Skip to main content
Glama
MadameFabulous

Chainsaw MCP Server

Chainsaw: search events

chainsaw_search

Search Windows event logs and evidence for keywords, regular expressions, or tau field expressions to find matching events summarized by host, channel, event ID, and hour.

Instructions

Search evidence for keywords, regular expressions, or tau field expressions.

Runs chainsaw search; each matching document is stored under a result handle and summarised by host, channel, event ID and hour. Use tau expressions to pivot on a specific field (for example a LogonId, process GUID, or user) after a hunt.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
tauNoTau field expressions such as 'Event.System.EventID: =4104' or 'Event.EventData.Image: i*mimikatz*'. Combined with AND unless match_any.
pathsYesEvidence files or directories under an allowed root.
fieldsNoDotted paths or shorthand names to project in the inline preview; see chainsaw_result_fields. Omit for the standard shorthand columns.
previewNoEvents to include inline.
to_timeNoDrop documents newer than YYYY-MM-DDTHH:MM:SS.
patternsNoString or regular-expression patterns matched against the whole document. All must match unless match_any is true.
timezoneNoIANA timezone for output.
extensionNoOnly load this extension.
from_timeNoDrop documents older than YYYY-MM-DDTHH:MM:SS.
match_anyNoMatch a document when any one of the patterns matches (and, separately, any one of the tau expressions) instead of requiring all of them. Patterns and tau expressions are always combined with AND.
ignore_caseNoCase-insensitive pattern matching.
skip_errorsNoContinue past unreadable files.
load_unknownNoTry to parse unidentified files.
timestamp_fieldNoField holding the timestamp when from_time/to_time are set. Default for EVTX: Event.System.TimeCreated_attributes.SystemTime.

Schema Changelog

Changes observed during successful MCP inspections.

  1. First observedv0.1.0

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With annotations present, the description adds meaningful behavior beyond them: each matching document is persisted under a result handle and summarised by host, channel, event ID and hour. This side effect is consistent with readOnlyHint=false, and the output shape is disclosed despite no output schema. Auth/rate-limit context is absent, keeping it below 5.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three tightly written sentences: purpose first, then result-handle behavior, then the pivot use case. No filler, nothing repeated, and the most important information is front-loaded.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a 14-parameter tool with no output schema, the description covers purpose, persistence behavior, and the summary shape (host, channel, event ID, hour), which fills the return-value gap. It does not spell out how result handles are consumed or interact with the chainsaw_result_* siblings, leaving a small gap.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the schema already documents all 14 parameters, including tau expression syntax. The description only references the examples already in the schema (LogonId, process GUID, user) and points to chainsaw_result_fields for the fields param, adding little new semantic meaning.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb and resource ('Search evidence') plus the three matching modes (keywords, regex, tau expressions), and the second sentence explains what happens to matches. It differentiates from siblings only implicitly via 'after a hunt' rather than naming chainsaw_hunt as the alternative, so it falls just short of a 5.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

'Use tau expressions to pivot on a specific field ... after a hunt' gives a concrete situation for calling the tool and a worked example (LogonId, process GUID, user). It lacks explicit when-not guidance or a named alternative tool, so it is clear context without exclusions.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.