loggly-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| LOGGLY_TOKEN | No | Loggly API token. Replaced by LOGGLY_ACCOUNTS when that is set. | |
| MCP_HTTP_PORT | No | Port for the stateless Streamable HTTP MCP server. Default: `8787`. | 8787 |
| LOGGLY_ACCOUNTS | No | JSON object mapping an account name to its credentials, e.g. {"acme":{"subdomain":"acme","token":"acme_token","authMode":"bearer"},"beta":{"subdomain":"beta","token":"beta_token"}}. When set, it replaces LOGGLY_SUBDOMAIN/LOGGLY_TOKEN/LOGGLY_AUTH_MODE and every tool accepts an optional `account` argument. | |
| LOGGLY_FIELD_IP | No | Override for the IP field name used by the aggregation tools, instead of discovery-first field resolution. | |
| LOGGLY_AUTH_MODE | No | Loggly authentication mode: `bearer` (default) or `basic`. Replaced by LOGGLY_ACCOUNTS when that is set. | bearer |
| LOGGLY_LOG_LEVEL | No | Log verbosity: `error`, `warn`, `info` (default), or `debug`. Logs are written to stderr. | info |
| LOGGLY_SUBDOMAIN | No | Loggly account subdomain or full Loggly URL (e.g. `your-subdomain` or `https://your-subdomain.loggly.com`). Replaced by LOGGLY_ACCOUNTS when that is set. | |
| MCP_BEARER_TOKEN | No | Bearer token gating access to the remote HTTP MCP server (`POST /mcp` requires `Authorization: Bearer <MCP_BEARER_TOKEN>`). Required when running the HTTP variant via `npm run start:http`. Treat as a secret. | |
| ABUSEIPDB_API_KEY | No | AbuseIPDB API key used by `ip_reputation` and `get_ip_context`. If missing, that source comes back as `available: false` rather than an error. | |
| GREYNOISE_API_KEY | No | GreyNoise API key used by `ip_reputation` and `get_ip_context`. If missing, that source comes back as `available: false` rather than an error. | |
| LOGGLY_FIELD_HOST | No | Override for the host field name used by the aggregation tools, instead of discovery-first field resolution. | |
| LOGGLY_FIELD_PATH | No | Override for the path field name used by the aggregation tools, instead of discovery-first field resolution. | |
| LOGGLY_SMOKE_TEST | No | Set to `1` to run the smoke test without Loggly credentials. | |
| LOGGLY_MAX_RETRIES | No | Maximum number of retries for transient failures (429, 500 with timeout-like body, 503, 504, or network timeouts). Default: `2`. | 2 |
| LOGGLY_FIELD_STATUS | No | Override for the status field name used by the aggregation tools, instead of discovery-first field resolution. | |
| LOGGLY_DEFAULT_ACCOUNT | No | Default account name used when a tool's optional `account` argument is omitted and LOGGLY_ACCOUNTS is set. | |
| LOGGLY_FIELD_USER_AGENT | No | Override for the user agent field name used by the aggregation tools, instead of discovery-first field resolution. | |
| LOGGLY_REQUEST_TIMEOUT_MS | No | Per-call request timeout in milliseconds. Default: `15000`. | 15000 |
| LOGGLY_MAX_CONCURRENT_REQUESTS | No | Caps how many fan-out requests the aggregation tools run at once per account. Default: `4`. | 4 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| connection_testB | Validates Loggly credentials by creating a small search and returning the RSID. |
| create_searchC | Creates a Loggly search and returns its RSID metadata. |
| get_eventsC | Retrieves event results for a previously-created RSID from /apiv2/events. |
| search_and_get_eventsC | Creates a search then fetches one page from legacy /apiv2/events using the returned RSID. |
| count_eventsD | Calls /apiv2/events/count to return event count and optional volume. |
| iterate_events_pageC | Calls /apiv2/events/iterate with query parameters and returns the first page plus |
| iterate_events_nextA | Fetches the next page from /apiv2/events/iterate using the exact |
| volume_metricsC | Calls /apiv2/volume-metrics to retrieve count/volume grouped or filtered by host/app/log type/tag. |
| stats_queryC | Calls /apiv2/stats// for numeric field statistics. |
| list_fieldsC | Calls /apiv2/fields/ to return parsed field names in the selected time range. |
| field_facetsC | Calls /apiv2/fields// to return terms and counts for a specific field. |
| raw_api_callC | Makes a GET request to a Loggly API path. Useful while discovering exact endpoint behavior. |
| search_logsA | Runs a query and returns an aggregated summary (total, top hosts/paths/status codes/user agents, a bucketed timeline, and a small representative sample) instead of raw events. Prefer this over get_events/iterate_events_* for exploratory analysis. |
| traffic_by_ipC | Aggregated traffic summary (see search_logs) scoped to a single IP address. |
| traffic_by_hostC | Aggregated traffic summary (see search_logs) scoped to a single hostname. |
| traffic_by_pathC | Aggregated traffic summary (see search_logs) scoped to a single request path. |
| group_by_ipC | Facet counts by IP for a query/time range (thin wrapper over field_facets). |
| group_by_pathC | Facet counts by path for a query/time range (thin wrapper over field_facets). |
| group_by_user_agentB | Facet counts by User-Agent for a query/time range (thin wrapper over field_facets). |
| timelineC | Bucketed event counts over a time range for a query, computed client-side from /apiv2/events/count. |
| sample_eventsA | Returns a small number of representative events for a query — use this instead of pulling full result pages when you just need examples, not the complete set. |
| rdap_lookupC | Looks up IP ownership/network registration data (RIR, netblock, org, country) via public RDAP (rdap.org) — no API key required. |
| ip_reputationA | Checks GreyNoise (internet-wide scanning noise) and AbuseIPDB (community abuse reports) for an IP. Requires GREYNOISE_API_KEY / ABUSEIPDB_API_KEY env vars — returns available:false for whichever isn't configured, rather than erroring. |
| get_ip_contextB | Combines RDAP, GreyNoise/AbuseIPDB reputation, and Loggly traffic (1h/24h/30d counts, first/last seen, hosts, top paths — checked across every configured Loggly account unless |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
| server-info | Loggly MCP server configuration and capability summary. |
| tools | All registered Loggly MCP tools and input metadata. |
| resource-templates | Parameterized resource URI templates supported by this server. |
| tool-connection_test | Validates Loggly credentials by creating a small search and returning the RSID. |
| tool-call-connection_test | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-create_search | Creates a Loggly search and returns its RSID metadata. |
| tool-call-create_search | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-get_events | Retrieves event results for a previously-created RSID from /apiv2/events. |
| tool-call-get_events | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-search_and_get_events | Creates a search then fetches one page from legacy /apiv2/events using the returned RSID. |
| tool-call-search_and_get_events | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-count_events | Calls /apiv2/events/count to return event count and optional volume. |
| tool-call-count_events | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-iterate_events_page | Calls /apiv2/events/iterate with query parameters and returns the first page plus `next` URL. |
| tool-call-iterate_events_page | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-iterate_events_next | Fetches the next page from /apiv2/events/iterate using the exact `next` URL returned by the previous page. |
| tool-call-iterate_events_next | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-volume_metrics | Calls /apiv2/volume-metrics to retrieve count/volume grouped or filtered by host/app/log type/tag. |
| tool-call-volume_metrics | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-stats_query | Calls /apiv2/stats/<stat_type>/<field> for numeric field statistics. |
| tool-call-stats_query | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-list_fields | Calls /apiv2/fields/ to return parsed field names in the selected time range. |
| tool-call-list_fields | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-field_facets | Calls /apiv2/fields/<field>/ to return terms and counts for a specific field. |
| tool-call-field_facets | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-raw_api_call | Makes a GET request to a Loggly API path. Useful while discovering exact endpoint behavior. |
| tool-call-raw_api_call | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-search_logs | Runs a query and returns an aggregated summary (total, top hosts/paths/status codes/user agents, a bucketed timeline, and a small representative sample) instead of raw events. Prefer this over get_events/iterate_events_* for exploratory analysis. |
| tool-call-search_logs | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-traffic_by_ip | Aggregated traffic summary (see search_logs) scoped to a single IP address. |
| tool-call-traffic_by_ip | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-traffic_by_host | Aggregated traffic summary (see search_logs) scoped to a single hostname. |
| tool-call-traffic_by_host | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-traffic_by_path | Aggregated traffic summary (see search_logs) scoped to a single request path. |
| tool-call-traffic_by_path | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-group_by_ip | Facet counts by IP for a query/time range (thin wrapper over field_facets). |
| tool-call-group_by_ip | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-group_by_path | Facet counts by path for a query/time range (thin wrapper over field_facets). |
| tool-call-group_by_path | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-group_by_user_agent | Facet counts by User-Agent for a query/time range (thin wrapper over field_facets). |
| tool-call-group_by_user_agent | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-timeline | Bucketed event counts over a time range for a query, computed client-side from /apiv2/events/count. |
| tool-call-timeline | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-sample_events | Returns a small number of representative events for a query — use this instead of pulling full result pages when you just need examples, not the complete set. |
| tool-call-sample_events | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-rdap_lookup | Looks up IP ownership/network registration data (RIR, netblock, org, country) via public RDAP (rdap.org) — no API key required. |
| tool-call-rdap_lookup | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-ip_reputation | Checks GreyNoise (internet-wide scanning noise) and AbuseIPDB (community abuse reports) for an IP. Requires GREYNOISE_API_KEY / ABUSEIPDB_API_KEY env vars — returns available:false for whichever isn't configured, rather than erroring. |
| tool-call-ip_reputation | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
| tool-get_ip_context | Combines RDAP, GreyNoise/AbuseIPDB reputation, and Loggly traffic (1h/24h/30d counts, first/last seen, hosts, top paths — checked across every configured Loggly account unless `account` is given) into one normalized profile for an IP. Flags cross_domain_correlation when the IP shows activity in more than one account, which the bot-traffic-triage playbook treats as the single strongest escalation signal. |
| tool-call-get_ip_context | Execute this tool via resources/read. Pass JSON object in ?arguments_json=... |
TDQS
Scored across 24 tools
There is real overlap: get_events, search_and_get_events, iterate_events_page/next, search_logs, and sample_events all retrieve event data, and the traffic_by_*/group_by_* families are near-identical variants differing only by dimension (some explicitly 'thin wrappers over field_facets'). The descriptions do provide guidance ('prefer this over...'), which prevents outright confusion, but an agent must read carefully to pick correctly.
All names use snake_case and are largely verb_noun or noun_verb forms (create_search, get_events, count_events, list_fields, sample_events, rdap_lookup). A few noun-first names (volume_metrics, field_facets, traffic_by_ip, timeline) deviate from the verb-first majority but remain readable and predictable.
24 tools is on the heavy end for a log-search server, and several families are redundant (traffic_by_ip/host/path, group_by_ip/path/user_agent) and could be collapsed into parameterized tools. It's justifiable but feels inflated by wrapper duplication.
The surface covers the core Loggly lifecycle well: credential check, search creation, event retrieval/iteration, counts, volume, stats, field listing/facets, plus aggregation helpers and external IP enrichment (RDAP, GreyNoise, AbuseIPDB, combined context). Minor gaps like saved-search management or write/delete operations exist but are outside the apparent read-only analytics scope.