Wazuh MCP Server
W

Wazuh MCP Server

A production - grade open - source MCP server for integrating Wazuh security data with LLMs (such as the Claude desktop application). This service authenticates through the Wazuh RESTful API, retrieves alerts from the Elasticsearch index, converts events into an MCP - compatible JSON format, and exposes an HTTP endpoint for the Claude desktop to obtain real - time security context.
2.5 points
7.7K

What is the Wazuh MCP Server?

The Wazuh MCP Server is a bridge service that connects the Wazuh security monitoring system and AI assistants (such as Claude). It can automatically obtain security alert information and convert it into a standardized format that AI can understand, enabling security teams to obtain security event analysis through natural language queries.

How to use the Wazuh MCP Server?

Simply complete the simple configuration. After starting the service, the AI assistant can automatically obtain Wazuh security alerts. The security team can directly ask the AI about the latest security events.

Use cases

It is suitable for security operations centers (SOCs) to quickly understand the security situation, obtain context information when investigating security incidents, or conduct natural - language interactions related to security with AI assistants.

Main features

Security authentication
Use JWT tokens to communicate securely with the Wazuh API to ensure the security of data transmission
Alert retrieval
Automatically obtain Wazuh alert data from Elasticsearch to keep the information up - to - date
Format conversion
Convert raw security events into the standard MCP message format for easy understanding by AI
HTTP interface
Provide the /mcp endpoint for clients such as Claude to obtain security context
Advantages
Ready - to - use: Can be quickly deployed and used with simple configuration
High real - time performance: AI can obtain security events immediately after they occur
Standardized interface: Adopt the general MCP protocol and be compatible with multiple AI systems
Limitations
The Wazuh security system needs to be pre - deployed
Currently mainly supports the Claude AI system
Large amounts of alert data may affect performance

How to use

Environment preparation
Ensure that Python 3.8+ and the Wazuh system are installed
Get the code
Clone the GitHub repository to the local machine
Install dependencies
Create a virtual environment and install the required Python packages
Configure parameters
Set the Wazuh connection parameters and environment variables
Start the service
Run the main program to start the MCP server

Usage examples

Query the latest security events
A security analyst wants to know all the security events that occurred in the past hour
Security status of a specific host
An administrator wants to check the security status of a server

Frequently Asked Questions

Do I need to modify the Wazuh configuration?
Which AI systems are supported?
Will the data be sent to the cloud?

Related resources

Wazuh official documentation
Complete documentation for the Wazuh security platform
GitHub repository
Project source code and the latest version
MCP protocol specification
Technical specification of the Model Context Protocol

Installation

Copy the following command to your Client for configuration
Note: Your key is sensitive information, do not share it with anyone.

Alternatives

A
Aderyn
Aderyn is an open - source Solidity smart contract static analysis tool written in Rust, which helps developers and security researchers discover vulnerabilities in Solidity code. It supports Foundry and Hardhat projects, can generate reports in multiple formats, and provides a VSCode extension.
Rust
5.9K
5 points
M
MCP Scan
MCP-Scan is a security scanning tool for MCP servers, used to detect common security vulnerabilities such as prompt injection, tool poisoning, and cross-domain escalation.
Python
14.6K
5 points
A
Agentic Radar
Agentic Radar is a security scanning tool for analyzing and assessing agentic systems, helping developers, researchers, and security experts understand the workflows of agentic systems and identify potential vulnerabilities.
Python
11.9K
5 points
2
2344
Opik is an open-source LLM evaluation framework that supports tracking, evaluating, and monitoring LLM applications, helping developers build more efficient and cost-effective LLM systems.
TypeScript
17.2K
5 points
I
Ida Pro MCP
Certified
IDA Pro MCP is a server plugin for reverse engineering. It interacts with client tools through the MCP protocol, providing functions such as function analysis, comment modification, variable renaming, etc., and supports multiple MCP clients such as Cline, Roo Code, etc.
Python
17.0K
5 points
M
MCP Shield
MCP - Shield is a security tool for scanning MCP server vulnerabilities, which can detect security risks such as tool poisoning attacks, data leakage channels, and cross - domain violations.
TypeScript
9.3K
5 points
G
Gitlab MCP Server
Certified
The GitLab MCP server is a project based on the Model Context Protocol that provides a comprehensive toolset for interacting with GitLab accounts, including code review, merge request management, CI/CD configuration, and other functions.
TypeScript
16.6K
4.3 points
N
Notion Api MCP
Certified
A Python-based MCP Server that provides advanced to-do list management and content organization functions through the Notion API, enabling seamless integration between AI models and Notion.
Python
14.8K
4.5 points
M
Markdownify MCP
Markdownify is a multi-functional file conversion service that supports converting multiple formats such as PDFs, images, audio, and web page content into Markdown format.
TypeScript
24.6K
5 points
D
Duckduckgo MCP Server
Certified
The DuckDuckGo Search MCP Server provides web search and content scraping services for LLMs such as Claude.
Python
44.0K
4.3 points
U
Unity
Certified
UnityMCP is a Unity editor plugin that implements the Model Context Protocol (MCP), providing seamless integration between Unity and AI assistants, including real - time state monitoring, remote command execution, and log functions.
C#
19.2K
5 points
F
Figma Context MCP
Framelink Figma MCP Server is a server that provides access to Figma design data for AI programming tools (such as Cursor). By simplifying the Figma API response, it helps AI more accurately achieve one - click conversion from design to code.
TypeScript
44.5K
4.5 points
G
Gmail MCP Server
A Gmail automatic authentication MCP server designed for Claude Desktop, supporting Gmail management through natural language interaction, including complete functions such as sending emails, label management, and batch operations.
TypeScript
14.8K
4.5 points
M
Minimax MCP Server
The MiniMax Model Context Protocol (MCP) is an official server that supports interaction with powerful text-to-speech, video/image generation APIs, and is suitable for various client tools such as Claude Desktop and Cursor.
Python
30.3K
4.8 points
AIBase
Zhiqi Future, Your AI Solution Think Tank
© 2025AIBase