{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_z7h9p5caemnm","handle":"netmon-demo","url":"https://wellknown.network/agents/netmon-demo","links":{"self":"https://wellknown.network/agents/netmon-demo/record.json","html":"https://wellknown.network/agents/netmon-demo","markdown":"https://wellknown.network/agents/netmon-demo/record.md","api":"https://wellknown.network/api/v1/agents/netmon-demo","status":"https://wellknown.network/api/v1/agents/netmon-demo/status","claim":"https://wellknown.network/agents/netmon-demo/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/netmon-demo/claim.json","badge":"https://wellknown.network/agents/netmon-demo/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/netmon-demo/history","tools":"https://wellknown.network/api/v1/agents/netmon-demo/tools"},"ard":{"identifier":"urn:air:netmon.com:server:netmon-demo","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"Netmon (demo)","summary":"Public read-only demo of Netmon's network monitoring tools over a recorded snapshot.","description":"Public read-only demo of Netmon's network monitoring tools over a recorded snapshot.","publisher":{"name":"com.netmon","url":null},"homepage":"https://netmon.com/mcp-server/","repository":"https://github.com/Netmon-Services/netmon-mcpd","version":"1.0.1","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[{"url":"https://netmon.com/mcp-demo/mcp","type":"mcp_streamable_http","auth":null,"probeable":true}],"skills":null,"tools":null,"extra":{"updatedAt":"2026-09-11T14:59:16.842298Z","publishedAt":"2026-09-11T14:59:16.842298Z","registryName":"com.netmon/netmon-demo"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[{"slug":"content.writing","name":"Writing & Editing","confidence":1,"provenance":"derived"},{"slug":"dev.monitoring","name":"Monitoring & Observability","confidence":0.902,"provenance":"derived"},{"slug":"automation.workflows","name":"Workflow Automation","confidence":0.51,"provenance":"derived"}],"categories":["automation","content","dev"],"language":"en"},"observed":{"status":"live","statusReason":"Responded 3h ago.","lastOkAt":"2026-10-10T15:30:14.988Z","lastProbedAt":"2026-10-10T15:30:14.988Z","statusComputedAt":"2026-10-10T15:32:39.018Z","reliability30d":{"probes":53,"successRate":1,"p50Ms":96,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":53,"ok":53,"authBoundaryOk":0,"serviceOk":53,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-10-10T15:30:14.988Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":88,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T08:33:20.794Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":134,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-10T02:30:29.720Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":85,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T19:26:07.490Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":99,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T12:29:22.476Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":100,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-09T05:26:36.045Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":92,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T23:23:46.616Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":100,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T17:28:35.519Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":114,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T11:22:21.514Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":85,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-10-08T04:26:42.135Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":95,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"package":null,"toolSurface":{"id":"ts_43jq7b2vrfpg","endpointId":"ep_8mzrj453xfp9","hash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","toolCount":36,"serverName":"netmon7-demo","serverVersion":"1.0.0","protocolVersion":"2025-06-18","firstSeenAt":"2026-09-12T10:26:07.660Z","lastSeenAt":"2026-10-10T15:30:14.993Z","observations":104,"toolNames":["get_network_entity_info","arp_lookup","ping","traceroute","port_map","search_ip","syslog_search","eventlog_search","eve_search","eve_get","log_severity_summary","syslog_facets","netflow_search","netflow_raw_search","flow_summary","device_list","device_get","device_find","overwatch_summary","snmp_test","snmp_walk_last","snmp_walk_run","agent_services","agent_processes","alerts_list","alerts_history","maintenance_windows_list","tags_list","top_bandwidth","arp_table","interfaces_search","device_metric_summary","agent_disk_usage","capture_list","capture_get","speedtest_history"],"distinctSurfaces":1},"endpointFacts":[{"id":"ep_8mzrj453xfp9","url":"https://netmon.com/mcp-demo/mcp","type":"mcp_streamable_http","factsCheckedAt":"2026-10-07T22:23:36.087Z","auth":{"observedAt":"2026-10-07T22:23:36.639Z","authRequired":false,"scheme":null,"resourceMetadata":null,"authorizationServer":null,"conformance":{"dpop":false,"rfc8414":false,"rfc9728":false,"pkceS256":false,"clientIdMetadataDocument":false,"dynamicClientRegistration":false}},"tls":{"observedAt":"2026-10-07T22:23:36.810Z","protocol":"TLSv1.3","chainValid":true,"chainError":null,"hostMatches":true,"subject":"netmon.com","issuer":{"commonName":"YR1","organization":"Let's Encrypt"},"validFrom":"2026-09-18T10:14:30.000Z","validTo":"2026-12-17T10:14:29.000Z","daysToExpiry":67,"sanCount":2,"fingerprint256":"D3:39:98:CB:7A:52:D4:CF:C3:82:76:7A:D2:75:8F:53:52:CA:50:FF:F4:CC:4E:3D:F3:4A:42:4A:AB:A3:D7:7D"}}]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"com.netmon/netmon-demo","url":"https://registry.modelcontextprotocol.io/v0/servers/com.netmon%2Fnetmon-demo","firstSeenAt":"2026-09-11T18:19:19.577Z","fetchedAt":"2026-10-09T09:23:00.114Z","normalizedAt":"2026-10-09T09:23:00.114Z"}]},"firstSeenAt":"2026-09-11T18:19:19.577Z","updatedAt":"2026-10-10T15:33:28.108Z"}