Skip to main content
Glama
vola-trebla

ndjson-local-log-triage-mcp

by vola-trebla

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": true
}

Tools

Functions exposed to the LLM to take actions

NameDescription
query_log_patternA

Filter NDJSON log file by field/value pattern, return top N matching entries.

detect_error_anomaliesB

Z-score frequency analysis to find sudden error spikes by time window.

summarize_log_timelineA

Chronological severity aggregation — errors, warnings, and info counts per time window.

correlate_requestA

Reconstruct a distributed trace by collecting all log events matching a trace/request ID across multiple NDJSON files, sorted chronologically.

discover_log_schemaB

Analyze a log file to infer format and type schemas, including key type polymorphism and regex patterns for timestamps.

group_semantic_patternsA

Cluster similar log messages using Drain algorithm to isolate core events and parameter distributions.

start_live_triageA

Start background log tailing with real-time Z-score anomaly alerting and heap memory safety limits.

query_external_logsA

Query external log providers (Datadog, Splunk, Elasticsearch) translating search patterns and mapping to OpenTelemetry format.

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

A3.8/5.0

Scored across 8 tools

Disambiguation4/5

Tools target distinct operations: schema exploration, pattern querying, anomaly detection, timeline summary, request correlation, semantic clustering, live monitoring, and external integration. Some minor overlap exists between static anomaly detection and live triage, but descriptions clarify the static vs. real-time contexts.

Naming Consistency5/5

All tool names follow a consistent verb_noun pattern using snake_case, with clear action verbs (discover, query, detect, summarize, correlate, group, start). Even the two query tools are distinguished by their target (local pattern vs. external providers).

Tool Count5/5

8 tools is well within the optimal range for a log triage server, covering analysis, querying, aggregation, correlation, clustering, live monitoring, and external access without being excessive or sparse.

Completeness4/5

The tool set covers the core triage lifecycle: schema discovery, querying, anomaly detection, timeline summary, trace correlation, semantic grouping, live monitoring, and external log retrieval. Notable gaps include the absence of a stop/control tool for live triage and a dedicated raw context retrieval by log ID, but these are minor and workable.

Maintenance

ActivityInactive
ResponsivenessUnresponsive