loggly-mcp
Related Servers
Alternatives to loggly-mcp
- AlicenseBqualityCmaintenanceA read-only MCP server for OpenObserve Community Edition that works over the REST API. Provides tools for searching logs, traces, stream schemas, and dashboards - no Enterprise license required.894 PyPI16GPL 3.0
- FlicenseNot gradedqualityCmaintenanceRead-only MCP server for Elasticsearch log querying. Enables natural language search, filtering, context retrieval, and aggregation of logs.-
Related Servers
- AlicenseAqualityAmaintenanceMCP server for Malcolm (Zeek/Suricata/Arkime/OpenSearch/NetBox): full read surface plus opt-in, audited write tools.5192 PyPI3MIT
- AlicenseAqualityCmaintenanceRead-only MCP server for the SentinelOne management API, exposing sites, endpoint agents, threats, and activity logs with aggregation tools for MSP/MSSP reporting.614 npmMIT
- AlicenseNot gradedqualityFmaintenanceA read-only MCP server that exposes Quickwit log search and aggregations to LLM clients, enabling natural language log investigation.Apache 2.0
- AlicenseAqualityBmaintenanceCloudOps MCP is a read-only Model Context Protocol server that exposes normalized operational infrastructure context (logs, metrics, deployments, health) to AI agents through a small set of typed, bounded tools.6MIT
- FlicenseAqualityCmaintenanceRead-only MCP server for searching migrated Papertrail logs via SolarWinds Observability API. Provides tools to list environments and perform bearer-authenticated log queries through stdio.221 npm-
- FlicenseNot gradedqualityCmaintenanceRead-only MCP server for querying Microsoft Purview unified audit logs across M365 workloads, wrapping the Graph API's asynchronous audit log search.-
TDQS
Scored across 24 tools
There is real overlap: get_events, search_and_get_events, iterate_events_page/next, search_logs, and sample_events all retrieve event data, and the traffic_by_*/group_by_* families are near-identical variants differing only by dimension (some explicitly 'thin wrappers over field_facets'). The descriptions do provide guidance ('prefer this over...'), which prevents outright confusion, but an agent must read carefully to pick correctly.
All names use snake_case and are largely verb_noun or noun_verb forms (create_search, get_events, count_events, list_fields, sample_events, rdap_lookup). A few noun-first names (volume_metrics, field_facets, traffic_by_ip, timeline) deviate from the verb-first majority but remain readable and predictable.
24 tools is on the heavy end for a log-search server, and several families are redundant (traffic_by_ip/host/path, group_by_ip/path/user_agent) and could be collapsed into parameterized tools. It's justifiable but feels inflated by wrapper duplication.
The surface covers the core Loggly lifecycle well: credential check, search creation, event retrieval/iteration, counts, volume, stats, field listing/facets, plus aggregation helpers and external IP enrichment (RDAP, GreyNoise, AbuseIPDB, combined context). Minor gaps like saved-search management or write/delete operations exist but are outside the apparent read-only analytics scope.