{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_eg3wb94sxa79","handle":"iflow-mcp-socfortress-wazuh-mcp-server","url":"https://wellknown.network/agents/iflow-mcp-socfortress-wazuh-mcp-server","links":{"self":"https://wellknown.network/agents/iflow-mcp-socfortress-wazuh-mcp-server/record.json","html":"https://wellknown.network/agents/iflow-mcp-socfortress-wazuh-mcp-server","markdown":"https://wellknown.network/agents/iflow-mcp-socfortress-wazuh-mcp-server/record.md","api":"https://wellknown.network/api/v1/agents/iflow-mcp-socfortress-wazuh-mcp-server","status":"https://wellknown.network/api/v1/agents/iflow-mcp-socfortress-wazuh-mcp-server/status","claim":"https://wellknown.network/agents/iflow-mcp-socfortress-wazuh-mcp-server/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/iflow-mcp-socfortress-wazuh-mcp-server/claim.json","badge":"https://wellknown.network/agents/iflow-mcp-socfortress-wazuh-mcp-server/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/iflow-mcp-socfortress-wazuh-mcp-server/history","tools":"https://wellknown.network/api/v1/agents/iflow-mcp-socfortress-wazuh-mcp-server/tools"},"ard":{"identifier":"urn:air::server:iflow-mcp-socfortress-wazuh-mcp-server","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"iflow-mcp_socfortress-wazuh-mcp-server","summary":"Model Context Protocol server for Wazuh Manager integration","description":"# Wazuh MCP Server\n\nA production-ready **Model Context Protocol (MCP) server** for seamless integration between Wazuh SIEM and Large Language Models (LLMs).\n\n[![Build Status](https://github.com/socfortress/wazuh-mcp-server/actions/workflows/publish.yml/badge.svg)](https://github.com/socfortress/wazuh-mcp-server/actions)\n[![Python 3.11+](https://img.shields.io/badge/python-3.11+-blue.svg)](https://www.python.org/downloads/)\n[![YouTube Channel Subscribers](https://img.shields.io/youtube/channel/subscribers/UC4EUQtTxeC8wGrKRafI6pZg)](https://www.youtube.com/@taylorwalton_socfortress/videos)\n[![Get in Touch](https://img.shields.io/badge/📧%20Get%20in%20Touch-Friendly%20Support%20Awaits!-blue?style=for-the-badge)](https://www.socfortress.co/contact_form.html)\n\n> **Why?**\n> Combine the power of Wazuh's comprehensive security monitoring with the reasoning capabilities of large language models—enabling natural language queries and intelligent analysis of your security data.\n\n---\n\n## ✨ Key Features\n\n- 🚀 **Production-ready**: Proper package structure, logging, error handling, and configuration management\n- 🔐 **Secure**: JWT token management with automatic refresh\n- 🌐 **HTTP/2 Support**: Built on modern async HTTP client with connection pooling\n- 📊 **Comprehensive API**: Access Wazuh agents, authentication, and more\n- 🎛️ **Configurable**: Environment variables, CLI arguments, and fine-grained tool filtering\n- 📦 **Pip installable**: Install directly from GitHub releases or source\n\n---\n\n## Table of Contents\n- [Quick Start](#quick-start)\n- [Installation](#installation)\n- [Configuration](#configuration)\n- [Usage](#usage)\n- [Available Tools](#available-tools)\n- [Development](#development)\n- [CI/CD](#continuous-integration)\n- [Deployment](#deployment)\n- [Security](#security-considerations)\n- [Contributing](#contributing)\n- [License](#license)\n\n---\n\n## Quick Start\n\n### 1. Install\n\n#### From GitHub (Recommended)\n```bash\npython -m venv .venv && source .venv/bin/activate\npip inst…","publisher":null,"homepage":"https://github.com/socfortress/wazuh-mcp-server#readme","repository":"https://github.com/socfortress/wazuh-mcp-server#readme","version":"0.1.0","license":null,"protocols":["mcp"],"tags":["wazuh","mcp","llm","security","siem"],"pricing":null,"endpoints":[{"url":"pypi:iflow-mcp_socfortress-wazuh-mcp-server","type":"package_pypi","auth":null,"probeable":false}],"skills":null,"tools":null,"extra":null,"attribution":{"kind":"pypi","name":"pypi","repoUrl":"pypi","summary":"pypi","version":"pypi","description":"pypi","homepageUrl":"pypi"}},"derived":{"capabilities":[{"slug":"dev.ci-cd","name":"CI/CD & Deploy","confidence":1,"provenance":"derived"}],"categories":["dev"],"language":"en"},"observed":{"status":"unknown","statusReason":"Distributed as a package to run locally; no network endpoint to check.","lastOkAt":null,"lastProbedAt":null,"statusComputedAt":null,"reliability30d":null,"latestObservations":[],"tools":null,"package":{"name":"iflow-mcp_socfortress-wazuh-mcp-server","registry":"pypi","observedAt":"2026-09-15T20:21:23.178Z","publishedAt":"2026-02-12T21:17:15.067552Z","latestVersion":"0.1.0"},"toolSurface":null,"endpointFacts":[]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"pypi","key":"iflow-mcp_socfortress-wazuh-mcp-server","url":"https://pypi.org/project/iflow-mcp_socfortress-wazuh-mcp-server/","firstSeenAt":"2026-09-09T21:23:59.557Z","fetchedAt":"2026-09-15T20:19:42.372Z","normalizedAt":"2026-09-15T20:19:42.372Z"}]},"firstSeenAt":"2026-09-09T21:23:59.557Z","updatedAt":"2026-09-15T20:21:23.178Z"}