Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
LOGGLY_TOKENNoLoggly API token. Replaced by LOGGLY_ACCOUNTS when that is set.
MCP_HTTP_PORTNoPort for the stateless Streamable HTTP MCP server. Default: `8787`.8787
LOGGLY_ACCOUNTSNoJSON object mapping an account name to its credentials, e.g. {"acme":{"subdomain":"acme","token":"acme_token","authMode":"bearer"},"beta":{"subdomain":"beta","token":"beta_token"}}. When set, it replaces LOGGLY_SUBDOMAIN/LOGGLY_TOKEN/LOGGLY_AUTH_MODE and every tool accepts an optional `account` argument.
LOGGLY_FIELD_IPNoOverride for the IP field name used by the aggregation tools, instead of discovery-first field resolution.
LOGGLY_AUTH_MODENoLoggly authentication mode: `bearer` (default) or `basic`. Replaced by LOGGLY_ACCOUNTS when that is set.bearer
LOGGLY_LOG_LEVELNoLog verbosity: `error`, `warn`, `info` (default), or `debug`. Logs are written to stderr.info
LOGGLY_SUBDOMAINNoLoggly account subdomain or full Loggly URL (e.g. `your-subdomain` or `https://your-subdomain.loggly.com`). Replaced by LOGGLY_ACCOUNTS when that is set.
MCP_BEARER_TOKENNoBearer token gating access to the remote HTTP MCP server (`POST /mcp` requires `Authorization: Bearer <MCP_BEARER_TOKEN>`). Required when running the HTTP variant via `npm run start:http`. Treat as a secret.
ABUSEIPDB_API_KEYNoAbuseIPDB API key used by `ip_reputation` and `get_ip_context`. If missing, that source comes back as `available: false` rather than an error.
GREYNOISE_API_KEYNoGreyNoise API key used by `ip_reputation` and `get_ip_context`. If missing, that source comes back as `available: false` rather than an error.
LOGGLY_FIELD_HOSTNoOverride for the host field name used by the aggregation tools, instead of discovery-first field resolution.
LOGGLY_FIELD_PATHNoOverride for the path field name used by the aggregation tools, instead of discovery-first field resolution.
LOGGLY_SMOKE_TESTNoSet to `1` to run the smoke test without Loggly credentials.
LOGGLY_MAX_RETRIESNoMaximum number of retries for transient failures (429, 500 with timeout-like body, 503, 504, or network timeouts). Default: `2`.2
LOGGLY_FIELD_STATUSNoOverride for the status field name used by the aggregation tools, instead of discovery-first field resolution.
LOGGLY_DEFAULT_ACCOUNTNoDefault account name used when a tool's optional `account` argument is omitted and LOGGLY_ACCOUNTS is set.
LOGGLY_FIELD_USER_AGENTNoOverride for the user agent field name used by the aggregation tools, instead of discovery-first field resolution.
LOGGLY_REQUEST_TIMEOUT_MSNoPer-call request timeout in milliseconds. Default: `15000`.15000
LOGGLY_MAX_CONCURRENT_REQUESTSNoCaps how many fan-out requests the aggregation tools run at once per account. Default: `4`.4

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}
resources
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
connection_testB

Validates Loggly credentials by creating a small search and returning the RSID.

create_searchC

Creates a Loggly search and returns its RSID metadata.

get_eventsC

Retrieves event results for a previously-created RSID from /apiv2/events.

search_and_get_eventsC

Creates a search then fetches one page from legacy /apiv2/events using the returned RSID.

count_eventsD

Calls /apiv2/events/count to return event count and optional volume.

iterate_events_pageC

Calls /apiv2/events/iterate with query parameters and returns the first page plus next URL.

iterate_events_nextA

Fetches the next page from /apiv2/events/iterate using the exact next URL returned by the previous page.

volume_metricsC

Calls /apiv2/volume-metrics to retrieve count/volume grouped or filtered by host/app/log type/tag.

stats_queryC

Calls /apiv2/stats// for numeric field statistics.

list_fieldsC

Calls /apiv2/fields/ to return parsed field names in the selected time range.

field_facetsC

Calls /apiv2/fields// to return terms and counts for a specific field.

raw_api_callC

Makes a GET request to a Loggly API path. Useful while discovering exact endpoint behavior.

search_logsA

Runs a query and returns an aggregated summary (total, top hosts/paths/status codes/user agents, a bucketed timeline, and a small representative sample) instead of raw events. Prefer this over get_events/iterate_events_* for exploratory analysis.

traffic_by_ipC

Aggregated traffic summary (see search_logs) scoped to a single IP address.

traffic_by_hostC

Aggregated traffic summary (see search_logs) scoped to a single hostname.

traffic_by_pathC

Aggregated traffic summary (see search_logs) scoped to a single request path.

group_by_ipC

Facet counts by IP for a query/time range (thin wrapper over field_facets).

group_by_pathC

Facet counts by path for a query/time range (thin wrapper over field_facets).

group_by_user_agentB

Facet counts by User-Agent for a query/time range (thin wrapper over field_facets).

timelineC

Bucketed event counts over a time range for a query, computed client-side from /apiv2/events/count.

sample_eventsA

Returns a small number of representative events for a query — use this instead of pulling full result pages when you just need examples, not the complete set.

rdap_lookupC

Looks up IP ownership/network registration data (RIR, netblock, org, country) via public RDAP (rdap.org) — no API key required.

ip_reputationA

Checks GreyNoise (internet-wide scanning noise) and AbuseIPDB (community abuse reports) for an IP. Requires GREYNOISE_API_KEY / ABUSEIPDB_API_KEY env vars — returns available:false for whichever isn't configured, rather than erroring.

get_ip_contextB

Combines RDAP, GreyNoise/AbuseIPDB reputation, and Loggly traffic (1h/24h/30d counts, first/last seen, hosts, top paths — checked across every configured Loggly account unless account is given) into one normalized profile for an IP. Flags cross_domain_correlation when the IP shows activity in more than one account, which the bot-traffic-triage playbook treats as the single strongest escalation signal.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription
server-infoLoggly MCP server configuration and capability summary.
toolsAll registered Loggly MCP tools and input metadata.
resource-templatesParameterized resource URI templates supported by this server.
tool-connection_testValidates Loggly credentials by creating a small search and returning the RSID.
tool-call-connection_testExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-create_searchCreates a Loggly search and returns its RSID metadata.
tool-call-create_searchExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-get_eventsRetrieves event results for a previously-created RSID from /apiv2/events.
tool-call-get_eventsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-search_and_get_eventsCreates a search then fetches one page from legacy /apiv2/events using the returned RSID.
tool-call-search_and_get_eventsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-count_eventsCalls /apiv2/events/count to return event count and optional volume.
tool-call-count_eventsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-iterate_events_pageCalls /apiv2/events/iterate with query parameters and returns the first page plus `next` URL.
tool-call-iterate_events_pageExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-iterate_events_nextFetches the next page from /apiv2/events/iterate using the exact `next` URL returned by the previous page.
tool-call-iterate_events_nextExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-volume_metricsCalls /apiv2/volume-metrics to retrieve count/volume grouped or filtered by host/app/log type/tag.
tool-call-volume_metricsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-stats_queryCalls /apiv2/stats/<stat_type>/<field> for numeric field statistics.
tool-call-stats_queryExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-list_fieldsCalls /apiv2/fields/ to return parsed field names in the selected time range.
tool-call-list_fieldsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-field_facetsCalls /apiv2/fields/<field>/ to return terms and counts for a specific field.
tool-call-field_facetsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-raw_api_callMakes a GET request to a Loggly API path. Useful while discovering exact endpoint behavior.
tool-call-raw_api_callExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-search_logsRuns a query and returns an aggregated summary (total, top hosts/paths/status codes/user agents, a bucketed timeline, and a small representative sample) instead of raw events. Prefer this over get_events/iterate_events_* for exploratory analysis.
tool-call-search_logsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-traffic_by_ipAggregated traffic summary (see search_logs) scoped to a single IP address.
tool-call-traffic_by_ipExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-traffic_by_hostAggregated traffic summary (see search_logs) scoped to a single hostname.
tool-call-traffic_by_hostExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-traffic_by_pathAggregated traffic summary (see search_logs) scoped to a single request path.
tool-call-traffic_by_pathExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-group_by_ipFacet counts by IP for a query/time range (thin wrapper over field_facets).
tool-call-group_by_ipExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-group_by_pathFacet counts by path for a query/time range (thin wrapper over field_facets).
tool-call-group_by_pathExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-group_by_user_agentFacet counts by User-Agent for a query/time range (thin wrapper over field_facets).
tool-call-group_by_user_agentExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-timelineBucketed event counts over a time range for a query, computed client-side from /apiv2/events/count.
tool-call-timelineExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-sample_eventsReturns a small number of representative events for a query — use this instead of pulling full result pages when you just need examples, not the complete set.
tool-call-sample_eventsExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-rdap_lookupLooks up IP ownership/network registration data (RIR, netblock, org, country) via public RDAP (rdap.org) — no API key required.
tool-call-rdap_lookupExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-ip_reputationChecks GreyNoise (internet-wide scanning noise) and AbuseIPDB (community abuse reports) for an IP. Requires GREYNOISE_API_KEY / ABUSEIPDB_API_KEY env vars — returns available:false for whichever isn't configured, rather than erroring.
tool-call-ip_reputationExecute this tool via resources/read. Pass JSON object in ?arguments_json=...
tool-get_ip_contextCombines RDAP, GreyNoise/AbuseIPDB reputation, and Loggly traffic (1h/24h/30d counts, first/last seen, hosts, top paths — checked across every configured Loggly account unless `account` is given) into one normalized profile for an IP. Flags cross_domain_correlation when the IP shows activity in more than one account, which the bot-traffic-triage playbook treats as the single strongest escalation signal.
tool-call-get_ip_contextExecute this tool via resources/read. Pass JSON object in ?arguments_json=...

TDQS

C2.7/5.0

Scored across 24 tools

Disambiguation3/5

There is real overlap: get_events, search_and_get_events, iterate_events_page/next, search_logs, and sample_events all retrieve event data, and the traffic_by_*/group_by_* families are near-identical variants differing only by dimension (some explicitly 'thin wrappers over field_facets'). The descriptions do provide guidance ('prefer this over...'), which prevents outright confusion, but an agent must read carefully to pick correctly.

Naming Consistency4/5

All names use snake_case and are largely verb_noun or noun_verb forms (create_search, get_events, count_events, list_fields, sample_events, rdap_lookup). A few noun-first names (volume_metrics, field_facets, traffic_by_ip, timeline) deviate from the verb-first majority but remain readable and predictable.

Tool Count3/5

24 tools is on the heavy end for a log-search server, and several families are redundant (traffic_by_ip/host/path, group_by_ip/path/user_agent) and could be collapsed into parameterized tools. It's justifiable but feels inflated by wrapper duplication.

Completeness4/5

The surface covers the core Loggly lifecycle well: credential check, search creation, event retrieval/iteration, counts, volume, stats, field listing/facets, plus aggregation helpers and external IP enrichment (RDAP, GreyNoise, AbuseIPDB, combined context). Minor gaps like saved-search management or write/delete operations exist but are outside the apparent read-only analytics scope.

Maintenance

ActivityMaintained
ResponsivenessNo issues