Skip to content
Vinkius

Wazuh (SIEM) Connector for AI agents.

21 live capabilities

Manage your security infrastructure and monitor endpoint health with natural language queries.

Live agent request Wazuh (SIEM) / Connector

Waiting for input…

AI Agent

Why people use Wazuh (SIEM)

Wazuh SIEM for Faster Security Auditing

With the Wazuh SIEM MCP, you just ask your agent to find the issues. You can pull logs, check manager status, and see FIM results in a single chat thread. You get your answers in seconds without ever leaving your workspace.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • Visual Studio Code
  • Windsurf

What Vinkius changes

You get a conversational interface for your entire security stack.

Use it from Claude, ChatGPT, Cursor or another AI client you already have.

One account · 5,900+ Connectors

  1. Real-world use case 01

    Responding to a suspected breach

    An analyst asks their agent to pull manager logs and MITRE mappings for a specific alert.

  2. Real-world use case 02

    Auditing endpoint compliance

    A security lead needs to find all agents with failed security checks.

  3. Real-world use case 03

    Bulk agent maintenance

    A DevSecOps engineer needs to update 200 agents.

Complete set · 21capabilities

The complete Wazuh (SIEM) capability set.

These are the exact actions your AI can choose when you ask it to work with Wazuh (SIEM).

Capability set01 / 06

01—04

4 capabilities in this set.

Part of 21 available through Wazuh (SIEM).

  1. 01 Capability

    List decoders

    List all loaded Wazuh decoders. Use WQL filtering to find specific ones quickly.

  2. 02 Capability

    Delete agents

    Remove agents from your system. Use WQL to specify exactly which ones you want to delete.

  3. 03 Capability

    List agents

    See every agent enrolled in your Wazuh setup. It supports WQL filtering for easier searching.

  4. 04 Capability

    Get logtest

    Test your rules and decoders against specific logs. This helps you validate your detection pipeline.

Capability set02 / 06

05—08

4 capabilities in this set.

Part of 21 available through Wazuh (SIEM).

  1. 05 Capability

    Get manager logs

    Pull the logs from your Wazuh manager. This is useful for debugging daemon issues.

  2. 06 Capability

    Get manager status

    Check if the Wazuh manager daemon is running. Use this to ensure your system is online.

  3. 07 Capability

    Restart agents

    Restart your Wazuh agents remotely. Use this to apply updates or clear hung processes.

  4. 08 Capability

    Restart cluster

    Restart your entire Wazuh cluster. Use this when you need to perform maintenance on cluster nodes.

Capability set03 / 06

09—12

4 capabilities in this set.

Part of 21 available through Wazuh (SIEM).

  1. 09 Capability

    Get rootcheck

    Pull Rootcheck results from your agents. This helps identify unauthorized root access attempts.

  2. 10 Capability

    List rules

    See all the rules currently loaded in your Wazuh system. Use WQL filtering to find specific rule types.

  3. 11 Capability

    Get sca

    Get Security Configuration Assessment results. Use WQL filtering to find specific compliance failures.

  4. 12 Capability

    List security users

    See the list of users authorized on your Wazuh API. This helps you manage access.

Capability set04 / 06

13—15

3 capabilities in this set.

Part of 21 available through Wazuh (SIEM).

  1. 13 Capability

    Get syscheck

    Get File Integrity Monitoring results. Use WQL filtering to see which files were modified.

  2. 14 Capability

    Get syscollector

    Pull your Syscollector inventory data. This gives you a clear picture of your endpoint hardware and software.

  3. 15 Capability

    Update rule file

    Modify a specific Wazuh rule file. This lets you fine-tune your detection logic on the fly.

Capability set05 / 06

16—18

3 capabilities in this set.

Part of 21 available through Wazuh (SIEM).

  1. 16 Capability

    Update security config

    Change your Wazuh security configuration. Use this to update global security settings.

  2. 17 Capability

    Upgrade agents

    Push updates to your Wazuh agents. This keeps your entire fleet running on the latest version.

  3. 18 Capability

    Create security role

    Create a new Wazuh security role. This helps you manage permissions for different users.

Capability set06 / 06

19—21

3 capabilities in this set.

Part of 21 available through Wazuh (SIEM).

  1. 19 Capability

    Get mitre

    Get MITRE ATT&CK results for your threats. Use WQL filtering to narrow down the results.

  2. 20 Capability

    List cluster nodes

    See all nodes in your Wazuh cluster. Use this to monitor high availability.

  3. 21 Capability

    Create agent

    Enroll a new agent into your Wazuh system. This makes onboarding new devices much faster.

Set up in minutes

One URL. Then ask Wazuh (SIEM) to work.

Claude and ChatGPT only need the Connector URL. Copy it once, add it in settings, and use Wazuh (SIEM) from the conversation.

Choose your client

Live preview
Advanced clients IDE · CLI

Claude · Web + desktop

Official guide ↗

Connector URL · ready to paste

Streamable HTTP
https://edge.vinkius.com/vk_preview_REUf3LN8uLwAvmnqLRFwWwNJqnVgVW6WS1Ew5q4A/mcp
  1. Step 01

    Open Connectors

    In Claude Web or Claude Desktop, open Settings and choose Connectors.

  2. Step 02

    Add the URL

    Choose Add custom connector, name it Wazuh (SIEM), and paste the URL above.

  3. Step 03

    Turn it on in chat

    Select +, open Connectors, and enable Wazuh (SIEM) for the conversation.

Where the request belongs

Work Wazuh can move forward.

Built around the request

This is for the security professional who is tired of clicking through dozens of dashboard screens just to find one piece of data. It's for the engineer who needs to manage hundreds of endpoints without the manual overhead.

01

Security Analyst

You use this to quickly query FIM results and security configurations without navigating the main Wazuh dashboard.

02

DevSecOps Engineer

You use this to automate agent upgrades and monitor cluster health from your terminal based AI capabilities.

03

Incident Responder

You use this to grab manager logs and MITRE mappings instantly during a live security breach.

Bring your own AI

Change the model, client or framework. Keep Wazuh connected.

  • Claude
  • ChatGPT
  • Gemini
  • Cursor
  • VS Code
  • Windsurf
  • ZCode
  • Cline
  • Zed
  • Continue
  • Kiro
  • Roo Code
  • Zencoder
  • Goose
  • Void
  • Augment Code
  • Amp
  • Qodo
  • Tabnine
  • Pieces
  • Sourcegraph Cody
  • JetBrains
  • Warp
  • Amazon Q
  • Antigravity
  • BoltAI
  • Raycast
  • Jan
  • LM Studio
  • AnythingLLM
  • Open WebUI
  • Msty
  • Cherry Studio
  • LibreChat
  • TypingMind
  • Chorus
  • 5ire
  • n8n
  • LangChain
  • LlamaIndex
  • CrewAI
  • Vercel AI SDK

Before you connect

Questions about Wazuh.

The practical details behind the request, access and result.

How does the Wazuh SIEM MCP help with incident response?

It lets you pull manager logs and MITRE ATT&CK mappings instantly through your AI agent. Instead of hunting through a UI, you can get the data you need to understand a threat in a single chat.

Can I use the Wazuh SIEM MCP to update my security rules?

Yes, you can use it to modify your Wazuh rule files and security configurations. Your agent can handle the updates for you based on your instructions.

Does the Wazuh SIEM MCP support bulk agent actions?

It does. You can use your agent to restart or upgrade multiple Wazuh agents at once, which saves a lot of time on fleet maintenance.

Is the Wazuh SIEM MCP good for auditing file changes?

Yes, it's great for that. You can ask your agent to pull File Integrity Monitoring results to see exactly which files were modified across your infrastructure.

How do I connect my Wazuh instance to the Connector?

You just need to provide your Wazuh API URL and credentials. Once connected through Vinkius, your AI client can start querying your security data immediately.

Can the Wazuh SIEM MCP check if my manager is running?

Yes, it can check the manager daemon status and pull logs. This helps you ensure your SIEM infrastructure is healthy and available at all times.

Can I filter agents by specific operating systems or versions?

Yes! The list_agents capability supports WQL (Wazuh Query Language). You can use queries like os.name=ubuntu;os.version>18 to find specific endpoints.

How do I check for unauthorized file changes on my servers?

You can use the get_syscheck capability. It retrieves File Integrity Monitoring (FIM) results, allowing you to audit file modifications, deletions, or additions across your agents.

Is it possible to check the health of the Wazuh manager cluster?

Absolutely. Use get_manager_status to check daemon health or list_cluster_nodes to see the status of all nodes in your Wazuh cluster.

One connection away

Give your agent a direct line to Wazuh.

Connect Wazuh once. Keep it beside 5,900+ managed Connectors when the next task needs more.

Explore every Connector No credit card required · Free tier available