4,500+ servers built on MCP Fusion
Vinkius
Wazuh (SIEM) logo
Vinkius
Pydantic AI logo

How to Use the Wazuh (SIEM) MCP in Pydantic AI

Ensure data correctness when managing SIEM with Pydantic AI.

See Vinkius in Action

Works with every AI agent you already use

…and any MCP-compatible client

Wazuh (SIEM) MCP on Cursor AI Code Editor MCP Client Wazuh (SIEM) MCP on Claude Desktop App MCP Integration Wazuh (SIEM) MCP on OpenAI Agents SDK MCP Compatible Wazuh (SIEM) MCP on Visual Studio Code MCP Extension Client Wazuh (SIEM) MCP on GitHub Copilot AI Agent MCP Integration Wazuh (SIEM) MCP on Google Gemini AI MCP Integration Wazuh (SIEM) MCP on Lovable AI Development MCP Client Wazuh (SIEM) MCP on Mistral AI Agents MCP Compatible Wazuh (SIEM) MCP on Amazon AWS Bedrock MCP Support
MCP Servers - Free for Subscribers
Pydantic AI

Connect Wazuh (SIEM) MCP to Pydantic AI

Create your Vinkius account to connect Wazuh (SIEM) to Pydantic AI and route execution through our secure gateway. The platform manages server hosting, runtime updates, and security layers. Configuration requires no manual server provisioning.

GDPR Free for Subscribers

Audit Wazuh Agents and Nodes via MCP Server

Need to check the agent list? Call `list_agents` for an accurate inventory, or use `create_agent` to onboard a new endpoint. The tool also lets you delete agents with `delete_agents`, filtered by WQL. Because responses are type-safe, you'll always know exactly what fields you received when checking agent status.

Validate Wazuh (SIEM) Threat Findings

The tool supports several checks for security posture. You can get root system audit results via `get_rootcheck`, or check file integrity with `get_syscheck`. Both methods accept WQL filters, guaranteeing precise data. If the API returns unexpected data during these runs, your agent fails loudly—you won't miss a critical field.

Manage Wazuh (SIEM) Operational Status

Check if everything is running right. Use `get_manager_status` to verify the daemon health, or grab historical records with `get_manager_logs`. You can also check loaded decoders using `list_decoders`. This structure guarantees that status metrics are returned in a predictable format.

Setup guide

Set up Wazuh (SIEM) MCP in Pydantic AI

Prerequisites

  • Python 3.10+ installed
  • pydantic-ai-slim[fastmcp] package
  • Active Vinkius subscription with a valid endpoint token
  1. 1

    Install Pydantic AI with FastMCP

    Run pip install "pydantic-ai-slim[fastmcp]". The FastMCP toolset replaces the deprecated MCPServerHTTP class with full protocol support.

  2. 2

    Configure the FastMCPToolset

    Pass a JSON-style config dict to FastMCPToolset with your Vinkius URL. Replace [YOUR_TOKEN_HERE] with your token from cloud.vinkius.com. Supports Streamable HTTP, SSE, and Stdio transports.

  3. 3

    Create and run your agent

    Pass the toolset to Agent(toolsets=[toolset]) and call agent.run(). Swap openai:gpt-4o for any supported model — Anthropic, Google, Mistral, or Groq.

agent.py
from pydantic_ai import Agent
from pydantic_ai.toolsets.fastmcp import FastMCPToolset

toolset = FastMCPToolset({
    "mcpServers": {
        "wazuh-siem-mcp": {
            "url": "https://edge.vinkius.com/[YOUR_TOKEN_HERE]/mcp"
        }
    }
})

agent = Agent(
    "openai:gpt-4o",
    toolsets=[toolset],
    system_prompt="You have access to Wazuh (SIEM) tools.",
)

result = await agent.run("List recent Wazuh (SIEM) transactions")
print(result.output)

Independent Platform Disclaimer: Vinkius is an independent platform and is not affiliated with, endorsed by, sponsored by, verified by, or otherwise authorized by Wazuh. All third-party trademarks, logos, and brand names are the property of their respective owners. Their use on this website is strictly for informational purposes to identify service compatibility and interoperability.

Why Choose Vinkius

Vinkius connects your tools to AI with real-time monitoring and automatic cost savings — all from one dashboard.

Real-time monitoring

Live

visibility into every interaction

Connect your favorite tools to your AI and see exactly what's happening — every request, every response, in real time.

Built-in savings

60%

lower AI costs

Vinkius compresses data between your apps and your AI automatically. Lower bills every month — no configuration required.

Single dashboard

One

place for every integration

Every tool your AI connects to, managed from a single screen. One account, complete control.

Common questions about Wazuh (SIEM) MCP in Pydantic AI

The framework allows the use of `create_agent` for enrollment and `delete_agents` to remove endpoints. Since results are validated by Pydantic models, you get guaranteed data structure when listing agents.
Yes. You can run `get_sca` for Security Configuration Assessment results and the tool will validate every field against your defined schema, preventing silent data corruption.
Combine agent listings (`list_agents`) with threat checks like `get_mitre`. The type-safe approach ensures that all metrics and findings you combine are structurally sound.
The toolset manages rules via `update_rule_file` or modifies security settings with `update_security_config`. Pydantic validation ensures these updates are processed and reported correctly.
The server handles system logs and agent configuration. The toolset requires interaction with Agent lists and rules to function.

Start using the Wazuh (SIEM) MCP today

We host it, we monitor it, we maintain it. You just paste one token.

Built & Managed by Vinkius 30s setup 21 tools

We've already built the connector for Wazuh (SIEM). Just plug in your AI agents and start using Vinkius.

No hosting. No infrastructure. No complex setup.
All 21 tools are live and waiting. You're up and running in seconds.

Claude Claude
ChatGPT ChatGPT
Cursor Cursor
Gemini Gemini
Windsurf Windsurf
VS Code VS Code
JetBrains JetBrains
Vercel Vercel
+ other MCP clients

Vinkius gives your AI agents access to the full catalog of app connectors, all fully managed, secure, and enterprise-ready. One subscription, every tool you need.

Zero hosting required Full MCP catalog included Enterprise-grade security Auto-updated by Vinkius

Built, hosted, and secured by Vinkius. You just connect and go.