# klaxon

> klaxon — sec73-klaxon. Use this tool when you need to integrate language models with security information and event management (SIEM) systems, enabling plain-language queries and analysis of security data. It connects language models to a Wazuh SIEM cluster, providing read-only access to security data and supporting schema inspection, field coverage analysis, and decoder testing. Ideal for use cases requiring natural language interface to SIEM data, such as security monitoring and incident response.

Canonical page: https://skillsregistry.net/skills/sec73-klaxon  
JSON: https://api.skillsregistry.net/v1/skills/sec73-klaxon

## Description

An MCP server that connects language models to a Wazuh SIEM cluster, enabling read-only plain-language queries, schema inspection, field coverage analysis, and decoder testing.

## Trust

- **Trust score (0–1):** 0.00
- **Verification tier:** scanned
- **Last scanned:** 2026-08-29

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** other
- **Updated:** 2026-08-29

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/ns7z702rks)
- **Repository:** <https://github.com/sec73/klaxon>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "sec73-klaxon"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/sec73-klaxon` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/sec73-klaxon/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
