wazuh-mcp
An MCP server for the Wazuh SIEM/XDR platform that enables users to query agents, security alerts, detection rules, and decoders through Claude or other MCP clients. It provides specialized tools and prompts for investigating security alerts, performing agent health checks, and generating environmental security overviews.
Install
npx -y wazuh-mcp
Paste the configuration above into your MCP client config (claude_desktop_config.json for Claude Desktop) and restart the client.
{
"mcpServers": {
"wazuh-mcp": {
"command": "npx",
"args": [
"-y",
"wazuh-mcp"
],
"env": {
"WAZUH_URL": "<WAZUH_URL>",
"WAZUH_USER": "<WAZUH_USER>",
"WAZUH_BASE_URL": "<WAZUH_BASE_URL>",
"WAZUH_PASSWORD": "<WAZUH_PASSWORD>",
"WAZUH_USERNAME": "<WAZUH_USERNAME>",
"WAZUH_VERIFY_SSL": "<WAZUH_VERIFY_SSL>"
}
}
}
}Paste the configuration above into your MCP client config (claude_desktop_config.json for Claude Desktop) and restart the client.
Sources: public MCP Server directories. This is an independent third-party directory with no affiliation to or endorsement from the maintainers of the listed servers.