Skip to main content
Glama
amittell

firewalla-mcp-server

search_alarms

Read-only

Search Firewalla alarms using full-text or field filters for type, status, device, region, and more. Retrieve paginated results or grouped counts to identify security, bandwidth, and connectivity events.

Instructions

Search alarms using full-text or field filters. Alarm types: 1=Security Activity, 2=Abnormal Upload, 3=Large Bandwidth Usage, 4=Monthly Data Plan, 5=New Device, 6=Device Back Online, 7=Device Offline, 8=Video Activity, 9=Gaming Activity, 10=Porn Activity, 11=VPN Activity, 12=VPN Connection Restored, 13=VPN Connection Error, 14=Open Port, 15=Internet Connectivity Update, 16=Large Upload. Reads GET /v2/alarms, 500 per request, following the cursor up to limit. Scoped to FIREWALLA_BOX_ID when set, otherwise every box.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
limitNoMaximum results (optional, default: 200, API maximum: 500)
queryYesSearch query using Firewalla syntax. Supported fields: type:1-16 (see alarm types above), status:1/2 (active/archived), device.ip:192.168.*, region:US (country code), box.id:box_gid, device.name:*. Examples: "type:8 AND region:US" (video from US), "type:10 AND status:1" (active porn alerts), "device.ip:192.168.* AND status:1" (active alarms from the LAN), "porn" (free text: a term without a qualifier searches alarm text)
cursorNoPagination cursor from previous response
sortByNoSort alarms (default: ts:desc)
groupByNoFields to group by, comma-separated, e.g. "type", "status", "device" or "type,box". The API then returns groups instead of alarms: groups of { key, count }, where key holds the group fields (gid for box, device.id for device) and count the alarms in the group.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed2 schema fields changedv1.5.0
    • changedInput schema / properties / groupBy / description
      Previous value: -"Group alarms by specified fields (comma-separated)"New value: +"Fields to group by, comma-separated, e.g. \"type\", \"status\", \"device\" or \"type,box\". The API then returns groups instead of alarms: groups of { key, count }, where key holds the group fields (gid for box, device.id for device) and count the alarms in the group."
    • changedInput schema / properties / query / description
      Previous value: -"Search query using Firewalla syntax. Supported fields: type:1-16 (see alarm types above), resolved:true/false, status:1/2 (active/archived), source_ip:192.168.*, region:US (country code), gid:box_id, device.name:*, message:\"text search\". Examples: \"type:8 AND region:US\" (video from US), \"type:10 AND status:1\" (active porn alerts), \"source_ip:192.168.* AND NOT resolved:true\""New value: +"Search query using Firewalla syntax. Supported fields: type:1-16 (see alarm types above), status:1/2 (active/archived), device.ip:192.168.*, region:US (country code), box.id:box_gid, device.name:*. Examples: \"type:8 AND region:US\" (video from US), \"type:10 AND status:1\" (active porn alerts), \"device.ip:192.168.* AND status:1\" (active alarms from the LAN), \"porn\" (free text: a term without a qualifier searches alarm text)"
  2. Changed1 schema field changedv1.3.0
    • changedInput schema / required
      Previous value: -[]New value: +[
      +  "query"
      +]
  3. First observed

TDQS

B3.4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint and openWorldHint. The description adds valuable behavior: it mentions the HTTP endpoint (GET /v2/alarms), pagination limit of 500 per request, cursor following up to the limit, and scoping to a box ID. This goes beyond the annotation flags and helps the agent anticipate API behavior. No contradiction with annotations.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is a single paragraph that lists all 16 alarm types, making it somewhat long but logically structured. It front-loads the core purpose, then provides the type mapping and behavioral details. While it could be more concise (e.g., moving the type list to a reference section), it is organized and readable.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a search tool with no output schema, the description covers input semantics, pagination, and scoping but does not describe the response format (e.g., what fields are returned, how groups look). This is a gap because agents need to know how to parse results. Given the complexity of 5 parameters, this omission prevents full completeness.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so all parameters have descriptions. The description adds the alarm type mapping (1-16) referenced by the query parameter, which is essential for constructing valid queries. It also explains pagination behavior with cursor and limit, adding meaning beyond the schema's generic descriptions. This is a meaningful supplement to the schema.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose4/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the tool's function: 'Search alarms using full-text or field filters.' It specifies the resource (alarms) and the action (search), and even lists alarm types, which helps understanding. However, it does not explicitly differentiate from sibling tools like get_active_alarms or get_specific_alarm, so it falls short of the 5-level criterion that requires distinguishing from siblings.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines2/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description provides no guidance on when to use this tool versus alternatives. It does not mention conditions for choosing this over get_active_alarms or get_specific_alarm, nor does it state any exclusions or prerequisites. The only context given is scoping to FIREWALLA_BOX_ID, which is a parameter detail, not usage guidance.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.