4,500+ servers built on MCP Fusion
Vinkius
Wazuh (SIEM) logo
Vinkius
Claude Code logo

How to Use the Wazuh (SIEM) MCP in Claude Code

Run Wazuh SIEM Audits in CI/CD Pipelines with Claude Code: Script security checks from the terminal.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Wazuh (SIEM) MCP on Cursor AI Code Editor MCP Client Wazuh (SIEM) MCP on Claude Desktop App MCP Integration Wazuh (SIEM) MCP on OpenAI Agents SDK MCP Compatible Wazuh (SIEM) MCP on Visual Studio Code MCP Extension Client Wazuh (SIEM) MCP on GitHub Copilot AI Agent MCP Integration Wazuh (SIEM) MCP on Google Gemini AI MCP Integration Wazuh (SIEM) MCP on Lovable AI Development MCP Client Wazuh (SIEM) MCP on Mistral AI Agents MCP Compatible Wazuh (SIEM) MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Claude Code

Connect Wazuh (SIEM) MCP to Claude Code

Create your Vinkius account to connect Wazuh (SIEM) to Claude Code and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Automate Agent Lifecycle Management via MCP Server

Integrate agent management directly into your pipeline script. Before deployment, run `list_agents` to confirm all required endpoints are online. If not, the script fails immediately. Need to clean up old credentials? Use `delete_agents` with WQL to remove stale entries in bulk before running the build.

Enforce Compliance Checks using Claude Code

Build a non-interactive compliance gate. Run `get_rootcheck` or `get_sca` and pipe the exit code into your CI/CD system. The script passes if no high-severity findings are returned. This makes security audits part of your mandatory build steps, not optional tasks.

Manage Wazuh (SIEM) Infrastructure State

Your pipelines need stability. Use the MCP Server to manage the cluster state; run `restart_cluster` if a node fails mid-build. You can also update rules using `update_rule_file` before testing, ensuring your deployment uses the latest detection logic. This keeps your SIEM environment reliable for automated testing.

Setup guide

Set up Wazuh (SIEM) MCP in Claude Code

Prerequisites

  • Claude Code CLI installed (npm install -g @anthropic-ai/claude-code)
  • Active Vinkius subscription with a valid endpoint token
  1. 1

    Run the add command

    Open your terminal and run the command shown on the right. Replace [YOUR_TOKEN_HERE] with your endpoint token from cloud.vinkius.com. Use --scope user to make it available across all projects.

  2. 2

    Verify the connection

    Start a Claude Code session and type /mcp to list connected servers. You should see wazuh-siem-mcp with a green status indicator.

  3. 3

    Start using tools

    Ask Claude Code something like "Check my latest Wazuh (SIEM) transactions." It will automatically discover and invoke the available Wazuh (SIEM) tools.

Terminal
claude mcp add --transport http wazuh-siem-mcp https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about Wazuh (SIEM) MCP in Claude Code

You run `list_agents` and pipe the JSON output into your logging system. This allows you to confirm agent status every hour without needing a GUI or manual interaction.
Yes. Use `list_security_users` to script out the current user list and compare it against your deployment manifest, ensuring no unauthorized accounts exist.
Run `get_logtest` as a dedicated stage in your pipeline. This tool validates detection logic using sample logs, providing immediate pass/fail exit codes that stop deployment if issues surface.
Absolutely. Use `list_cluster_nodes` to verify node connectivity. If a critical node is missing, your script can automatically trigger alerts or halt the pipeline.
This server manages detection logic. You use `list_rules` to dump all active rules or `list_decoders` to check parsing capabilities, which is essential for scripting rule validation.

Start using the Wazuh (SIEM) MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 21 tools

We've already built the connector for Wazuh (SIEM). Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 21 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.