ndjson-local-log-triage-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| query_log_patternA | Filter NDJSON log file by field/value pattern, return top N matching entries. |
| detect_error_anomaliesB | Z-score frequency analysis to find sudden error spikes by time window. |
| summarize_log_timelineA | Chronological severity aggregation — errors, warnings, and info counts per time window. |
| correlate_requestA | Reconstruct a distributed trace by collecting all log events matching a trace/request ID across multiple NDJSON files, sorted chronologically. |
| discover_log_schemaB | Analyze a log file to infer format and type schemas, including key type polymorphism and regex patterns for timestamps. |
| group_semantic_patternsA | Cluster similar log messages using Drain algorithm to isolate core events and parameter distributions. |
| start_live_triageA | Start background log tailing with real-time Z-score anomaly alerting and heap memory safety limits. |
| query_external_logsA | Query external log providers (Datadog, Splunk, Elasticsearch) translating search patterns and mapping to OpenTelemetry format. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 8 tools
Tools target distinct operations: schema exploration, pattern querying, anomaly detection, timeline summary, request correlation, semantic clustering, live monitoring, and external integration. Some minor overlap exists between static anomaly detection and live triage, but descriptions clarify the static vs. real-time contexts.
All tool names follow a consistent verb_noun pattern using snake_case, with clear action verbs (discover, query, detect, summarize, correlate, group, start). Even the two query tools are distinguished by their target (local pattern vs. external providers).
8 tools is well within the optimal range for a log triage server, covering analysis, querying, aggregation, correlation, clustering, live monitoring, and external access without being excessive or sparse.
The tool set covers the core triage lifecycle: schema discovery, querying, anomaly detection, timeline summary, trace correlation, semantic grouping, live monitoring, and external log retrieval. Notable gaps include the absence of a stop/control tool for live triage and a dedicated raw context retrieval by log ID, but these are minor and workable.