F6 XDR MCP Server
OfficialServer Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| XDR_API_KEY | Yes | Personal API token for the XDR user | |
| XDR_BASE_URL | Yes | Base URL of your XDR installation | |
| XDR_CA_BUNDLE | No | PEM bundle for installations behind an internal CA. | |
| XDR_ALLOW_WRITE | No | Set to '1' to enable the xdr_mark_event tool. Disabled by default. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| experimental | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| xdr_searchA | Search for events/objects in an XDR section. Returns matching records; an empty query returns the section unfiltered. Use xdr_get_mapping first to discover available fields. |
| xdr_countA | Get the total count of records in an XDR section. Optionally filter by query to count matching records only. |
| xdr_get_mappingA | Get all available search fields for an XDR section. Returns field names, labels, categories, and supported operators. Call this first to understand what you can search on. |
| xdr_get_filtersC | Get available filter options for an XDR section. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 4 tools
Each tool has a clearly distinct purpose: search returns records, count returns aggregates, get_mapping lists searchable fields, and get_filters lists filter options. There is no functional overlap that would cause an agent to select the wrong tool.
All tool names follow a consistent pattern: the xdr_ prefix plus an action verb (search, count, get_mapping, get_filters). The convention is uniform and predictable.
With only 4 tools, the server is tightly scoped to a focused XDR query/exploration workflow. Each tool earns its place, and the count is well within the ideal range.
The server covers the core XDR search workflow well: discover fields, inspect filters, run searches, and get counts. A minor gap is the lack of an explicit tool for listing available XDR sections, but this may be outside the intended scope.