Graylog MCP Server
by jperelliio.github.jperelli/graylog-mcpv1.3.0
Query logs from Graylog: get streams, search messages, aggregate, and get full data.
context tax
queued
security
queued
cold start
queued
freshness
Maintained3mo ago
Install Graylog MCP server
Install in Claude Code
claude mcp add graylog-jperelli -e GRAYLOG_BASE_URL_INSTANCE_1='<graylog-base-url-instance-1>' -e GRAYLOG_API_TOKEN_INSTANCE_1='<graylog-api-token-instance-1>' -- npx -y @jperelli/graylog-mcpInstall in Cursor
{
"mcpServers": {
"graylog-jperelli": {
"command": "npx",
"args": [
"-y",
"@jperelli/graylog-mcp"
],
"env": {
"GRAYLOG_BASE_URL_INSTANCE_1": "<graylog-base-url-instance-1>",
"GRAYLOG_API_TOKEN_INSTANCE_1": "<graylog-api-token-instance-1>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"graylog-jperelli": {
"command": "npx",
"args": [
"-y",
"@jperelli/graylog-mcp"
],
"env": {
"GRAYLOG_BASE_URL_INSTANCE_1": "<graylog-base-url-instance-1>",
"GRAYLOG_API_TOKEN_INSTANCE_1": "<graylog-api-token-instance-1>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"graylog-jperelli": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"@jperelli/graylog-mcp"
],
"env": {
"GRAYLOG_BASE_URL_INSTANCE_1": "<graylog-base-url-instance-1>",
"GRAYLOG_API_TOKEN_INSTANCE_1": "<graylog-api-token-instance-1>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"graylog-jperelli": {
"command": "npx",
"args": [
"-y",
"@jperelli/graylog-mcp"
],
"env": {
"GRAYLOG_BASE_URL_INSTANCE_1": "<graylog-base-url-instance-1>",
"GRAYLOG_API_TOKEN_INSTANCE_1": "<graylog-api-token-instance-1>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| GRAYLOG_BASE_URL_INSTANCE_1 | yes | — | Base URL of the first Graylog instance, e.g. http://graylog.example.com:9000 |
| GRAYLOG_API_TOKEN_INSTANCE_1 | yes | yes | API token for the first Graylog instance (used as the HTTP Basic username). |
| GRAYLOG_LABEL_INSTANCE_1 | — | — | Optional human-readable label for the first instance (default: instance_1). |
Freshness
Maintained — last maintenance signal 3mo ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-07-17 · 3mo ago · GitHub
Latest release
2026-07-17 · 3mo ago · GitHub · v1.3.0
Package published
no data · npm/PyPI
Registry entry updated
2026-07-17 · 3mo ago · official registry · v1.3.0
FAQ
›How do I install the Graylog MCP server in Claude Code?
Run: claude mcp add graylog-jperelli -e GRAYLOG_BASE_URL_INSTANCE_1='<graylog-base-url-instance-1>' -e GRAYLOG_API_TOKEN_INSTANCE_1='<graylog-api-token-instance-1>' -- npx -y @jperelli/graylog-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does Graylog require an API key?
Yes. It expects GRAYLOG_BASE_URL_INSTANCE_1, GRAYLOG_API_TOKEN_INSTANCE_1, of which 1 is a secret.
›Can I use Graylog as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is Graylog in the official MCP registry?
Yes, as io.github.jperelli/graylog-mcp.
Alternatives to Graylog
Other monitoring & observability MCP servers.