Skip to main content
Glama
weihong-xu-hpe

humio-mcp

HumioMCP

MCP server for querying Humio/LogScale dashboards and executing search queries.

Built with FastMCP (Python).

Features

  • list_dashboards — List all dashboards in a Humio repo/view, with optional name filtering

  • get_dashboard_queries — Extract all search queries (with time ranges) from a dashboard's widgets

  • execute_search — Run a search query and get results as JSON (default limit: 200 events)

  • Multi-cluster support via TOML config

  • Both relative time (24h, 7d) and ISO 8601 (2024-01-01T00:00:00Z) supported


Related MCP server: openobserve-community-mcp

Quick Start for Others

No clone needed. Add this to your VS Code settings.json or .vscode/mcp.json:

{
  "servers": {
    "humio-mcp": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "--from", "git+https://github.com/weihong-xu-hpe/humio-mcp.git",
        "humio-mcp"
      ],
      "env": {
        "HUMIO_MCP_CONFIG": "${userHome}/.config/humio-mcp/config.toml"
      }
    }
  }
}

Then create the config file at ~/.config/humio-mcp/config.toml:

default_cluster = "us-west-2"

[clusters.us-west-2]
url = "https://your-humio-url.example.com/logs"
token = "your-api-token"

That's it — uvx handles install and updates automatically.

Prerequisite: uv must be installed (brew install uv or curl -LsSf https://astral.sh/uv/install.sh | sh)

Option B: Clone and run locally

git clone https://github.com/weihong-xu-hpe/humio-mcp.git
cd humio-mcp
uv sync

cp config.example.toml config.toml
# Edit config.toml with your cluster URLs and API tokens

VS Code config for local clone:

{
  "servers": {
    "humio-mcp": {
      "type": "stdio",
      "command": "uv",
      "args": ["run", "--directory", "/path/to/HumioMCP", "humio-mcp"]
    }
  }
}

Option C: Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "humio-mcp": {
      "command": "uvx",
      "args": [
        "--from", "git+https://github.com/weihong-xu-hpe/humio-mcp.git",
        "humio-mcp"
      ],
      "env": {
        "HUMIO_MCP_CONFIG": "/Users/yourname/.config/humio-mcp/config.toml"
      }
    }
  }
}

Configuration

Edit config.toml (or ~/.config/humio-mcp/config.toml):

default_cluster = "us-west-2"

[clusters.us-west-2]
url = "https://mira-us-west-2.cloudops.ccs.arubathena.com/logs"
token = "your-api-token"

[clusters.eu-central-1]
url = "https://mira-eu-central-1.example.com/logs"
token = "another-token"

Config search order:

  1. HUMIO_MCP_CONFIG environment variable

  2. ./config.toml

  3. ~/.config/humio-mcp/config.toml

Development

# MCP Inspector (interactive debugging)
uv run fastmcp dev src/humio_mcp/server.py

# Stdio mode
uv run humio-mcp

Tools

list_dashboards

Param

Type

Required

Description

repo

str

Yes

Repository/view name

cluster

str

No

Cluster name (default from config)

search_filter

str

No

Filter by name substring

get_dashboard_queries

Param

Type

Required

Description

repo

str

Yes

Repository/view name

dashboard_name

str

Yes

Dashboard name

cluster

str

No

Cluster name

Param

Type

Required

Description

repo

str

Yes

Repository/view name

query_string

str

Yes

Humio search query

start

str

No

Start time (default: 24h)

end

str

No

End time (default: now)

cluster

str

No

Cluster name

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    C
    maintenance
    Enables querying and analyzing Falco security events from Falcosidekick UI through MCP tools. Supports filtering events by time windows and retrieving full event details for security monitoring and incident investigation.
    -
  • A
    license
    B
    quality
    C
    maintenance
    A read-only MCP server for OpenObserve Community Edition that works over the REST API. Provides tools for searching logs, traces, stream schemas, and dashboards - no Enterprise license required.
    8
    190 PyPI
    16
    GPL 3.0
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables MCP-compatible agents to interact with Grafana instances for searching, creating, and updating dashboards, exploring logs via Loki, querying datasources, managing alerts, incidents, and on-call shifts, and accessing observability data.
    8
    Apache 2.0
  • A
    license
    A
    quality
    C
    maintenance
    Enables querying logs, traces, and metrics from multiple OpenObserve instances via MCP tools, with parallel execution, batching, and caching.
    6
    89 npm
    9
    MIT