process
(optional): Filter by process name
How to use it
process is exposed by the Wazuh MCP Server MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the process tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install Wazuh MCP Server
pip install git+https://github.com/socfortress/wazuh-mcp-server.gitOther tools in Wazuh MCP Server (39)
(required): Agent ID to get ports from
(optional): Filter by package architecture
(optional): Look for distinct values
(optional): Filter by process egroup
(optional): Filter by process euser
(optional): Filter by process fgroup
(optional): Filter by filename
(optional): Filter by package format (e.g., 'deb', 'rpm')
(optional): Filter by GDPR requirement
(optional): Filter by GPG13 requirement
(optional): Filter by rule group
(optional): Filter by rule level (e.g., '4' or '2-4')
(optional): Maximum number of agents to return (default: 500)
(optional): Filter by local IP address
(optional): Filter by local port
(optional): Filter by package name
(optional): Filter by process nlwp
(optional): Offset for pagination (default: 0)
(optional): Filter by PCIDSS requirement
(optional): Filter by process pgrp
(optional): Filter by process ID
(optional): Filter by process parent PID
(optional): Filter by process priority
(optional): Filter by protocol (tcp, udp)
(optional): Filter by relative directory name
(optional): Filter by remote IP address
(optional): Filter by process rgroup
(optional): List of rule IDs to filter by
(optional): Filter by process ruser
(optional): Search for elements containing the specified string
(optional): Select which fields to return
(optional): Filter by process sgroup
(optional): Sort results by field(s)
(optional): Filter by state (listening, established, etc.)
(optional): Filter by agent status (e.g., ["active"])
(optional): Filter by process suser
(optional): Filter by txqueue
(optional): Filter by package vendor
(optional): Filter by package version