mcp-syslog
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| SYSLOG_LOG_ROOT | No | Collector log root, mounted read-only | /logs |
| SYSLOG_SCAN_LIMIT | No | Cap on lines examined per call | 2000000 |
| SYSLOG_MAX_RESULTS | No | Cap on entries returned per call | 200 |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| logging | {} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| syslog_sources_toolA | List log sources available to query, with size and last-write time. |
| syslog_search_toolC | Search collected logs by source, time window, severity and pattern. |
| syslog_grep_toolC | Regex search across all sources, or within one named source. |
| syslog_tail_toolC | Return the most recent entries for one source. |
| syslog_context_toolA | Return log entries surrounding a specific moment. Use this after an alert names a time. Omitting source spans the whole fleet, which is how a failure gets correlated with whatever else was happening. |
| syslog_stats_toolA | Summarise log volume and error rate per source. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 6 tools
Most tools target distinct operations: listing sources, tailing, stats, and context retrieval are clearly separated. However, syslog_search_tool (pattern search) and syslog_grep_tool (regex search across/within sources) overlap substantially and an agent could easily pick the wrong one for a pattern-matching query.
All six tools use the identical syslog_<action>_tool convention, making the pattern predictable and easy to scan. The redundant '_tool' suffix is uniform, so it does not hinder consistency.
Six tools is well-scoped for a log-query server, each covering a distinct access pattern (discovery, search, grep, tail, aggregate, context). No filler or redundancy beyond the search/grep overlap.
The surface covers the core log-investigation lifecycle: discovering sources, filtering, tailing, aggregating, and contextual surrounding entries. Minor gaps exist, such as no explicit pagination/offset control or config/retention management, but agents can work around these.