inside compatible MCP client applications.

Category: Monitoring & Observability

Tags: compliance, siem, threat-detection, vulnerability, wazuh

Visit Wazuh Mcp Server

How to install and configure Wazuh Mcp Server

  1. Check the official GitHub repository at https://github.com/Karibusan/Wazuh-MCP-Server for current system requirements, installation scripts, and environment variable requirements. 2. Clone or download the repository to your local system. 3. Configure your Wazuh API connection credentials and endpoint details as instructed in the repository documentation. 4. Register the server executable or entry command in your MCP client configuration file, such as Claude Desktop or Cursor, under the mcpServers property. 5. Restart your MCP client to load the connection and verify access to Wazuh tools.

What you can do with Wazuh Mcp Server

  • Query recent security alerts and threat detections across monitored endpoints using natural language queries directly within an MCP client. * Check agent connection status and system health for specific hosts managed by the Wazuh security server. * Summarize vulnerability scanning results and compliance reports across organizational infrastructure for internal security audits. * Investigate suspicious authentication logs and incident triggers to accelerate triage workflows during active security investigations.

Key facts

  • Open Source
  • https://github.com/Karibusan/Wazuh-MCP-Server
  • Monitoring & Observability, Security & Compliance
  • compliance, siem, threat-detection, vulnerability, wazuh

Part of MCP Servers

Related MCP servers

  • MCP Node.js Debugger — MCP Node.js Debugger is an MCP server that provides runtime debugging access for running Node.js applications to AI programming tools…
  • MCP Performance Analysis Server — MCP Performance Analysis Server is an MCP server that inspects mobile application performance monitoring metrics to identify critical performance anomalies.…
  • MCP Prometheus — MCP Prometheus is an MCP server that exposes Prometheus and Mimir time-series databases to AI assistants through standardized interfaces. Written…
  • MCP Status Observer — MCP Status Observer is an MCP server that monitors the real-time operational status, component health, and incident history of major…
  • MCP Tool Poisoning Attacks — MCP Tool Poisoning Attacks is an MCP server and client demonstration environment that demonstrates security vulnerabilities and threat models involving…
  • MCP Useful Assistant — MCP Useful Assistant is an MCP server that provides AI clients with a multipurpose toolkit spanning file operations, web intelligence,…

What is Wazuh Mcp Server?

Wazuh Mcp Server is an open-source integration that bridges the Wazuh open-source security platform with Model Context Protocol clients. It enables AI models to fetch, examine, and analyze security telemetry, alert logs, and system metrics directly from Wazuh environments.

Is Wazuh Mcp Server open source?

Yes, Wazuh Mcp Server is open source and hosted on GitHub under a community repository. Users can inspect its source code, modify it for custom environments, and contribute to its development via its repository page.

Which MCP clients work with Wazuh Mcp Server?

The server functions with standard Model Context Protocol clients that support local stdio or server connections. Common compatible environments include Claude Desktop, Cursor, and custom tooling built on top of the standard Model Context Protocol specification.

How do I configure Wazuh Mcp Server?

Because specific configuration flags are maintained in the repository, you should visit https://github.com/Karibusan/Wazuh-MCP-Server to review setup guides. Typically, you must provide your Wazuh API server URL and credentials so the MCP server can authenticate queries.

  • AI Tools
  • Categories
  • Industries
  • CLI Coding Agents
  • MCP Servers
  • MCP Categories