An MCP (Model Context Protocol) server that integrates with Wazuh SIEM to provide natural language query capabilities, security alert retrieval, agent management, and DSL-based search through OpenSearch/Wazuh Indexer
This server has 7 tools with mixed definition quality. Strengths: tool names follow verb_noun convention (get_*, search_*, restart_*); all tools have descriptions; input schemas are present for most tools. Major gaps: descriptions lack LLM-optimization guidance and context about when to use each tool; the natural_query and simple_query tools duplicate functionality and create agent confusion; parameter descriptions are generic; no documented output schemas; no error handling guidance; schemas lack proper JSON Schema typing in many cases. The server relies on HTTP transport (positive), but tool composition violates the single-responsibility pattern, three query tools (natural_query, simple_query, search) do overlapping work. Average per-tool score is 52, reflecting pervasive but fixable issues.
Perform MCP server health check including Wazuh API and Wazuh Indexer connectivity status
Fetch all Wazuh agents with their details including ID, name, IP, OS, and status
Fetch alerts from Wazuh with optional filtering by agent ID, severity level, and limit
Execute a natural language query against Wazuh with automatic LLM-based parsing, DSL generation, and response formatting. Supports full query lifecycle from NL to structured results
Restart the Wazuh manager service
Execute a structured search query against Wazuh Indexer using DSL (Domain Specific Language). Supports filtering, time ranges, aggregations with validation and optional dry-run mode
Execute a simple natural language query using Wazuh Manager API directly without DSL parsing. Faster but less flexible. Supports agent queries and alert retrieval with keyword-based routing
Three tools (natural_query, simple_query, search) provide overlapping query functionality without clear disambiguation. LLMs will struggle to select the correct tool, wasting reasoning cycles and risking wrong query execution.
Descriptions lack LLM-optimization guidance. Most descriptions under 100 characters or too generic (e.g., 'Optional agent ID to filter alerts'). Per pattern:tool-description baseline (194 chars avg), descriptions should answer: WHAT does the tool do? WHEN should I call it? WHAT does it return? Current descriptions answer only WHAT partially.
No output schemas documented for any tool. LLMs cannot plan downstream calls or extract data without knowing what fields to expect. This violates pattern:tool (document output schema) and wastes LLM reasoning as it discovers structure by trial.
Inferred effective spec: <=2025-11-25.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | D | 50 | <=2025-11-25 | v2 |
| 2026-03-09 | F | 0 | - | v1 |
Parameter descriptions are terse and lack actionable constraints. Example: 'severity' parameter in get_alerts has description 'Optional severity level to filter alerts (e.g., "12" for critical, "8" for high)', but includes example values (violates pattern:tool-description guideline: examples cause literal reuse). Should be an enum or range spec instead.
wazuh.restart_manager is a WRITE operation with no confirmation or dry-run support. Description fails to warn about destructive consequences. Violates pattern:command-tool (document state changes) and pattern:confirmation-request (irreversible operations should offer confirmation).
No error handling guidance in tool descriptions. LLMs have no recovery path for common failures (e.g., 'User not found. Try search_users() first' per pattern:recovery-guide). Examples: search fails, DSL is invalid, indexer timeout.
Tool naming inconsistency: mcp.health_check uses dot-prefixed namespace (mcp.) while all other tools use wazuh. namespace. This breaks naming consistency and confuses agents about tool grouping.
search tool has limit parameter (max 200 results) but no documented pagination mechanism (no next_cursor or offset). Large result sets risk exhausting context window. Violates pattern:paginated-result.