4,500+ servers built on MCP Fusion
Vinkius
Wazuh (SIEM) logo
Vinkius
Claude Desktop logo

How to Use the Wazuh (SIEM) MCP in Claude

See all your Wazuh security data and infrastructure logs right here in Claude Desktop.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Wazuh (SIEM) MCP on Cursor AI Code Editor MCP Client Wazuh (SIEM) MCP on Claude Desktop App MCP Integration Wazuh (SIEM) MCP on OpenAI Agents SDK MCP Compatible Wazuh (SIEM) MCP on Visual Studio Code MCP Extension Client Wazuh (SIEM) MCP on GitHub Copilot AI Agent MCP Integration Wazuh (SIEM) MCP on Google Gemini AI MCP Integration Wazuh (SIEM) MCP on Lovable AI Development MCP Client Wazuh (SIEM) MCP on Mistral AI Agents MCP Compatible Wazuh (SIEM) MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Claude Desktop

Connect Wazuh (SIEM) MCP to Claude Desktop

Create your Vinkius account to connect Wazuh (SIEM) to Claude Desktop and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Manage Agent Lifecycle

You can enroll new endpoints with `create_agent` or quickly remove agents using `delete_agents`. This lets you control which devices are reporting data to your Wazuh (SIEM) system. You'll also see the full status of every connected machine by running `list_agents`, letting you confirm coverage across your network.

Run Security Audits via MCP Server

Need to know if a system is compromised? Run deep checks like `get_rootcheck` or assess configurations with `get_syscheck`. You just pass the parameters and get back actionable security results. The tool also lets you run MITRE ATT&CK lookups using `get_mitre`, giving context on specific attack vectors.

Inspect Wazuh Rules

Got a rule that isn't firing right? List every loaded decoder or check the syntax of rules with `list_decoders` and `list_rules`. This gives you visibility into what’s actually being processed. You can update files directly using `update_rule_file`, so you don't have to log into the management console just to tweak a regex.

Setup guide

Set up Wazuh (SIEM) MCP in Claude Web or Desktop

  1. 1

    Open Claude Settings

    Go to claude.ai, click your profile icon, then navigate to Customize → Connectors.

  2. 2

    Add Custom Connector

    Click the "+" button and select Add custom connector. Paste your Vinkius endpoint URL: https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp Replace [YOUR_TOKEN_HERE] with your token from cloud.vinkius.com. For OAuth-protected servers, expand Advanced settings to add credentials.

  3. 3

    Start a conversation

    Open a new chat. The Wazuh (SIEM) MCP tools are available immediately — no restart needed.

Endpoint URL

https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp

No configuration file needed — paste the URL directly in the Claude web interface.

Available on Free (1 connector), Pro, Max, Team, and Enterprise plans.

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about Wazuh (SIEM) MCP in Claude Desktop

Use the `get_logtest` tool. You pass it sample logs, and the server runs those against your current rules and decoders to show you exactly what they catch.
Yes, running `list_agents` gives you a comprehensive list of every active agent registered with the manager. It’s fast and simple to check inventory status.
You can pull historical data by calling `get_manager_logs`. This retrieves the main manager daemon's activity, letting you trace back issues that occurred hours ago.
Most of the read tools—like `get_mitre`, `list_agents`, and `get_rootcheck`—support WQL, so you can narrow down results to specific time ranges or hosts.
It handles agent configuration details and raw security event logs. These are highly sensitive operational records that need careful management.

Start using the Wazuh (SIEM) MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 21 tools

We've already built the connector for Wazuh (SIEM). Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 21 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.