Wazuh-MCP-Server

MCP.Pizza Chef: gensecaihq

Over fifty commands let you ask about alerts, agents, unpatched vulnerabilities and compliance scores in plain English, and read back cluster health or manager logs. Fourteen of them act rather than report, blocking an address, isolating a machine, killing a process or disabling a user, and those stay hidden unless you grant write permission. It needs a Wazuh deployment you already run, version 4.8 through 4.14, plus Docker and your Wazuh sign-in details. It can also run entirely against a local model, so nothing leaves your network.

Data
Other

Use This MCP server To

Show me the critical alerts from the last hour Ask which machines still have unpatched critical vulnerabilities Block a suspicious address on one machine, then confirm it stuck Check how we score against PCI-DSS or ISO 27001 Isolate a compromised machine and release it later Summarize this week's security activity into a report

README

Wazuh MCP Server

License: MIT Python 3.11+ MCP 2026-07-28 Docker

Talk to your SIEM. Query alerts, hunt threats, check vulnerabilities, and trigger active responses across your entire Wazuh deployment — through natural conversation with any AI assistant.

v4.2.1 | 55 security tools | Wazuh 4.8.0–4.14.7 | Changelog


What This Does

Your Wazuh SIEM generates thousands of alerts, vulnerability findings, and agent events daily. Investigating them means juggling dashboards, writing API queries, and manually correlating data across tools.

This MCP server turns that workflow into a conversation:

You:    "Show me critical alerts from the last hour"
AI:     [calls get_wazuh_alerts] Found 3 critical alerts:
        1. SSH brute force from 10.0.1.45 → agent-003 (Rule 5712, Level 10)
        2. Rootkit detection on agent-007 (Rule 510, Level 12)
        3. FIM change /etc/shadow on agent-001 (Rule 550, Level 10)

You:    "Block that source IP on agent-003"
AI:     [calls wazuh_block_ip] Blocked 10.0.1.45 via firewall-drop on agent-003.

You:    "Which agents have unpatched critical CVEs?"
AI:     [calls get_wazuh_critical_vulnerabilities] 3 agents with critical vulnerabilities...

It works with Claude Desktop, Open WebUI + Ollama (fully local, air-gapped), mcphost, or any MCP-compliant client.


Works With Cloud AND Local LLMs

This is a standard MCP tool server. It doesn't care what LLM you use — it just executes tools and returns results.

Mode LLM Client Data leaves your network?
Cloud Claude, GPT, etc. Claude Desktop, any MCP client Yes (to LLM provider)
Local Llama, Qwen, Mistral via Ollama Open WebUI, mcphost, IBM/mcp-cli No. Fully air-gappable.

For security teams that can't send SIEM data to cloud APIs (compliance, air-gapped networks, data sovereignty), the local mode with Ollama keeps everything on-premises. Both modes coexist — same server, same tools, same API.

Wazuh-MCP-Server FAQ

Do I need a Wazuh installation already?
Yes. It talks to a Wazuh deployment you already run, version 4.8 through 4.14, with management access enabled. It is not a security product on its own.
Do I need a key or password?
Yes. You supply a Wazuh username and password, and the server issues a bearer key that your assistant uses to connect.
Can it change things, or only look?
Both, but the fourteen acting commands are filtered out unless write permission is granted. Out of the box it is read-only.
Can I use this without sending data to a cloud provider?
Yes — paired with Open WebUI or mcphost and a local model such as Llama or Qwen, everything stays inside your own network.
Which apps does it work in?
Claude Desktop connects as a custom connector. Open WebUI and mcphost are documented too, as is any MCP-compatible client.
How hard is setup?
This is the technical end of the scale. You clone the project, fill in a settings file and start it with Docker Compose, or pull a prebuilt image.
Can I undo something it did?
Yes. Five commands exist purely to reverse actions: releasing a machine, re-enabling a user, restoring a quarantined file and unblocking an address.
Is it still maintained?
Yes, actively. The code was updated within the last couple of days.