{"$schema":"https://wellknown.network/schemas/agent-record-v1.json","schemaVersion":"1","id":"ag_q2dvaudwmsyp","handle":"netmon","url":"https://wellknown.network/agents/netmon","links":{"self":"https://wellknown.network/agents/netmon/record.json","html":"https://wellknown.network/agents/netmon","markdown":"https://wellknown.network/agents/netmon/record.md","api":"https://wellknown.network/api/v1/agents/netmon","status":"https://wellknown.network/api/v1/agents/netmon/status","claim":"https://wellknown.network/agents/netmon/claim","claimApi":"https://wellknown.network/api/v1/claims","claimDescriptor":"https://wellknown.network/agents/netmon/claim.json","badge":"https://wellknown.network/agents/netmon/badge.svg","openapi":"https://wellknown.network/openapi.json","history":"https://wellknown.network/api/v1/agents/netmon/history","tools":"https://wellknown.network/api/v1/agents/netmon/tools"},"ard":{"identifier":"urn:air:wellknown.network:record:netmon","type":"application/mcp-server-card+json"},"kind":"mcp_server","declared":{"name":"Netmon","summary":"Query devices, alerts, syslog, Suricata IDS, NetFlow and captures on your Netmon appliance.","description":"Query devices, alerts, syslog, Suricata IDS, NetFlow and captures on your Netmon appliance.","publisher":{"name":"com.netmon","url":null},"homepage":"https://netmon.com/mcp-server/","repository":"https://github.com/Netmon-Services/netmon-mcpd","version":"0.1.9","license":null,"protocols":["mcp"],"tags":[],"pricing":null,"endpoints":[],"skills":null,"tools":null,"extra":{"updatedAt":"2026-09-11T14:59:15.338316Z","publishedAt":"2026-09-11T14:59:15.338316Z","registryName":"com.netmon/netmon"},"attribution":{"kind":"mcp_registry","name":"mcp_registry","repoUrl":"mcp_registry","summary":"mcp_registry","version":"mcp_registry","description":"mcp_registry","homepageUrl":"mcp_registry","publisherName":"mcp_registry"}},"derived":{"capabilities":[],"categories":[],"language":"fr"},"observed":{"status":"live","statusReason":"Responded 15d ago.","lastOkAt":"2026-09-26T03:24:47.193Z","lastProbedAt":"2026-09-26T03:24:47.193Z","statusComputedAt":"2026-09-26T03:25:22.477Z","reliability30d":{"probes":53,"successRate":1,"p50Ms":96,"basis":"service","measures":{"availability":"availability","latency":"response time","tools":"tool surface observed","summary":"Checks reached the service itself."},"checks":{"total":53,"ok":53,"authBoundaryOk":0,"serviceOk":53,"note":"Counted from the observation rows for the window, checks of the server only (HTTP, A2A card, MCP initialize). ok = authBoundaryOk + serviceOk. `probes` is the sum of daily rollups and includes registry checks, so it can differ from `total`."}},"latestObservations":[{"at":"2026-09-26T03:24:47.193Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":85,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-25T21:23:48.893Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":86,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-25T15:26:45.370Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":100,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-25T09:31:00.945Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":87,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-25T03:25:00.111Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":84,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-24T21:26:03.507Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":95,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-24T15:29:35.707Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":100,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-24T09:24:00.386Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":87,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-24T03:23:48.872Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":100,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}},{"at":"2026-09-23T21:26:03.757Z","kind":"mcp_initialize","ok":true,"httpStatus":200,"latencyMs":84,"error":null,"detail":{"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"toolCount":36,"toolsHash":"9fbf852683b33e74ed127abcf36544bcde6b126cd93273ac3ac98f610ff81ea0","serverName":"netmon7-demo","capabilities":["tools","prompts","resources","logging"],"serverVersion":"1.0.0","protocolVersion":"2025-06-18"}}],"tools":[{"name":"get_network_entity_info","description":"Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolu"},{"name":"arp_lookup","description":"Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable in"},{"name":"ping","description":"Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server, not on the mcpmond ho"},{"name":"traceroute","description":"Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).\n\nThe probe runs ON the netmon server — hops refle"},{"name":"port_map","description":"Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).\n\nServer runs `nmap -oX - -p <ports> --open <ip"},{"name":"search_ip","description":"Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.\n\nReturns one"},{"name":"syslog_search","description":"Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.\n\nFilters (all optional): device_id, severity"},{"name":"eventlog_search","description":"Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.\n\nSeverity is the raw Wind"},{"name":"eve_search","description":"Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.\n\nSeverity is Suricata-native: 1=high, 2=medium, 3=low"},{"name":"eve_get","description":"Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/c"},{"name":"log_severity_summary","description":"Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.\n\nstream='syslog'   → wraps /api/syslog/sevSum  "},{"name":"syslog_facets","description":"Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pu"},{"name":"netflow_search","description":"Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated serve"},{"name":"netflow_raw_search","description":"Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).\n\nHORIZON — read this before choosing a window: the raw tab"},{"name":"flow_summary","description":"Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual \"other\" bucket plus overall totals. W"},{"name":"device_list","description":"List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.\n\nFilters (all optional, combinable):\n  - tag: ta"},{"name":"device_get","description":"Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow"},{"name":"device_find","description":"Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).\n\nUse devi"},{"name":"overwatch_summary","description":"High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregate"},{"name":"snmp_test","description":"Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 6"},{"name":"snmp_walk_last","description":"Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.\n\nAl"},{"name":"snmp_walk_run","description":"Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).\n\nSLOW and SIDE-EFFECTING. Server-side this shells ou"},{"name":"agent_services","description":"List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).\n\nReturns rows of {Name"},{"name":"agent_processes","description":"List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).\n\nReturns rows as r"},{"name":"alerts_list","description":"List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_do"},{"name":"alerts_history","description":"Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch"},{"name":"maintenance_windows_list","description":"Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintena"},{"name":"tags_list","description":"List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: "},{"name":"top_bandwidth","description":"Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that"},{"name":"arp_table","description":"Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses ar"},{"name":"interfaces_search","description":"Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, whi"},{"name":"device_metric_summary","description":"Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.\n\nm"},{"name":"agent_disk_usage","description":"Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath whi"},{"name":"capture_list","description":"Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most"},{"name":"capture_get","description":"Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status f"},{"name":"speedtest_history","description":"Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.\n\nEach row carries"}],"package":null,"toolSurface":null,"endpointFacts":[]},"verification":{"claimed":false,"claimedAt":null,"proofs":[]},"provenance":{"sources":[{"source":"mcp_registry","key":"com.netmon/netmon","url":"https://registry.modelcontextprotocol.io/v0/servers/com.netmon%2Fnetmon","firstSeenAt":"2026-09-05T20:18:53.003Z","fetchedAt":"2026-10-09T09:23:00.114Z","normalizedAt":"2026-10-09T09:23:00.114Z"}]},"firstSeenAt":"2026-09-05T20:18:53.003Z","updatedAt":"2026-09-26T10:25:03.673Z"}