Query devices, alerts, syslog, Suricata IDS, NetFlow and captures on your Netmon appliance.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Connect an AI assistant to a Netmon appliance.
Netmon ships an MCP server on the appliance itself. This repository holds the client-side bridge: a small Node process that runs on your own machine, speaks stdio to Claude Desktop, and forwards every JSON-RPC message to your Netmon's /mcp endpoint over HTTPS.
Once connected, an assistant can read your devices, interfaces, logs, flow records, alerts, and Windows-agent data by calling Netmon's tools directly β with the same sign-in and permissions as any operator, and the same tag restrictions.
A public, read-only demo server answers the same 36 tools from a recorded, de-identified snapshot of a fictional 90-device network:
No account, no token, no install. Point any MCP client at it:
GUI clients β Claude Desktop (Settings β Connectors β Add custom connector) and ChatGPT (developer mode β Connectors) β take the URL with authentication set to None. For Cursor, Zed, Kimi Code CLI, Continue and LM Studio, drop the URL into that client's MCP config file:
Then ask it something real: "what's down?", "show me the Suricata alerts from last week", "which host is using the most bandwidth, and who is it talking to?"
It is a fixture, not an appliance: nothing writes, nothing reaches a real network, and every answer is the same shape a live Netmon returns β with timestamps shifted forward so the snapshot always reads as the last day or so.
Two separate walls stand between an MCP client and an appliance on your LAN, and the bridge exists for both.
Where the connection comes from. Claude Desktop's remote-connector option and ChatGPT's custom connectors both fetch the MCP URL from their vendor's cloud, not from your machine β Anthropic's docs say so outright, and their connector resolves the hostname and rejects private addresses before any request leaves their network, so your appliance's log stays empty. Most other clients (Claude Code, Codex, Gemini CLI, Cursor, VS Code, Zed, Cline, Continue, opencode, Goose, LM Studio, Kimi) connect from your own machine and are unaffected.
The certificate. This one catches nearly everyone. Most clients validate TLS against the operating system trust store and expose no skip-verify option, and an appliance ships a self-signed certificate β so the route succeeds and the handshake fails. Either install the appliance's certificate in the machine's trust store, or use the bridge, which pins it on first use.
The bridge runs as a local process and handles both. It is not a Claude-specific workaround; it is the general answer.
If your appliance is internet-facing with a publicly-trusted certificate, you can skip the bridge and point any MCP client straight at the endpoint. See Install β any MCP client below.
mcp:* scopes you want the assistant to have..mcpb install. Claude Desktop supplies its own Node runtime, so nothing else is needed. Running the bridge outside Claude Desktop requires Node 18 or newer.Download netmon-mcp-<version>.mcpb from Releases. The same bundle ships with your appliance β Settings β System β Downloadables β Claude Desktop Extension.
In Claude Desktop, open Settings β Extensions β Advanced settings β Extension Developer β Install Extensionβ¦ and select the file.
Fill in the two settings the extension asks for:
| Setting | Value |
|---|---|
| Netmon URL | https://<your-netmon>/mcp β the full endpoint, including /mcp |
| API Token | a personal access token (see below). The Bearer prefix is added for you if you leave it off. |
Restart the extension. Ask Claude something like "list the devices that are down" to confirm it is working.
In Netmon, go to Settings β Users, click the key icon on your user, and create a personal access token. Select only the scopes the assistant needs β the token cannot be widened later, and it can be revoked from the same screen at any time.
The account must hold the API permission. Without it, token minting and OAuth consent are both refused.
The appliance serves Streamable HTTP at https://<your-netmon>/mcp (POST for JSON-RPC, GET for the server-to-client SSE stream, DELETE to end a session).
Clients that support OAuth 2.1 discover the authorization server on their own: the endpoint answers an unauthenticated request with 401 and a WWW-Authenticate: Bearer resource_metadata="β¦" challenge pointing at RFC 9728 protected-resource metadata, alongside RFC 8414 authorization-server metadata and dynamic client registration at /auth/register. You sign in through your browser on your own Netmon and approve the scopes on a consent page.
Clients without OAuth support pass a token directly:
Most appliances serve a self-signed certificate. A direct type: http entry will fail against one β the OAuth bootstrap rejects the certificate and does not consult NODE_EXTRA_CA_CERTS. Use the bridge instead, which handles the certificate itself:
36 read tools, each wrapping a Netmon API endpoint and gated by an OAuth scope that is checked before the call runs.
| Area | Scope | Example tools |
|---|---|---|
| Devices & fleet | mcp:devices | device_find, device_get, device_list, device_metric_summary, overwatch_summary, tags_list |
| Traffic & topology | mcp:vne, mcp:devices | top_bandwidth, netflow_search, netflow_raw_search, flow_summary, get_network_entity_info, arp_table, interfaces_search |
| Logs & security | mcp:logs | syslog_search, eventlog_search, eve_search, eve_get, log_severity_summary, syslog_facets |
| Alerts | mcp:alerts | alerts_list, alerts_history, maintenance_windows_list |
| Windows agent | mcp:devices | agent_processes, agent_services, agent_disk_usage |
| Live tools | mcp:tools, mcp:devices, mcp:capture | ping, traceroute, arp_lookup, port_map, snmp_test, snmp_walk_run, snmp_walk_last, search_ip, speedtest_history, capture_list, capture_get |
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/netmon-2)<a href="https://allmcps.com/mcp/netmon-2"><img src="https://allmcps.com/api/badge/netmon-2?style=directory" alt="Netmon on AllMCPs" /></a>