How to Use the Wazuh (SIEM) MCP in Claude
See all your Wazuh security data and infrastructure logs right here in Claude Desktop.
Works with every AI agent you already use
…and any MCP-compatible client
Connect Wazuh (SIEM) MCP to Claude Desktop
Create your Vinkius account to connect Wazuh (SIEM) to Claude Desktop and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.
Manage Agent Lifecycle
You can enroll new endpoints with `create_agent` or quickly remove agents using `delete_agents`. This lets you control which devices are reporting data to your Wazuh (SIEM) system. You'll also see the full status of every connected machine by running `list_agents`, letting you confirm coverage across your network.
Run Security Audits via MCP Server
Need to know if a system is compromised? Run deep checks like `get_rootcheck` or assess configurations with `get_syscheck`. You just pass the parameters and get back actionable security results. The tool also lets you run MITRE ATT&CK lookups using `get_mitre`, giving context on specific attack vectors.
Inspect Wazuh Rules
Got a rule that isn't firing right? List every loaded decoder or check the syntax of rules with `list_decoders` and `list_rules`. This gives you visibility into what’s actually being processed. You can update files directly using `update_rule_file`, so you don't have to log into the management console just to tweak a regex.
Set up Wazuh (SIEM) MCP in Claude Web or Desktop
- 1
Open Claude Settings
Go to claude.ai, click your profile icon, then navigate to Customize → Connectors.
- 2
Add Custom Connector
Click the "+" button and select Add custom connector. Paste your Vinkius endpoint URL:
https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcpReplace[YOUR_TOKEN_HERE]with your token from cloud.vinkius.com. For OAuth-protected servers, expand Advanced settings to add credentials. - 3
Start a conversation
Open a new chat. The Wazuh (SIEM) MCP tools are available immediately — no restart needed.
Endpoint URL
https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp No configuration file needed — paste the URL directly in the Claude web interface.
Available on Free (1 connector), Pro, Max, Team, and Enterprise plans.
Why Choose Vinkius
Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.
Real-time monitoring
Live
visibility into every interaction
Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.
Built-in savings
60%
lower AI costs
Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.
Single dashboard
One
place for every integration
Every tool your AI connects to, managed from a single screen. One account, complete control.
Common questions about Wazuh (SIEM) MCP in Claude Desktop
Use it with your favorite AI tools
Connect this server to Cursor, Claude, VS Code, and more.
Start using the Wazuh (SIEM) MCP today
We host it, we monitor it, we maintain it. You just paste one token.