Skip to main content
Glama
rnd-rtcyber

Wazuh 5 MCP Server (Wrapper)

by rnd-rtcyber

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault
MCP_BINDNoBind address for Docker Compose (optional, default 127.0.0.1)
MCP_HOSTNoHost to bind the MCP server (optional)0.0.0.0
MCP_PORTNoPort to bind the MCP server (optional)3000
AUTH_MODENoAuthentication mode (optional)bearer
WAZUH_HOSTYesWazuh manager host (required, always)
WAZUH_PASSYesWazuh API password (required, always)
WAZUH_PORTNoWazuh manager port (optional)55000
WAZUH_USERYesWazuh API user (required, always)
ENVIRONMENTNoEnvironment mode (e.g., production) (optional)
MCP_API_KEYNoFixed API key (optional; auto-generated and logged on startup if unset)
WAZUH5_HOSTNoWazuh 5 host (optional, enables Wazuh 5 tools)
WAZUH5_PASSNoWazuh 5 password (optional)
WAZUH5_PORTNoWazuh 5 manager port (optional)55000
WAZUH5_USERNoWazuh 5 user (optional)
MCP_TUNNEL_CMDNoCommand to run a custom tunnel (optional, for start.bat)
AUTH_SECRET_KEYNoSecret key for JWT signing (required in ENVIRONMENT=production; run openssl rand -hex 32)
RESPONSE_FORMATNoResponse format (e.g., gcf for compact encoding) (optional)
WAZUH_INDEXER_HOSTNoWazuh Indexer host (optional, enables 4.x alert/vulnerability tools)
WAZUH_INDEXER_PASSNoWazuh Indexer password (optional)
WAZUH_INDEXER_PORTNoWazuh Indexer port (optional)9200
WAZUH_INDEXER_USERNoWazuh Indexer user (optional)
WAZUH5_INDEXER_HOSTNoWazuh 5 Indexer host (optional, defaults to WAZUH5_HOST)
WAZUH5_INDEXER_PASSNoWazuh 5 Indexer password (optional)
WAZUH5_INDEXER_PORTNoWazuh 5 Indexer port (optional)9200
WAZUH5_INDEXER_USERNoWazuh 5 Indexer user (optional)
MCP_TUNNEL_URL_REGEXNoRegex to extract public URL from tunnel output (optional)
WAZUH5_DASHBOARD_HOSTNoWazuh 5 Dashboard host (optional, defaults to Indexer values)
WAZUH5_DASHBOARD_PASSNoWazuh 5 Dashboard password (optional)
WAZUH5_DASHBOARD_PORTNoWazuh 5 Dashboard port (optional)443
WAZUH5_DASHBOARD_USERNoWazuh 5 Dashboard user (optional)
WAZUH_REQUIRE_ACTION_CONFIRMATIONNoRequire confirmation for write actions (optional)

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Server capabilities have not been inspected yet.

Tools

Functions exposed to the LLM to take actions

NameDescription

No tools

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources