AcademyMCP serversOperations

Wazuh MCP Server

IT and security operations teams that want to query Wazuh alerts and agent health by asking questions in natural language.

  • Recommendedour rating
  • 239gitHub stars
  • MITlicence
  • 10 months agolast update
claude mcp add wazuh -e WAZUH_API_HOST=your_wazuh_manager_api_host -e WAZUH_API_PORT=55000 -e WAZUH_API_USERNAME=your_wazuh_api_user -e WAZUH_API_PASSWORD=your_wazuh_api_password -e WAZUH_INDEXER_HOST=your_wazuh_indexer_host -e WAZUH_INDEXER_PORT=9200 -e WAZUH_INDEXER_USERNAME=your_wazuh_indexer_user -e WAZUH_INDEXER_PASSWORD=your_wazuh_indexer_password -e WAZUH_VERIFY_SSL=false -e WAZUH_TEST_PROTOCOL=https -e RUST_LOG=info -- /path/to/mcp-server-wazuh
README.md

Loading the file...

What it does

A Rust-based MCP server that connects Claude Desktop to a Wazuh SIEM. It gives your assistant access to security alerts, agent status, vulnerability data, rules, statistics and logs, so you can ask about your security environment in plain language instead of calling the API by hand.

Use cases

  1. 01Ask for the latest security alerts
  2. 02Check the health of Wazuh agents
  3. 03Review vulnerability data for patch priorities

Questions about
Wazuh MCP Server.

What is Wazuh MCP Server used for?

IT and security operations teams that want to query Wazuh alerts and agent health by asking questions in natural language. A Rust-based MCP server that connects Claude Desktop to a Wazuh SIEM. It gives your assistant access to security alerts, agent status, vulnerability data, rules, statistics and logs, so you can ask about your security environment in plain language instead of calling the API by hand.

How do I install Wazuh MCP Server?

Run this in your terminal: claude mcp add wazuh -e WAZUH_API_HOST=your_wazuh_manager_api_host -e WAZUH_API_PORT=55000 -e WAZUH_API_USERNAME=your_wazuh_api_user -e WAZUH_API_PASSWORD=your_wazuh_api_password -e WAZUH_INDEXER_HOST=your_wazuh_indexer_host -e WAZUH_INDEXER_PORT=9200 -e WAZUH_INDEXER_USERNAME=your_wazuh_indexer_user -e WAZUH_INDEXER_PASSWORD=your_wazuh_indexer_password -e WAZUH_VERIFY_SSL=false -e WAZUH_TEST_PROTOCOL=https -e RUST_LOG=info -- /path/to/mcp-server-wazuh

Is Wazuh MCP Server open source?

Yes. The code is on GitHub (gbrigandi/mcp-server-wazuh) under the MIT licence.

Is Wazuh MCP Server safe to use?

It passed our automatic scan for credential theft, hidden instructions and risky install commands. Third party open source software. Sabemos AI does not maintain it. Check the code and permissions before you connect it to company data.