BrowseFull catalogOutcomesSolve a specific problemRolesStack by teamTrustFilter by risk tier
← Back to the Claude Observatory

Wazuh MCP Server (SIEM)

Connector Security Usable
Works inClaude Code Claude Cowork Claude Chat
Usable Scanned — metadata only

Talk to your SIEM — security teams query alerts, hunt threats, and check compliance in plain English instead of writing complex queries.

Self-hosted MCP server that turns Wazuh SIEM operations into conversation: query and aggregate alerts, hunt threats, check vulnerabilities and compliance (PCI-DSS, HIPAA, ISO 27001, NIST), and trigger active responses like blocking IPs or isolating hosts. 54 tools with RBAC, audit logging, and output sanitization; works with cloud LLMs or fully air-gapped local models via Ollama.

221 starsMIT (commercial OK)FreeDeveloper setup
Usable rating — This tool is functional but has notable gaps. Review the evaluation notes below before deploying.

Talk to your SIEM — security teams query alerts, hunt threats, and check compliance in plain English instead of writing complex queries.

Security operations teams using Wazuh who want conversational threat hunting and alert investigation.

Claude Code Claude Cowork Claude Chat

https://github.com/gensecaihq/Wazuh-MCP-Server

By gensecaihq

How to Get It

Option 1: Claude Desktop AppOpen the Customize panel in the sidebar → browse connectors → search and add. Works in Claude Code, Claude Cowork, and Claude Chat.
Option 2: Paste into Claude CodeCopy the command below and paste it into a Claude Code conversation. Claude will run it for you.
Command
git clone https://github.com/gensecaihq/Wazuh-MCP-Server.git && cd Wazuh-MCP-Server && cp .env.example .env   # edit .env with WAZUH_HOST/USER/PASS, then: docker compose up -d

Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.

First thing to try

Once it’s connected, paste this into Claude:

Help me query security alerts in plain English instead of writing Wazuh queries
PrerequisitesDocker 20.10+ with Compose v2; Wazuh 4.8.0-4.14.4 with API access enabled.CostFree

Trust Signals Auto-scanned

Stars221Contributors17Last updated2026-08-16LicenseMIT (OK for commercial use)Known CVEsNone foundSources: GitHub Advisory Database + OSV.dev · Scanned 2026-08-17 · scanner v1

Data & Access

Data processingPrompts sent to Anthropic API. Enterprise/Team plans exclude training.

Community Pulse Growing

Discussed on Reddit

3 mentions across 1 sources

Reviewer notes

Auto-scanned review. These are observations, not a security certification.

catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 200 GitHub stars; 13 contributors; last commit 14d ago; license MIT.

Things to check

  • Self-hosted — you deploy and secure a server that sits between an LLM and your SIEM. The 14 state-changing tools (block IP, isolate host, kill process, quarantine file) require the opt-in wazuh:write scope; tokens without it are read-only by default. Claude Desktop connects as a remote custom connector with a bearer token.

How to evaluate tools before deploying →

Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.

Evaluation

Ease of Use
3/5
Versatility
3/5
Reliability
4/5
Security
3/5
Overall score3.25 / 5.00 UsableEvaluatedJul 2026
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 200 GitHub stars; 13 contributors; last commit 14d ago; license MIT.

← Back to the Claude Observatory

Rolling Claude out in your org? Let's talk.

Start a conversation →