Use Wazuh with your AI.
Connect your account once and let the AI you already use work with it, without building another integration. Manage your Wazuh SIEM infrastructure—monitor agents, inspect security events, and manage manager configurations directly from your AI agent.
Developed, maintained, and hosted by Vinkius.
MCP VERIFIED · PRODUCTION READY · VINKIUS GUARANTEED
Waiting for input…
Works with modern AI clients that support MCP, including ChatGPT, Claude, Cursor, and more.
Complete set · 21 capabilities
The complete Wazuh capability set.
These are the exact actions your AI can choose when you ask it to work with Wazuh.
01-04
4 capabilities in this set.
Part of 21 available through Wazuh.
- 01
List decoders
Supports WQL filtering. List loaded Wazuh decoders
- 02
Get logtest
Test rules and decoders against logs
- 03
Get manager logs
Retrieve Wazuh manager logs
- 04
Get manager status
Get Wazuh manager daemon status
05-08
4 capabilities in this set.
Part of 21 available through Wazuh.
- 05
Get rootcheck
Supports WQL filtering. Get Rootcheck results
- 06
Restart cluster
Restart the Wazuh cluster
- 07
Get sca
Supports WQL filtering. Get Security Configuration Assessment (SCA) results
- 08
List security users
List Wazuh API users
09-12
4 capabilities in this set.
Part of 21 available through Wazuh.
- 09
Get syscheck
Supports WQL filtering. Get File Integrity Monitoring (Syscheck) results
- 10
Get syscollector
Supports WQL filtering. Get Syscollector inventory
- 11
Update rule file
Update a Wazuh rule file
- 12
Update security config
Update Wazuh security configuration
13-15
3 capabilities in this set.
Part of 21 available through Wazuh.
- 13
Get mitre
Supports WQL filtering. Get MITRE ATT&CK results
- 14
List cluster nodes
List Wazuh cluster nodes
- 15
Create agent
Enroll a new Wazuh agent
16-18
3 capabilities in this set.
Part of 21 available through Wazuh.
- 16
Create security role
Create a new Wazuh security role
- 17
Delete agents
Use WQL to specify which agents to delete. Remove Wazuh agents
- 18
List agents
Supports WQL filtering. List all Wazuh agents
19-21
3 capabilities in this set.
Part of 21 available through Wazuh.
- 19
List rules
Supports WQL filtering. List loaded Wazuh rules
- 20
Restart agents
Restart Wazuh agents
- 21
Upgrade agents
Upgrade Wazuh agents
Observed, not estimated
931ms average. Fast in production.
Wazuh is checked daily against the live service.
- Fastest day
- 769ms
- Slowest day
- 1129ms
- 14-day trend
- Slowing+12%
Connect your client
One URL. Every client.
Activate the Connector, copy your link, and paste it into the client you already use. 21 capabilities arrive ready to run.
Preview access · not provider authentication
The vk_preview_* token belongs to Vinkius preview infrastructure. It lets Claude discover and display the capabilities of Wazuh, so you can see the experience inside your AI.
It does not authenticate your account with Wazuh. Actions requiring credentials or live account data may not run until you activate the Connector and authorize the service.
Wazuh Connector
You're all set. Choose your MCP client and follow the setup instructions.
https://edge.vinkius.com/vk_preview_REUf3LN8uLwAvmnqLRFwWwNJqnVgVW6WS1Ew5q4A/mcpClaude Desktop
Follow the steps below to connect in seconds.
- 1In Claude Desktop, open Settings → Connectors.
- 2Click “Add custom connector” and paste the connector link above as the remote MCP server URL.
- 3Click Add and start a new chat — Wazuh capabilities are ready to use.
{
"mcpServers": {
"wazuh-siem-mcp": {
"url": "https://edge.vinkius.com/vk_preview_REUf3LN8uLwAvmnqLRFwWwNJqnVgVW6WS1Ew5q4A/mcp"
}
}
}
Claude
ChatGPT
Cursor
VS Code
Windsurf
Claude Code
JetBrains
Cline
Step-by-step instructions for each client are in the guide. How to connect
FAQ
Questions Wazuh owners ask.
- 01
Can I filter agents by specific operating systems or versions?
Yes! The list_agents capability supports WQL (Wazuh Query Language). You can use queries like os.name=ubuntu;os.version>18 to find specific endpoints.
- 02
How do I check for unauthorized file changes on my servers?
You can use the get_syscheck capability. It retrieves File Integrity Monitoring (FIM) results, allowing you to audit file modifications, deletions, or additions across your agents.
- 03
Is it possible to check the health of the Wazuh manager cluster?
Absolutely. Use get_manager_status to check daemon health or list_cluster_nodes to see the status of all nodes in your Wazuh cluster.
Explore
More in Fort Knox
Aikido Security AI Connector
Query security vulnerabilities via Aikido — list open issues, check repositories, monitor cloud assets, and tr
ViewPatchstack Security AI Connector
Monitor WordPress security via Patchstack — track vulnerabilities, manage site software, and receive alerts di
ViewDatadog Cloud SIEM AI Connector
Manage cloud security via Datadog — search security signals, triage alerts, and audit detection rules directly
ViewSalt Security AI Connector
Integrate Salt Security directly with your AI for comprehensive API threat vector discovery, posture managemen
View
Suggestions
Levo.ai (API Security & Observability) AI Connector
Secure your APIs via Levo.ai — audit endpoints, monitor sensitive data (PII/PHI), and manage OWASP vulnerabili
ViewNmap Online AI Connector
Perform network discovery and security auditing via Nmap — track port scans, DNS lookups, and traceroutes dire
ViewPrisma Cloud AI Connector
Connect Prisma Cloud to any AI agent via MCP.
ViewHealthchecks.io AI Connector
Monitor cron jobs and background tasks via Healthchecks.io — list checks, track pings, and manage alerts direc
View
