An MCP server that enables conversational interaction with Wazuh SIEM, allowing users to investigate alerts, hunt threats, tune false positives, edit rules, and run security actions via natural language.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.ANSICONBUILD_DATEVERSIONPYTHON_VERSIONMCP_PORT— 3000 Server portATOMIC_TARGET_HOSTATOMIC_TRANSPORTATOMIC_MCP_HOSTATOMIC_MCP_PORTATOMIC_WAZUH_AGENT_NAMEATOMIC_VM_NAMEATOMIC_SNAPSHOT_NAMEATOMIC_ATOMICS_PATHATOMIC_MAX_RUNTIME_SECONDSATOMIC_OUTPUT_LIMIT_BYTESATOMIC_LEDGER_PATHATOMIC_COVERAGE_PATHATOMIC_WINRM_USERNAMEATOMIC_WINRM_PASSWORDATOMIC_WINRM_PORTATOMIC_WINRM_DOMAINATOMIC_AUTHLESS_ALLOW_WRITEMCP_HOST— 0.0.0.0 Server bind addressLOG_LEVELAUTH_SECRET_KEY— auto-generated JWT signing keyTOKEN_LIFETIME_HOURSMCP_API_KEY— headers: ["Authorization: Bearer ${env://}"]API_KEYSWAZUH_HOST— your-wazuh-serverWAZUH_USER— your-api-userWAZUH_PASS— your-api-passwordVERIFY_SSLWAZUH_INDEXER_HOST— Indexer hostnameWAZUH_INDEXER_USER— Indexer usernameWAZUH_INDEXER_PASS— Indexer passwordMCP_TRANSPORTAUTH_MODE— bearer oauth, bearer, or noneOAUTH_ISSUER_URLOAUTH_ENABLE_DCROAUTH_ACCESS_TOKEN_TTLOAUTH_REFRESH_TOKEN_TTLOAUTH_AUTHORIZATION_CODE_TTLALLOWED_ORIGINSWAZUH_PORT— 55000 Manager API portWAZUH_VERIFY_SSLWAZUH_ALLOW_SELF_SIGNEDWAZUH_INDEXER_PORT— 9200 Indexer portWAZUH_INDEXER_VERIFY_SSLENVIRONMENTMASTER_KEYSSE_PORTSSE_HOSTSSL_KEYFILESSL_CERTFILEREDIS_URL— Redis URL for multi-instance session storageKUBERNETES_SERVICE_HOSTDOCKER_CONTAINERMAX_MEMORY_MBRATE_LIMIT_REQUESTSRATE_LIMIT_WINDOWTRUSTED_PROXIESAUTHLESS_ALLOW_WRITE— false Allow active response in authless modeSESSION_TTL_SECONDSATOMIC_MCP_URLWAZUH_MCP_URLART_INTERVAL_SECART_ALERT_WAIT_SEC[](https://m8ven.ai/mcp/simoon896-ai-detection-engineering-platform-nurcjp)