# zeek-mcp

> Use this tool when you need to analyze and query network security monitoring data from Zeek and Suricata, providing intelligent log parsing and insights to enhance threat detection and incident response. It solves problems related to network security monitoring, log management, and threat analysis, offering a robust interface for querying and analyzing security data. The zeek-mcp tool accepts network security logs as input and outputs parsed, queryable data for further analysis and investigation.

Canonical page: https://skillsregistry.net/skills/solomonneas-zeek-mcp  
JSON: https://api.skillsregistry.net/v1/skills/solomonneas-zeek-mcp

## Description

An MCP server for Zeek and Suricata, providing intelligent log parsing, querying, and analysis over network security monitoring data.

## Trust

- **Trust score (0–1):** 0.97
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** monitoring
- **Updated:** 2026-09-28

## Source

- **Source listing:** [Glama](https://glama.ai/mcp/servers/e58xzuvxz6)
- **Repository:** <https://github.com/lidless-labs/zeek-mcp>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "solomonneas-zeek-mcp"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/solomonneas-zeek-mcp` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/solomonneas-zeek-mcp/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
