Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
GRAYLOG_URLNoURL of the Graylog instance
GRAYLOG_PROXYNoProxy URL for the env-only instance
GRAYLOG_TOKENNoAccess token of a read-only Graylog user
GRAYLOG_PASSWORDNoPassword for basic auth instead of a token
GRAYLOG_TIMEZONENoDisplay timezone and zone for naive times (default UTC)UTC
GRAYLOG_USERNAMENoUsername for basic auth instead of a token
GRAYLOG_CA_BUNDLENoPath to a CA bundle for TLS verification
GRAYLOG_MCP_CONFIGNoPath of a TOML config file
GRAYLOG_VERIFY_TLSNoTLS verification for the env-only instance
GRAYLOG_APP_PACKAGESNoApplication packages for stack trace folding, e.g. com.acme,/srv/app/
GRAYLOG_MCP_HTTP_TOKENNoBearer token required by the HTTP transport
GRAYLOG_REDACTION_PACKSNoRedaction packs to enable, e.g. vn,eu

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
prompts
{
  "listChanged": false
}
resources
{
  "subscribe": false,
  "listChanged": false
}

Tools

Functions exposed to the LLM to take actions

NameDescription
search_logsA

Search log messages with a Lucene query. Returns compact, redacted lines with a 'ref' (index/id) usable by get_message and context_around. Default range: last 15 minutes.

count_logsA

Exact number of messages matching a query. Cheap; use it to size a problem.

get_messageB

One message with all its fields (redacted), by ref.

trace_requestA

Follow one request across services: searches the configured trace fields (falls back to full text) on all streams and returns a chronological timeline, per-service steps with durations, and the first error.

context_aroundC

Messages logged within ±N seconds of a given message.

error_summaryB

Group errors (configured error query) by exception, logger, source or any field, with exact counts, first/last seen and a sample message per group.

log_histogramA

Message counts over time (exact). Reports the peak bucket, first/last non-empty bucket and the 'onset' of a spike, to find when a problem started.

top_valuesB

Top N values of a field with exact counts and percentages.

compare_periodsA

Compare two periods (default: last window vs the one before; or around split_at). Lists groups that are new, increased, gone or decreased, normalised per hour. Defaults to errors only.

root_causeA

Find which service broke first and why. Compares every service's errors, traffic and latency with a baseline, pins the first error of each to the millisecond, detects deploys/restarts/host rollouts from the logs, infers the call graph from traces, and returns a ranked verdict with a timeline and evidence. Start here for 'what is causing this incident?'.

detect_changesB

Deploys and restarts found in the logs themselves: new values of version fields (app_version, build, commit...), host rollouts (new sources replacing old ones), and start/stop lines. No CI/CD integration needed.

service_mapA

Which service calls which, inferred from sampled traces (no configuration): edges with traffic, error rate and p50/p95 latency, plus entry points.

list_streamsB

Streams (id, title, description) the token can read.

list_fieldsA

Field names (and types where available) present in the indices, plus the configured trace fields and error query. Use before writing queries on unfamiliar logs.

list_presetsC

Named queries defined in the server configuration.

run_presetC

Run a named preset query, optionally overriding its arguments.

list_instancesB

Configured Graylog instances with detected version, the API used for messages and aggregations, and active redaction rules.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.3/5.0

Scored across 17 tools

Disambiguation4/5

Each tool targets a distinct query or aggregation pattern (search, count, get, histogram, top values, trace, service map). The main overlap is that root_cause conceptually aggregates error_summary, compare_periods, detect_changes and service_map, which could make an agent unsure whether to use the composite or the individual tools, but descriptions clarify root_cause as the 'start here' entry point.

Naming Consistency4/5

All names are snake_case with a consistent verb_noun or noun form (search_logs, count_logs, get_message, compare_periods). Some are noun phrases (error_summary, log_histogram, service_map) and others are verb-led, but the style is uniform and readable throughout.

Tool Count4/5

17 tools is on the heavier side but justified for a rich observability domain covering search, aggregation, tracing, topology and infrastructure discovery. No tool appears redundant or purely decorative.

Completeness4/5

Covers the full investigation lifecycle: search/count/get/context, time-series and top-value aggregation, error grouping, period comparison, tracing, service topology, deploy detection, and discovery of streams/fields/instances/presets. Minor gaps exist (no alert or user/config management), but they are outside the core log-investigation purpose.

Maintenance

ActivityMaintained
ResponsivenessNo issues