An MCP server for the Wazuh SIEM/XDR platform that enables users to query agents, security alerts, detection rules, and decoders through Claude or other MCP clients. It provides specialized tools and prompts for investigating security alerts, performing agent health checks, and generating environmental security overviews.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
process.env. You'll be asked to provide them before it can run.WAZUH_BASE_URL— Alternative variable names and WAZUH_USER are also supported.WAZUH_INDEXER_PASSWORD— No - Indexer passwordWAZUH_INDEXER_URL— No - Wazuh Indexer URL (e.g., https://10.0.0.2:9200)WAZUH_INDEXER_USERNAME— No admin Indexer usernameWAZUH_INDEXER_VERIFY_SSL— No false Set to true to verify SSL certificatesWAZUH_PASSWORD— Yes - API passwordWAZUH_TIMEOUTWAZUH_URL— Yes - Wazuh API URL (e.g., https://10.0.0.2:55000)WAZUH_USER— Alternative variable names WAZUH_BASE_URL and are also supported.WAZUH_USERNAME— Yes - API usernameWAZUH_VERIFY_SSL— No false Set to true to verify SSL certificates[](https://m8ven.ai/mcp/solomonneas-wazuh-mcp-7r68a2)