监控 · 安全

Wazuh logo

Wazuh

unmuktoai/wazuh-mcp-server

一个开源的生产级MCP服务器,用于将Wazuh安全数据与LLMs(如Claude Desktop App)集成。

安装

docker run -d --name wazuh-mcp-server --env-file .env -e MCP_HOST=0.0.0.0 -e ENVIRONMENT=production \

环境变量

WAZUH_HOSTWAZUH_USERWAZUH_PASSWAZUH_INDEXER_HOSTWAZUH_INDEXER_USERWAZUH_INDEXER_PASSVLLM_API_KEYWEBUI_SECRET_KEY
GitHub 星标
14
分类
监控, 安全
许可证
MIT
更新于
2026年10月6日

工具(9)

  • WAZUH_DISABLED_TOOLS

    hides individual tools.

  • alerts

    get_wazuh_alerts, get_wazuh_alert_summary, get_alerts_aggregated, analyze_alert_patterns, search_security_events

  • agents

    get_wazuh_agents, get_wazuh_running_agents, check_agent_health, get_agent_processes, get_agent_ports, get_agent_configuration

  • vulnerabilities

    get_wazuh_vulnerabilities, get_wazuh_critical_vulnerabilities, get_wazuh_vulnerability_summary

  • analysis

    analyze_security_threat, check_ioc_reputation, perform_risk_assessment, get_top_security_threats, generate_security_report

  • web_search

    search_external_context — You.com web search; returns a "not enabled" result unless YDC_API_KEY is set

  • compliance

    run_compliance_check (PCI-DSS, HIPAA, SOX, GDPR, NIST, ISO27001), get_iso27001_dashboard, get_iso27001_control_detail, get_iso27001_gap_analysis,…

  • system

    get_wazuh_statistics, get_wazuh_weekly_stats, get_wazuh_cluster_health, get_wazuh_cluster_nodes, get_wazuh_rules_summary, get_wazuh_remoted_stats,…

  • wazuh_firewall_allow

    and wazuh_host_allow require an operator-deployed undo command (WAZUH_AR_FIREWALL_UNDO_COMMAND, WAZUH_AR_HOSTDENY_UNDO_COMMAND); without one they refuse.

本页信息摘自该项目的 README。 查看 README

支持的客户端

该服务器 README 中提到的客户端:

查看全部
Claude Desktop logo

Claude Desktop

桌面端 · 免费增值 · Proprietary

Anthropic 官方推出的 Claude AI 桌面应用程序。支持 MCP 服务器以扩展功能。

WindowsMacOS
Windsurf logo

Windsurf

桌面端 · 免费增值 · Proprietary

首个代理式 IDE。Windsurf 编辑器让开发者与 AI 的工作真正融合在一起。

WindowsMacOSLinux
LibreChat logo

LibreChat

网页端 · 免费 · MIT

可扩展的开源 AI 聊天平台。支持多个 AI 提供商和 MCP 服务器。

Web

相关 MCP 服务器

更多服务器
2344 logo

2344

comet-ml/opik

7k

Opik是一个开源的LLM评估框架,支持追踪、评估和监控LLM应用,帮助开发者构建更高效、更经济的LLM系统。

监控
MCP Grafana logo

MCP Grafana

grafana/mcp-grafana

612

Grafana MCP服务器提供对Grafana实例及其生态系统的访问,支持仪表盘搜索、数据源查询、事件管理等功能。

监控
Vite Plugin Vue MCP logo

Vite Plugin Vue MCP

webfansplz/vite-plugin-vue-mcp

407

Vite插件,为Vue应用提供MCP服务,支持组件树、状态、路由和Pinia的查看与编辑。

监控
api200 logo

api200

API-200/api200

169

API 200是一个开源API集成平台,提供第三方API的快速接入和管理功能,包含自动生成代码、文档、认证、缓存和错误处理等特性,支持自托管部署和MCP服务。

监控
WireMCP (Wireshark) logo

WireMCP (Wireshark)

0xkoda/wiremcp

98

WireMCP是一个为大型语言模型(LLM)提供实时网络流量分析能力的MCP服务器,通过Wireshark工具捕获和处理网络数据,支持威胁检测、网络诊断和异常分析。

监控
gospy logo

gospy

monsterxx03/gospy

90

Go进程检查工具,提供goroutine状态、内存统计和二进制信息分析,支持终端UI和HTTP API

监控