Connects MCP clients to Wazuh SIEM through 48 tools covering alert queries, agent monitoring, vulnerability scans, and active response actions. Query alerts in plain English, block IPs, isolate hosts, kill processes, and check compliance status without touching dashboards or writing API calls. Works with cloud LLMs via Claude Desktop or fully local setups using Ollama and Open WebUI for air-gapped environments. Includes proper RBAC, audit logging, and rate limiting since you're essentially giving an AI the keys to trigger security responses across your infrastructure.
claude mcp add --transport stdio gensecaihq-wazuh-mcp-server uvx wazuh-mcp-server