Skip to main content
Glama
F6-Security

F6 XDR MCP Server

Official
by F6-Security

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
XDR_API_KEYYesPersonal API token for the XDR user
XDR_BASE_URLYesBase URL of your XDR installation
XDR_CA_BUNDLENoPEM bundle for installations behind an internal CA.
XDR_ALLOW_WRITENoSet to '1' to enable the xdr_mark_event tool. Disabled by default.

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
xdr_searchA

Search for events/objects in an XDR section. Returns matching records; an empty query returns the section unfiltered. Use xdr_get_mapping first to discover available fields.

xdr_countA

Get the total count of records in an XDR section. Optionally filter by query to count matching records only.

xdr_get_mappingA

Get all available search fields for an XDR section. Returns field names, labels, categories, and supported operators. Call this first to understand what you can search on.

xdr_get_filtersC

Get available filter options for an XDR section.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.8/5.0

Scored across 4 tools

Disambiguation5/5

Each tool has a clearly distinct purpose: search returns records, count returns aggregates, get_mapping lists searchable fields, and get_filters lists filter options. There is no functional overlap that would cause an agent to select the wrong tool.

Naming Consistency5/5

All tool names follow a consistent pattern: the xdr_ prefix plus an action verb (search, count, get_mapping, get_filters). The convention is uniform and predictable.

Tool Count5/5

With only 4 tools, the server is tightly scoped to a focused XDR query/exploration workflow. Each tool earns its place, and the count is well within the ideal range.

Completeness4/5

The server covers the core XDR search workflow well: discover fields, inspect filters, run searches, and get counts. A minor gap is the lack of an explicit tool for listing available XDR sections, but this may be outside the intended scope.

Maintenance

ActivityMaintained
ResponsivenessNo issues