wazuh-mcp
Related Servers
Alternatives to wazuh-mcp
No user-submitted related servers found.
Related Servers
- AlicenseNot gradedqualityDmaintenanceEnables integration between Wazuh security platform and AI applications through the MCP framework, providing tools for security analysis, agent management, and system monitoring.4MIT
- AlicenseNot gradedqualityBmaintenanceEnables incident responders to query and correlate observability and DevOps evidence across Grafana, Prometheus, Loki, Uptime Kuma, CloudWatch, IAM, and PostHog from a local MCP client, with bounded reads and redacted audit records.MIT
- AlicenseAqualityCmaintenanceEnables any MCP-compatible agent to query, diagnose, map, and operate Elasticsearch or OpenSearch clusters via REST, with read-only defaults and layered safety controls.34Apache 2.0
- AlicenseNot gradedqualityAmaintenanceEnables local MCP access to attach to isolated backend environments, monitor runtime health/logs, check security posture, manage snapshots and diffs, audit events, and view sanitized remote inventory.9 npmApache 2.0
- AlicenseNot gradedqualityBmaintenanceEnables MCP clients to query homelab infrastructure such as Proxmox VE, NetBox, systemd services, Grafana, InfluxDB, AdGuard Home, ping logs, and configured HTTP JSON endpoints through read-only tools.AGPL 3.0
- AlicenseAqualityCmaintenanceEnables querying logs, traces, and metrics from multiple OpenObserve instances via MCP tools, with parallel execution, batching, and caching.646 npm11MIT
TDQS
Scored across 34 tools
Most tools target a distinct resource (alerts, agents, rules, SCA, FIM, vulnerabilities), but several overlap: wazuh_health, wazuh_cluster_status, and wazuh_agent_summary all describe health/status, and wazuh_search_alerts, wazuh_alert_stats, wazuh_alert_timeline, and wazuh_indexer_query all query alert data. The descriptions are clear enough to avoid most misselections, but the boundaries are not crisp.
All names share the wazuh_ prefix and snake_case, but the action pattern is inconsistent: some are verb-first (search_alerts, list_agents, generate_report), some are bare nouns (health, rootcheck, vulnerabilities), and some are noun phrases (cluster_status, agent_summary). A uniform verb_noun convention would make the set more predictable.
34 tools is well above the 25+ threshold and makes the surface feel heavy; several status/stat tools could be consolidated and two escape hatches cover long-tail needs. Wazuh is a broad platform, but this count will increase token overhead and selection difficulty.
The set covers the main Wazuh operations well: alert search, agent health, SCA/FIM/inventory, vulnerability lookup, rule/decoder reference, reporting, and active response. Minor gaps exist (no agent-group assignment, no rule/decoder editing, no alert triage/acknowledge), but the read-only API escape hatch and the breadth of purpose-built tools keep workflows from hitting dead ends.