Skip to main content
Glama
gensecaihq

pfSense MCP Server

by gensecaihq

get_log_file

Read-only

Retrieve the newest lines from pfSense log files (dhcpd, filter, resolver, system, auth) with an optional grep filter. Provides recent log data for troubleshooting, including logs not exposed by the REST API.

Instructions

Read the newest lines from a pfSense log file (dhcpd, filter, resolver, system, auth).

Reads the plain-text log file server-side with tail (and grep when a pattern is given), so it works for log types the REST API log endpoints don't expose (notably resolver) and avoids the known server-side OOM bug on /status/logs/ endpoints.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
grepNoOptional fixed-string filter applied before tail, so the newest matching lines are returned rather than matches within the newest lines
linesNoNumber of newest lines to return (default 100, max 1000)
log_fileYesWhich log to read (dhcpd, filter, resolver, system, auth)

Output Schema

TableJSON Schema
NameRequiredDescriptionDefault

No arguments

Schema Changelog

Changes observed during successful MCP inspections.

  1. Addedv1.1.0

TDQS

A4.5/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already declare readOnlyHint=true and destructiveHint=false, covering the safety profile. The description adds valuable behavioral context: it reads the plain-text file server-side with tail (and grep when a pattern is given), and explains the grep-before-tail ordering so the agent understands the semantics of returned results. This goes beyond what annotations provide, though it does not describe potential performance characteristics of large files or response size limits, which are minor given the output schema.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is two sentences with no filler. The first sentence states the purpose and scope, and the second provides implementation detail and the rationale for using this tool, all front-loaded and relevant.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness5/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a read-only tool with full schema descriptions, a readOnlyHint annotation, and an output schema, the description sufficiently covers what an agent needs: what the tool does, which log files it supports, why it exists (resolver coverage, OOM avoidance), and how filtering behaves. Nothing essential is missing.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, so the baseline is 3 because the schema already documents each parameter thoroughly. The description's mention of tail and grep when a pattern is given merely reinforces the schema's existing description of the grep parameter. No additional parameter-level meaning is added, so a 3 is appropriate.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description starts with a specific verb and resource: 'Read the newest lines from a pfSense log file' and enumerates the valid log types (dhcpd, filter, resolver, system, auth). It also distinguishes this tool from the REST API log endpoints by noting it covers log types like resolver that the API does not expose, so an agent can differentiate it without opening the schema.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines5/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explicitly states when to prefer this tool: for log types the REST API log endpoints don't expose (notably resolver) and to avoid the known OOM bug on /status/logs/ endpoints. This gives an agent concrete selection criteria relative to alternatives, even though sibling tools are not named individually.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Deploy Server

Other Tools