Skip to content
appsgit

Wazuh MCP Server

Wazuh MCP Server is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management… It has 248 GitHub stars, is released under the MIT license and runs locally with docker run -i --rm ghcr.io/gensecaihq/wazuh-mcp-server.

github.com/gensecaihq/Wazuh-MCP-Server (opens in a new tab)

  • Official
  • Other
  • MIT
  • Actively maintained

Install Wazuh MCP Server

Generated from the server's published package. Replace your-value with your own values.

Claude Desktop

claude_desktop_config.json
{
  "mcpServers": {
    "wazuh-mcp-server": {
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/gensecaihq/wazuh-mcp-server"
      ]
    }
  }
}

Settings > Developer > Edit Config. macOS: ~/Library/Application Support/Claude/, Windows: %APPDATA%\Claude\. Restart Claude Desktop afterwards.

Claude Code

claude mcp add --transport stdio wazuh-mcp-server -- docker run -i --rm ghcr.io/gensecaihq/wazuh-mcp-server

Cursor

.cursor/mcp.json
{
  "mcpServers": {
    "wazuh-mcp-server": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/gensecaihq/wazuh-mcp-server"
      ]
    }
  }
}

Project file; use ~/.cursor/mcp.json to enable it in every project.

VS Code

.vscode/mcp.json
{
  "servers": {
    "wazuh-mcp-server": {
      "type": "stdio",
      "command": "docker",
      "args": [
        "run",
        "-i",
        "--rm",
        "ghcr.io/gensecaihq/wazuh-mcp-server"
      ]
    }
  }
}

Config formats checked against the official docs on Oct 7, 2026: modelcontextprotocol.io (opens in a new tab), code.claude.com (opens in a new tab), cursor.com (opens in a new tab), code.visualstudio.com (opens in a new tab).

Tools (8)

Parsed from the Tools section of the README; check the repository for the current list.

  • alerts

    5 R

  • agents

    6 R

  • vulnerabilities

    3 R

  • analysis

    5 R

  • web_search

    1 R

  • compliance

    6 R

  • system

    10 R

  • wazuh_firewall_allow

    and wazuhhostallow require an operator-deployed undo command (WAZUHARFIREWALLUNDOCOMMAND, WAZUHARHOSTDENYUNDOCOMMAND);…

About Wazuh MCP Server

A Model Context Protocol (MCP) server for the Wazuh SIEM. Lets an MCP client — Claude, Open WebUI backed by a local model, or any client that speaks Streamable HTTP — query alerts, agents, vulnerabilities and compliance data, and dispatch active responses, with scope-based access control and audit logging.

  • ai
  • claude
  • mcp
  • mcp-server
  • model-context-protocol
  • python
  • wazuh
  • active-response
  • compliance
  • cybersecurity

FAQ

Wazuh MCP Server FAQ

Still curious? Email info@appsgit.com.

What is Wazuh MCP Server?

Wazuh MCP Server is an MCP server that adds tools to AI assistants such as Claude Desktop, Claude Code and Cursor. Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management… It has 248 GitHub stars, is released under the MIT license and runs locally with docker run -i --rm ghcr.io/gensecaihq/wazuh-mcp-server. The source code is at github.com/gensecaihq/Wazuh-MCP-Server.

How do I install the Wazuh MCP Server MCP server?

Add the command docker run -i --rm ghcr.io/gensecaihq/wazuh-mcp-server to your MCP client: put it in claude_desktop_config.json for Claude Desktop, run claude mcp add for Claude Code, or add it to .cursor/mcp.json (Cursor) or .vscode/mcp.json (VS Code). The snippets on this page are ready to paste.

Is Wazuh MCP Server free?

The server is open source under the MIT license, so running it is free. It does not declare any required API key.

Is Wazuh MCP Server actively maintained?

The most recent commit was on Sep 30, 2026. The latest release is v5.0.0, published Sep 24, 2026. appsgit only lists MCP servers with a commit in the last six months and re-checks every server daily.