Wazuh MCP Server
A production - grade open - source MCP server for integrating Wazuh security data with LLMs (such as the Claude desktop application). This service authenticates through the Wazuh RESTful API, retrieves alerts from the Elasticsearch index, converts events into an MCP - compatible JSON format, and exposes an HTTP endpoint for the Claude desktop to obtain real - time security context.
rating : 2.5 points
downloads : 33
What is the Wazuh MCP Server?
The Wazuh MCP Server is a bridge service that connects the Wazuh security monitoring system and AI assistants (such as Claude). It can automatically obtain security alert information and convert it into a standardized format that AI can understand, enabling security teams to obtain security event analysis through natural language queries.How to use the Wazuh MCP Server?
Simply complete the simple configuration. After starting the service, the AI assistant can automatically obtain Wazuh security alerts. The security team can directly ask the AI about the latest security events.Use cases
It is suitable for security operations centers (SOCs) to quickly understand the security situation, obtain context information when investigating security incidents, or conduct natural - language interactions related to security with AI assistants.Main features
Security authenticationUse JWT tokens to communicate securely with the Wazuh API to ensure the security of data transmission
Alert retrievalAutomatically obtain Wazuh alert data from Elasticsearch to keep the information up - to - date
Format conversionConvert raw security events into the standard MCP message format for easy understanding by AI
HTTP interfaceProvide the /mcp endpoint for clients such as Claude to obtain security context
Advantages and limitations
Advantages
Ready - to - use: Can be quickly deployed and used with simple configuration
High real - time performance: AI can obtain security events immediately after they occur
Standardized interface: Adopt the general MCP protocol and be compatible with multiple AI systems
Limitations
The Wazuh security system needs to be pre - deployed
Currently mainly supports the Claude AI system
Large amounts of alert data may affect performance
How to use
Environment preparation
Ensure that Python 3.8+ and the Wazuh system are installed
Get the code
Clone the GitHub repository to the local machine
Install dependencies
Create a virtual environment and install the required Python packages
Configure parameters
Set the Wazuh connection parameters and environment variables
Start the service
Run the main program to start the MCP server
Usage examples
Query the latest security eventsA security analyst wants to know all the security events that occurred in the past hour
Security status of a specific hostAn administrator wants to check the security status of a server
Frequently Asked Questions
Do I need to modify the Wazuh configuration?
Which AI systems are supported?
Will the data be sent to the cloud?
Related resources
Wazuh official documentation
Complete documentation for the Wazuh security platform
GitHub repository
Project source code and the latest version
MCP protocol specification
Technical specification of the Model Context Protocol
Featured MCP Services

Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
1.7K
5 points

Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
823
4.3 points

Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
79
4.3 points

Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
130
4.5 points

Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
554
5 points

Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
6.6K
4.5 points

Context7
Context7 MCP is a service that provides real-time, version-specific documentation and code examples for AI programming assistants. It is directly integrated into prompts through the Model Context Protocol to solve the problem of LLMs using outdated information.
TypeScript
5.2K
4.7 points

Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
745
4.8 points