Skip to main content
AllMCPs
BrowseBestCategoriesStackCompareToolsGuidesBlog
Log in Submit MCP

Stay in the loop

Get new MCP servers and top picks in your inbox.

AllMCPs

The open directory for discovering and installing Model Context Protocol servers.

AllMCPs on GitHub (opens in a new tab)
Launched onTiny Startupstinystartups.com
Explore
  • Browse servers
  • Best MCP servers
  • Categories
  • MCP clients
  • Agent prompts
  • Stack Builder
  • Compare servers
  • Random discovery New
  • Submit a server
  • Pricing & Boost Boost
Learn
  • Guides hub
  • What is MCP?
  • Install guide
  • Build an MCP server
  • Deploy an MCP server
  • Security guide
  • Troubleshooting
  • MCP for SEO & AEO
  • Protocol versioning
  • Blog & updates
Tools
  • All developer tools
  • Config generator
  • Config validator
  • Config auditor
  • MCP playground
  • Token calculator
  • OpenAPI β†’ MCP
  • Badge generator
For agents
  • REST API docs
  • Trust & traffic Live
  • Remote MCP server SSE β†— (opens in a new tab)
  • llms.txt β†— (opens in a new tab)
  • Catalog JSON β†— (opens in a new tab)
Company
  • About
  • Advertise Sponsor
  • Contact
  • GitHub β†— (opens in a new tab)
  • Terms
  • Privacy
AllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZoneAllMCPs VerifiedAllMCPs VerifiedFeatured on Nick LaunchesFeatured on Nick LaunchesLaunch Llama NewsletterLaunch Llama NewsletterVerified DR - allmcps.comVerified DR - allmcps.comFeatured on SaaSGrowFeatured on SaaSGrowFeatured on Twelve ToolsFeatured on Twelve ToolsFeatured on Saaspa.geFeatured on Saaspa.geFeatured on Findly.toolsFeatured on Findly.toolsFeatured on Startup FameFeatured on Startup FameFeatured on LaunchKiwiFeatured on LaunchKiwiFeatured on ScrollLaunchFeatured on ScrollLaunchFeatured on DailyPingsFeatured on DailyPingsFazier badgeFazier badgeFeatured on NewTool.siteFeatured on NewTool.siteFeatured on saasfame.comFeatured on saasfame.comDR Checker - Domain RatingDR Checker - Domain RatingListed on Turbo0Listed on Turbo0Launched on LaunchBoard - Product Launch PlatformLaunched on LaunchBoard - Product Launch PlatformList on SimilarlabsList on Similarlabshttps://codetrendy.comhttps://codetrendy.comListed on DevTool.ioFeatured on BuildlistFeatured on BuildlistLaunched on Tiny StartupsFeatured on ShowMeBestAIFeatured on ShowMeBestAIFind us on LaunchZoneFind us on LaunchZone
Β© 2026 Jackalope Digital LLC. All rights reserved.
  1. Home
  2. πŸ”’ Security
  3. MCP Server Wazuh
MCP Server Wazuh logo
Health: ActiveRecent health check succeeded.Last checked 9/9/2026, 12:33:50 PM

MCP Server Wazuh

User RatingsBe the first to rate and review this MCP server!
View Repository235 GitHub StarsTotal stargazers on GitHub for the source repository (235 stars).Visit Website
wazuhsiemsecurityincident-response

Connects Claude Desktop and other MCP clients to Wazuh alerts, agents, vulnerabilities, rules, logs, and cluster data.

Quick Install

Automated & IDE Setup

Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β€” or use 1-click editor setup below.

One-click editor setup isn’t available for this listing yet β€” we don’t have a confirmed install command, and we’d rather show nothing than point your editor at the wrong package or host. Follow the project’s own setup instructions, linked above.

Manual Client & Custom JSON ConfigExpand JSON β–Ύ
No confirmed setup config for this listing yet. We only publish a config block when the install details come from the project itself β€” its README, its docs, or a verified owner. We haven’t found those for gbrigandi/mcp-server-wazuh, and we’d rather show nothing than a guess you’d paste into your client. Follow the project’s own setup instructions for the current steps.
Install Directory Badge Claim listing AlternativesπŸ”’ More in Security

Overview

The gbrigandi/mcp-server-wazuh MCP server connects MCP-compatible assistants with Wazuh SIEM data through the Wazuh API and Indexer. It exposes security alerts, agent status, vulnerabilities, processes, ports, rules, logs, statistics, and cluster information in MCP-compatible responses. Use it when analysts need to investigate Wazuh data with natural-language queries instead of manually issuing API requests. The README specifically describes Claude Desktop integration and recommends Wazuh 4.12.

Use cases

β€’Triage recent Wazuh security alerts
β€’Prioritize critical vulnerabilities on agents
β€’Inspect agent processes and open ports
β€’Review Wazuh manager and cluster health
β€’Investigate manager logs during incidents

Key features

β€’Wazuh alert and event access
β€’Agent health, process, and port monitoring
β€’Vulnerability summaries and prioritization data
β€’Rules, statistics, and cluster inspection
β€’Manager log search and error analysis
β€’Natural-language MCP interaction

Capabilities & Tool Schemas

Inspect callable tools, capabilities, and parameters exposed to AI agents by MCP Server Wazuh.

Extracted Tool Capabilities
Wazuh alert and event access
Agent health, process, and port monitoring
Vulnerability summaries and prioritization data
Rules, statistics, and cluster inspection
Manager log search and error analysis
Natural-language MCP interaction

How MCP Server Wazuh works

What gbrigandi/mcp-server-wazuh MCP server does

The gbrigandi/mcp-server-wazuh MCP server makes Wazuh security and operations data available to an MCP-compatible LLM client. It is intended for environments where an assistant needs contextual access to a Wazuh deployment for alert review, vulnerability work, agent monitoring, incident investigation, and compliance checks.

The server covers data from both the Wazuh Indexer and Wazuh Manager. Indexer access supports alert and event analysis, while Manager access covers agents, rules, vulnerabilities, logs, statistics, and related operational information. Responses are converted into MCP-compatible data for use in conversational workflows.

How it works

A compatible client sends a natural-language request through MCP. The server queries the accessible Wazuh components and returns structured information that the assistant can use in its response. Example questions described by the project include finding critical vulnerabilities on web servers, inspecting processes on a particular agent, and checking PCI-DSS logging requirements.

The gbrigandi/mcp-server-wazuh MCP server can support investigations that combine multiple Wazuh data sources. For example, an analyst can review an alert, inspect the affected agent, check its open ports and processes, and examine relevant manager logs. The README also describes combining this server with separate Cortex, TheHive, or MISP MCP servers, but those are complementary projects rather than included capabilities.

Setup and configuration

You need an MCP-compatible LLM client, such as Claude Desktop, and a running Wazuh server with its API enabled and reachable. The project recommends Wazuh version 4.12. Network connectivity is required between the MCP server and the Wazuh API when API interaction is used.

The documented installation paths are a pre-built release binary or Docker. Release assets are provided for Linux amd64, macOS amd64, macOS arm64, and Windows amd64. A downloaded binary may need executable permissions on Unix-like systems and can optionally be placed on the system PATH. The supplied material does not include the Docker command, MCP client configuration block, or Wazuh credential variable names.

Tools and capabilities

Named tools in the README include:

  • get_wazuh_alert_summary for reviewing recent alert information.
  • get_wazuh_vulnerability_summary and get_wazuh_critical_vulnerabilities for vulnerability assessment.
  • get_wazuh_agent_processes, get_wazuh_agent_ports, and get_wazuh_running_agents for agent investigation and health monitoring.
  • get_wazuh_rules_summary for examining detection rules.
  • get_wazuh_weekly_stats, get_wazuh_remoted_stats, and get_wazuh_log_collector_stats for manager statistics.
  • get_wazuh_cluster_health and get_wazuh_cluster_nodes for cluster status.
  • search_wazuh_manager_logs and get_wazuh_manager_error_logs for log investigation.

These capabilities support alert triage, vulnerability prioritization, process and network analysis, rule review, performance monitoring, compliance assessment, and forensic work.

Limitations and notes

The project is a bridge to an existing Wazuh deployment; it does not replace Wazuh or provide a standalone SIEM. The README requires the Wazuh API to be enabled and accessible, but the supplied material does not specify authentication settings or environment variable names. It also does not establish support for clients beyond stating MCP compatibility and describing Claude Desktop integration. Tools or workflows belonging to the separately listed Cortex, TheHive, and MISP servers should not be treated as built into this server.

Read the full README β†’View source on GitHub β†’

Related MCP Servers

View all in Security View all alternatives
  • Jadx AI MCP logoJadx AI MCP

    JADX-AI-MCP is a plugin and MCP Server for the JADX decompiler that integrates directly with Model Context Protocol (MCP) to provide live reverse engineering support with LLMs like Claude.

    πŸ”’ Security3 views
    Compare vs Jadx AI MCP β†’
  • Apktool MCP Server logoApktool MCP Server

    APKTool MCP Server is a MCP server for the Apk Tool to provide automation in reverse engineering of Android APKs.

    πŸ”’ Security3 views
    Compare vs Apktool MCP Server β†’
  • MCP Server logoMCP Server

    MCP server for RAD Security, providing AI-powered security insights for Kubernetes and cloud environments. This server provides tools for querying the Rad Security API and retrieving security findings, reports, runtime data and many more.

    πŸ”’ Security2 views
    Compare vs MCP Server β†’
  • MCP Shodan logoMCP Shodan

    MCP server for querying the Shodan API and Shodan CVEDB. This server provides tools for IP lookups, device searches, DNS lookups, vulnerability queries, CPE lookups, and more.

    πŸ”’ Security3 views
    Compare vs MCP Shodan β†’

Adoption & maintenance

Factual signals from GitHub, npm, and our automated checks β€” not a rating.

GitHub stars
235
Stargazers on the source repository.
Last commit
9mo ago
Most recent push to the default branch.
Directory activity
3 views
Config copies, upvotes, and views on AllMCPs.

Reviews

No reviews yet β€” be the first to share how this listing worked for you.

Frequently Asked Questions about MCP Server Wazuh

Download a platform-specific binary from the project's GitHub Releases page or use the documented Docker option. The supplied material does not include an exact Docker command or MCP configuration block.

AllMCPs Directory Badge

Full Badge Customizer

Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.

Badge Style:
Live Dynamic SVG PreviewMCP Server Wazuh AllMCPs Directory Badge
Markdown (GitHub README)
[![AllMCPs](https://allmcps.com/api/badge/gbrigandi-mcp-server-wazuh?style=directory)](https://allmcps.com/mcp/gbrigandi-mcp-server-wazuh)
HTML Embed
<a href="https://allmcps.com/mcp/gbrigandi-mcp-server-wazuh"><img src="https://allmcps.com/api/badge/gbrigandi-mcp-server-wazuh?style=directory" alt="MCP Server Wazuh on AllMCPs" /></a>

Technical Specs & Signals

CategoryπŸ”’Security
PricingFree
More technical detailsExpand β–Ύ
AuthAPI key
LicenseMIT
ClientsClaude Desktop
Last updatedSep 7, 2026
Views3
Unique ViewsTotal visits recorded for this listing page on AllMCPs.
Installs0
Installs & Copy ActionsTotal times users copied install commands or configuration snippets for this server.
GitHub stars235
GitHub Star CountTotal stargazers on GitHub representing community popularity (235 stars).
Last commit9mo ago
Last Repository CommitThe most recent commit or push recorded for this server's GitHub repository.Last commit on Dec 12, 2025
45Quality signal: Fair Β· 45/100How this signal is calculated β–Ύ
Server availabilityNot measured

Not scored for repo-hosted servers β€” we can't reach the running server, only its GitHub page. Hosted MCP endpoints are health-checked live.

Verified ownership10/20
Documentation & tools19/30
Adoption & activity5/15
Community engagement0/10

A guidance signal from public completeness & health data β€” not a user rating. New listings start lower and rise as they add docs, get verified, and grow adoption. Signals we can't observe for a listing are skipped, not counted against it.

β˜… FeaturedMoxie Docs MCP logo

Moxie Docs MCP

MCP & Agent Skills for Automated Documentation, and codebase conventions + context

Explore Server β†’

Own this project?

This directory is pre-filled from public sources. Claim via GitHub README, site badge, or DNS TXT to unlock edit access and the Official badge β€” proof is checked automatically, then reviewed by our team.

Free dofollow backlink: add your website and place the AllMCPs badge on it β€” no claim needed. We detect it automatically and keep it verified as long as the badge stays live.

Claim & get free dofollow

Share & Embed

Add our SVG badge (dark/light directory styles) or embeddable widget to your site.

Explore more

More in πŸ”’ Security β†’Best MCP servers for Security β†’Alternatives to MCP Server Wazuh β†’Install in Claude DesktopInstall in CursorInstall in VS Code