Skip to main content
Glama
alexgoller

Illumio MCP Server

by alexgoller

get-events

Retrieve security events from the Illumio PCE with filters for status, severity, creator, type, and time range.

Instructions

Get events from the PCE with optional filtering

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
statusNoFilter by event status
severityNoFilter by event severity
created_byNoFilter by creator (user, agent, or system)
event_typeNoFilter by event type (e.g., 'system_task.expire_service_account_api_keys')
max_resultsNoMaximum number of events to return
timestamp_gteNoEarliest event timestamp (RFC 3339 format)
timestamp_lteNoLatest event timestamp (RFC 3339 format)

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed3 schema fields changedv0.8.0
    • addedInput schema / properties / created_by
      Added value: +{
      +  "description": "Filter by creator (user, agent, or system)",
      +  "type": "string"
      +}
    • addedInput schema / properties / timestamp_gte
      Added value: +{
      +  "description": "Earliest event timestamp (RFC 3339 format)",
      +  "type": "string"
      +}
    • addedInput schema / properties / timestamp_lte
      Added value: +{
      +  "description": "Latest event timestamp (RFC 3339 format)",
      +  "type": "string"
      +}
  2. Addedv1.0.0

TDQS

B3.1/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

No annotations are provided, so the description must carry the behavioral disclosure burden. It only states that events are fetched and that filtering is optional; it does not describe result ordering, pagination behavior, return format, or side-effect-free guarantees, all of which would be useful for a get tool.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single, front-loaded sentence with no filler or redundancy. It communicates the object and action efficiently.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a simple read tool, the core action is adequately conveyed, and all parameters are documented in the schema. However, with no annotations and no output schema, the description does not explain the return shape, default limits beyond the schema default, or how filters combine, leaving an agent to infer those details.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

The input schema covers all seven parameters with descriptions, including enum values and a default for max_results, so the description does not need to repeat parameter details. The description adds only the generic notion of 'optional filtering' and no extra semantic nuance, meeting the baseline for high schema coverage.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description states a clear verb ('Get'), a resource ('events'), and scope ('from the PCE'), so the core action is understandable. However, it does not elaborate on what kinds of events are included or differentiate itself from event-adjacent siblings like get-server-changelog, so it is not fully distinct.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The phrase 'with optional filtering' implies this is a query/list operation, but no explicit guidance is given about when to use this tool versus alternatives. No alternatives are named, and there is no mention of prerequisites or context in which get-events would not be appropriate.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.