Skip to content

⚙️ Tenzir MCP Server

PyPI License

A Model Context Protocol (MCP) server that enables AI assistants to interact with Tenzir—a data pipeline engine for security operations.

Warning

This MCP server is not actively maintained right now. tenzir/skills is superseding it and is where new work is happening.

This MCP server provides tools for executing pipelines written in the Tenzir Query Language (TQL)), working with Open Cybersecurity Schema Framework (OCSF), managing packages, generating parsers, and exploring documentation.

✨ Features

  • Pipeline Execution: Run TQL pipelines and tests
  • Documentation Access: Search and browse embedded Tenzir documentation with cross-reference support
  • OCSF Integration: Query and work with OCSF definitions, event classes, objects, and profiles.
  • Package Management: Create and manage Tenzir packages with operators, pipelines, enrichment contexts, and tests
  • Code Generation: Auto-generate TQL parsers and OCSF mapping packages

📦 Installation

Use Docker as the fastest way to get started:

docker run -i tenzir/mcp

Or use uvx when you have a local Tenzir installation:

uvx tenzir-mcp

📚 Documentation

Consult our setup guide for installation and MCP client configuration.

We also provide a reference that explains usage and available tools.

🤝 Contributing

Want to contribute? We're all-in on agentic coding with Claude Code! The repo comes pre-configured with our custom plugins—just clone and start hacking.

📜 License

This project is licensed under the Apache License 2.0.

About

Tenzir MCP server

Resources

Code of conduct

Contributing

Security policy

Stars

8 stars

Watchers

1 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages