Wazuh MCP Server integrates Wazuh security data with large language models like Claude. It authenticates via the Wazuh API to fetch alerts, transform them to MCP-compliant JSON, and provides an HTTP endpoint for real-time context.
Wazuh MCP Server integrates Wazuh security data with large language models like Claude. It authenticates via the Wazuh API to fetch alerts, transform them to MCP-compliant JSON, and provides an HTTP endpoint for real-time context.
Clone the repository, set up a virtual environment, install dependencies, configure environment variables, and run the server.Add this configuration to your claude_desktop_config.json:
{
"mcpServers": {
"wazuh-mcp-server": {
"command": "npx",
"args": [
"-y",
"Clone the repository, set up a virtual environment, install dependencies, configure environment variables, and run the server."
]
}
}
}Restart Claude Desktop, then ask:
"What tools do you have available from Wazuh MCP Server?"
No configuration required. This server works out of the box.
"What resources are available in Wazuh MCP Server?"
Claude will query available resources and return a list of what you can access.
"Show me details about [specific item] in Wazuh MCP Server"
Claude will fetch and display detailed information about the requested item.
"Create a new [item] in Wazuh MCP Server with [details]"
Claude will use the appropriate tool to create the resource and confirm success.
See what tools in your stack can connect to AI.
We build custom MCP integrations for B2B companies. From simple connections to complex multi-tool setups.