# Wazuh OpenSearch Analytics

> Use this tool when you need to analyze Wazuh security logs and investigate incidents, as it enables querying and visualization of log data stored in OpenSearch databases. It solves problems such as searching alerts, monitoring logs, and generating statistics on alert patterns, providing outputs like detailed event information and alert trends. It accepts inputs like search queries and alert IDs, making it ideal for security analysts to monitor and investigate security events within their AI assistant interface.

Canonical page: https://skillsregistry.net/skills/jetbalsa-opensearch-analytics  
JSON: https://api.skillsregistry.net/v1/skills/jetbalsa-opensearch-analytics

## Description

MCP-OpenSearch-JS is a server that enables AI assistants to query and analyze Wazuh security logs stored in OpenSearch databases. The implementation provides tools for searching alerts, exploring field values, monitoring logs in real-time, visualizing alert trends, and retrieving detailed information about specific security events. Built with FastMCP and the OpenSearch client library, it features robust error handling, progress reporting for long-running operations, and configurable timeouts to prevent connection issues. This server is particularly valuable for security analysts who need to investigate security incidents, generate statistics on alert patterns, or monitor security events without leaving their AI assistant interface.

## Trust

- **Trust score (0–1):** 0.50
- **Verification tier:** unverified

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** database
- **Updated:** 2026-04-25

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/jetbalsa-opensearch-analytics)
- **Repository:** <https://github.com/cyberbalsa/mcp-opensearch-js>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "jetbalsa-opensearch-analytics"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/jetbalsa-opensearch-analytics` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/jetbalsa-opensearch-analytics/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
