Skip to main content
Glama
lcaliani

graylog-mcp

by lcaliani

Graylog MCP Server

A minimal MCP (Model Context Protocol) server in JavaScript that integrates with Graylog.

Features

  • JavaScript MCP server

  • Tools: fetch_graylog_messages (query Graylog and return messages)

  • Multi-instance support — query multiple Graylog servers from a single MCP server

Related MCP server: Graylog MCP Server

Requirements

  • Node.js 18+

Configuration

Configure one or more Graylog instances using numbered env vars:

Variable

Required

Description

GRAYLOG_BASE_URL_INSTANCE_N

yes

Graylog base URL for instance N

GRAYLOG_API_TOKEN_INSTANCE_N

yes

API token for instance N

GRAYLOG_LABEL_INSTANCE_N

no

Human-readable label (default: instance_N)

Replace N with 1, 2, 3, … to register as many instances as needed. Only instances with both BASE_URL and API_TOKEN set will be active.

Use with an MCP client

No installation needed — npx downloads and runs the server automatically.

Claude Code

claude mcp add graylog-mcp npx @lcaliani/graylog-mcp-server@latest \
  -e GRAYLOG_BASE_URL_INSTANCE_1=http://your-graylog-production.example.com:9000 \
  -e GRAYLOG_API_TOKEN_INSTANCE_1=your_production_token \
  -e GRAYLOG_LABEL_INSTANCE_1=production \
  -e GRAYLOG_BASE_URL_INSTANCE_2=http://your-graylog-staging.example.com:9000 \
  -e GRAYLOG_API_TOKEN_INSTANCE_2=your_staging_token \
  -e GRAYLOG_LABEL_INSTANCE_2=staging

Or add it manually to ~/.claude.json:

{
  "mcpServers": {
    "graylog-mcp": {
      "command": "npx",
      "args": ["@lcaliani/graylog-mcp-server@latest"],
      "env": {
        "GRAYLOG_BASE_URL_INSTANCE_1":  "http://your-graylog-production.example.com:9000",
        "GRAYLOG_API_TOKEN_INSTANCE_1": "your_production_token",
        "GRAYLOG_LABEL_INSTANCE_1":     "production",

        "GRAYLOG_BASE_URL_INSTANCE_2":  "http://your-graylog-staging.example.com:9000",
        "GRAYLOG_API_TOKEN_INSTANCE_2": "your_staging_token",
        "GRAYLOG_LABEL_INSTANCE_2":     "staging"
      }
    }
  }
}

Cursor

Add to ~/.cursor/mcp.json:

{
  "mcpServers": {
    "graylog-mcp": {
      "command": "npx",
      "args": ["@lcaliani/graylog-mcp-server@latest"],
      "env": {
        "GRAYLOG_BASE_URL_INSTANCE_1":  "http://your-graylog-production.example.com:9000",
        "GRAYLOG_API_TOKEN_INSTANCE_1": "your_production_token",
        "GRAYLOG_LABEL_INSTANCE_1":     "production",

        "GRAYLOG_BASE_URL_INSTANCE_2":  "http://your-graylog-staging.example.com:9000",
        "GRAYLOG_API_TOKEN_INSTANCE_2": "your_staging_token",
        "GRAYLOG_LABEL_INSTANCE_2":     "staging"
      }
    }
  }
}

Claude Desktop

Config file locations:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json

  • Linux: ~/.config/claude-desktop/claude_desktop_config.json

  • Windows: %APPDATA%\Claude\claude_desktop_config.json

Use the same JSON structure shown above for Cursor.


Use

Once configured, the fetch_graylog_messages tool becomes available and will be automatically called when needed. Example prompts:

Search for the latest 20 error logs of the example application in the last 15 minutes.
Search for the latest 20 error logs of the example application in the last 15 minutes.
Query the "staging" Graylog instance.

Available tools

fetch_graylog_messages

Fetch messages from Graylog.

Parameters:

  • query (string, required): Search query. Example: level:ERROR AND service:api.

  • instance (string, optional): Label of the Graylog instance to query. Defaults to the first configured instance.

  • searchTimeRangeInSeconds (number, optional): Relative time range in seconds. Default: 900 (15 minutes).

  • searchCountLimit (number, optional): Max number of messages. Default: 50.

  • fields (string, optional): Comma-separated fields to include. Default: * (all fields).

Troubleshooting

  • Ensure at least GRAYLOG_BASE_URL_INSTANCE_1 and GRAYLOG_API_TOKEN_INSTANCE_1 are set.

  • Verify Node.js 18+ is installed.

  • Set DEBUG=true in the env to enable verbose logging to stderr.

License

MIT

Available Tools

1 tool
fetch_graylog_messagesA

Fetch messages from a Graylog instance.

Active instances: "instance_1". Default instance: "instance_1".

Use the "instance" parameter to target a specific Graylog server. Each instance is identified by its label (set via GRAYLOG_LABEL_INSTANCE_N env var). If no label is configured, instances are identified as "instance_1", "instance_2", etc.

ParametersJSON Schema
NameRequiredDescriptionDefault
instanceNoWhich Graylog instance to query. Active: "instance_1". Default: "instance_1".
queryYesThe search query, using Graylog query syntax (e.g. "level:ERROR AND service:api").
searchTimeRangeInSecondsNoRelative time range in seconds. Default: 900 (15 minutes).
searchCountLimitNoMax number of messages to return. Default: 50.
fieldsNoComma-separated list of fields to return. Default: '*' (all fields).

TDQS

A3.7/5.0
Behavior2/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

With no annotations provided, the description carries the full burden of disclosing behavioral traits. It only states 'fetch messages' without mentioning side effects, permissions, rate limits, error handling, or response format. This is insufficient for a tool with no annotation backup.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness3/5

Is the description appropriately sized, front-loaded, and free of redundancy?

The description is relatively short but contains repetition about instances (e.g., 'Active instances: instance_1' and 'Default instance: instance_1'). It could be more terse without losing clarity.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness3/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

The tool has 5 parameters with full schema coverage, but no output schema or sibling tools. The description covers instance selection and parameter defaults, but lacks information on return format, pagination, or how to handle large result sets.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters4/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema description coverage is 100%, but the description adds value beyond the schema by explaining instance label configuration, providing a query syntax example, and stating defaults for time range, count limit, and fields. This helps agents use parameters correctly.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

The description clearly states the verb 'fetch' and the resource 'messages from a Graylog instance'. It specifies the active and default instance, leaving no ambiguity about the tool's purpose.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines4/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description explains how to target a specific instance using the 'instance' parameter and how instances are identified. It provides clear context for instance selection, though it does not include explicit exclusions or when not to use the tool.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.

Tool Schema Changelog

Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.

  1. 1 tool updatev1.0.4
    • First observedfetch_graylog_messages

TDQS

A3.6/5.0
Disambiguation5/5

With only one tool, there is no possibility of confusion between tools. The tool's purpose is clearly stated.

Naming Consistency5/5

The single tool name 'fetch_graylog_messages' follows a consistent verb_noun pattern, which is clear and predictable.

Tool Count2/5

The server has only one tool for a domain (Graylog) that typically requires multiple operations. One tool feels insufficient for the apparent scope, leading to a score of 2.

Completeness1/5

The server provides only a single fetch tool, lacking any other operations such as search, create, update, or delete for messages, nor any management of streams or dashboards. This is severely incomplete for a Graylog integration.

Maintenance

ActivityInactive
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables AI assistants to query and analyze logs from Graylog instances using universal search with relative or absolute time windows, supporting both full result retrieval and lightweight count-only queries.
    23
    1
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Enables AI assistants to search and analyze logs in Graylog using three powerful tools: generic log search with Lucene queries, smart UUID/trace ID lookup across multiple fields, and stream-specific message retrieval with automatic field normalization.
    21
    MIT
  • A
    license
    D
    quality
    D
    maintenance
    Integrates AI assistants with Graylog to query and analyze log data using Elasticsearch syntax and stream-specific filtering. It enables users to perform advanced searches, retrieve log statistics, and manage Graylog streams through natural language.
    9
    11
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    Provides read-only access to Loki, Prometheus, and Tempo APIs, enabling natural language queries for logs, metrics, and traces. Supports multiple instances and authentication via bearer tokens.
    1
    MIT

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/lcaliani/graylog-mcp'

If you have feedback or need assistance with the MCP directory API, please join our Discord server