Wazuh MCP Server (SIEM)
Talk to your SIEM — security teams query alerts, hunt threats, and check compliance in plain English instead of writing complex queries.
Self-hosted MCP server that turns Wazuh SIEM operations into conversation: query and aggregate alerts, hunt threats, check vulnerabilities and compliance (PCI-DSS, HIPAA, ISO 27001, NIST), and trigger active responses like blocking IPs or isolating hosts. 54 tools with RBAC, audit logging, and output sanitization; works with cloud LLMs or fully air-gapped local models via Ollama.
- Query security alerts in plain English instead of writing Wazuh queries
- Hunt for threats across your environment through conversation
- Check compliance status and vulnerability assessments
Talk to your SIEM — security teams query alerts, hunt threats, and check compliance in plain English instead of writing complex queries.
Security operations teams using Wazuh who want conversational threat hunting and alert investigation.
https://github.com/gensecaihq/Wazuh-MCP-Server
By gensecaihq
How to Get It
git clone https://github.com/gensecaihq/Wazuh-MCP-Server.git && cd Wazuh-MCP-Server && cp .env.example .env # edit .env with WAZUH_HOST/USER/PASS, then: docker compose up -d
Tip: Paste this into a Claude Code conversation. Verify command matches your Claude Code version.
Once it’s connected, paste this into Claude:
Help me query security alerts in plain English instead of writing Wazuh queries
Trust Signals Auto-scanned
Data & Access
Community Pulse Growing
Discussed on Reddit
- [Release] Wazuh MCP v0.2.0 - Major Update — Reddit · 36 pts
- Built a Tool to Connect Wazuh with AI Models via MCP — Reddit · 23 pts
- Opensource Wazuh MCP Server : Looking for Contributors — Reddit · 20 pts
3 mentions across 1 sources
Reviewer notes
Auto-scanned review. These are observations, not a security certification.
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 200 GitHub stars; 13 contributors; last commit 14d ago; license MIT.
Things to check
- Self-hosted — you deploy and secure a server that sits between an LLM and your SIEM. The 14 state-changing tools (block IP, isolate host, kill process, quarantine file) require the opt-in wazuh:write scope; tokens without it are read-only by default. Claude Desktop connects as a remote custom connector with a bearer token.
How to evaluate tools before deploying →
Data shown here comes from public APIs and automated scanning. Reviewer notes reflect one person's experience. This is not a security certification or legal recommendation. Always evaluate tools according to your own organization's policies.
Evaluation
catalog_hygiene stale-eval refresh: Scored from trust signals (evidence-eval-v1): 200 GitHub stars; 13 contributors; last commit 14d ago; license MIT.