Skip to main content
Glama

Related Servers

Alternatives to zeek-mcp

No user-submitted related servers found.

    Related Servers

    • A
      license
      Not graded
      quality
      C
      maintenance
      A Model Context Protocol server that integrates Zeek network analysis capabilities with LLM chatbots, allowing them to analyze PCAP files and parse network logs through natural language interactions.
      7
      Apache 2.0
    • A
      license
      A
      quality
      A
      maintenance
      An MCP server that connects language models to a Wazuh SIEM cluster, enabling read-only plain-language queries, schema inspection, field coverage analysis, and decoder testing.
      10
      Apache 2.0
    • F
      license
      B
      quality
      D
      maintenance
      A log analysis MCP server that enables tailing, searching, filtering, and summarizing logs from local files and Docker containers.
      7
      -
    • A
      license
      Not graded
      quality
      C
      maintenance
      An MCP server that enables querying logs and metrics from Graylog, Prometheus, and InfluxDB 2.x. It provides tools for executing Lucene log searches, PromQL queries, and Flux queries directly within MCP-compatible clients.
      MIT
    • F
      license
      Not graded
      quality
      D
      maintenance
      SuricataMCP is a Model Context Protocol Server that allows MCP clients to autonomously use suricata for network traffic analysis. It enables programmatic interaction with Suricata through tools like get\_suricata\_version, get\_suricata\_help, and get\_alerts\_from\_pcap\_file.
      14
      -
    • F
      license
      Not graded
      quality
      Not graded
      maintenance
      A production-oriented, read-only MCP server for secure ELK stack analysis, compatible with OpenClaw.
      -

    TDQS

    A3.7/5.0

    Scored across 39 tools

    Disambiguation5/5

    Tools are clearly organized by source (zeek, suricata, misp, thehive, pcap, nids) and action, with distinct purposes. Even within Zeek, query tools target specific log types and detection tools address different anomalies, minimizing confusion.

    Naming Consistency5/5

    All tool names follow a consistent pattern: source_prefix (zeek_, suricata_, misp_, etc.) followed by a verb or descriptor. Underscores and lowercase are used uniformly, making the set predictable and easy to navigate.

    Tool Count3/5

    With 39 tools, the server is heavily weighted, exceeding the typical well-scoped range. While the tools are justified by the breadth of NIDS functionality, the count is borderline high and may overwhelm agents.

    Completeness5/5

    The tool set covers the full lifecycle of network threat detection and response: data acquisition (pcap, logs), querying (all log types), anomaly detection, threat intelligence integration (MISP), case management (TheHive), and cross-referencing (Suricata-Zeek). No obvious gaps.

    Maintenance

    ActivitySlowing
    ResponsivenessSlow