graylog-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| GRAYLOG_URL | No | URL of the Graylog instance | |
| GRAYLOG_PROXY | No | Proxy URL for the env-only instance | |
| GRAYLOG_TOKEN | No | Access token of a read-only Graylog user | |
| GRAYLOG_PASSWORD | No | Password for basic auth instead of a token | |
| GRAYLOG_TIMEZONE | No | Display timezone and zone for naive times (default UTC) | UTC |
| GRAYLOG_USERNAME | No | Username for basic auth instead of a token | |
| GRAYLOG_CA_BUNDLE | No | Path to a CA bundle for TLS verification | |
| GRAYLOG_MCP_CONFIG | No | Path of a TOML config file | |
| GRAYLOG_VERIFY_TLS | No | TLS verification for the env-only instance | |
| GRAYLOG_APP_PACKAGES | No | Application packages for stack trace folding, e.g. com.acme,/srv/app/ | |
| GRAYLOG_MCP_HTTP_TOKEN | No | Bearer token required by the HTTP transport | |
| GRAYLOG_REDACTION_PACKS | No | Redaction packs to enable, e.g. vn,eu |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": false
} |
| prompts | {
"listChanged": false
} |
| resources | {
"subscribe": false,
"listChanged": false
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_logsA | Search log messages with a Lucene query. Returns compact, redacted lines with a 'ref' (index/id) usable by get_message and context_around. Default range: last 15 minutes. |
| count_logsA | Exact number of messages matching a query. Cheap; use it to size a problem. |
| get_messageB | One message with all its fields (redacted), by ref. |
| trace_requestA | Follow one request across services: searches the configured trace fields (falls back to full text) on all streams and returns a chronological timeline, per-service steps with durations, and the first error. |
| context_aroundC | Messages logged within ±N seconds of a given message. |
| error_summaryB | Group errors (configured error query) by exception, logger, source or any field, with exact counts, first/last seen and a sample message per group. |
| log_histogramA | Message counts over time (exact). Reports the peak bucket, first/last non-empty bucket and the 'onset' of a spike, to find when a problem started. |
| top_valuesB | Top N values of a field with exact counts and percentages. |
| compare_periodsA | Compare two periods (default: last window vs the one before; or around split_at). Lists groups that are new, increased, gone or decreased, normalised per hour. Defaults to errors only. |
| root_causeA | Find which service broke first and why. Compares every service's errors, traffic and latency with a baseline, pins the first error of each to the millisecond, detects deploys/restarts/host rollouts from the logs, infers the call graph from traces, and returns a ranked verdict with a timeline and evidence. Start here for 'what is causing this incident?'. |
| detect_changesB | Deploys and restarts found in the logs themselves: new values of version fields (app_version, build, commit...), host rollouts (new sources replacing old ones), and start/stop lines. No CI/CD integration needed. |
| service_mapA | Which service calls which, inferred from sampled traces (no configuration): edges with traffic, error rate and p50/p95 latency, plus entry points. |
| list_streamsB | Streams (id, title, description) the token can read. |
| list_fieldsA | Field names (and types where available) present in the indices, plus the configured trace fields and error query. Use before writing queries on unfamiliar logs. |
| list_presetsC | Named queries defined in the server configuration. |
| run_presetC | Run a named preset query, optionally overriding its arguments. |
| list_instancesB | Configured Graylog instances with detected version, the API used for messages and aggregations, and active redaction rules. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 17 tools
Each tool targets a distinct query or aggregation pattern (search, count, get, histogram, top values, trace, service map). The main overlap is that root_cause conceptually aggregates error_summary, compare_periods, detect_changes and service_map, which could make an agent unsure whether to use the composite or the individual tools, but descriptions clarify root_cause as the 'start here' entry point.
All names are snake_case with a consistent verb_noun or noun form (search_logs, count_logs, get_message, compare_periods). Some are noun phrases (error_summary, log_histogram, service_map) and others are verb-led, but the style is uniform and readable throughout.
17 tools is on the heavier side but justified for a rich observability domain covering search, aggregation, tracing, topology and infrastructure discovery. No tool appears redundant or purely decorative.
Covers the full investigation lifecycle: search/count/get/context, time-series and top-value aggregation, error grouping, period comparison, tracing, service topology, deploy detection, and discovery of streams/fields/instances/presets. Minor gaps exist (no alert or user/config management), but they are outside the core log-investigation purpose.