Journald MCP server
Incident forensic with log files analyzing
Journald MCP Server
An MCP server for accessing systemd journal logs.
Features
- List systemd units from journal logs
- List syslog identifiers from journal logs
- Get datetime of first journal entry
- Filter journal entries by datetime range (since/until)
- Filter by systemd unit or syslog identifier
- Filter by message content (case-insensitive substring matching)
- Natural language datetime parsing (e.g., "2 hours ago", "yesterday at 3pm")
- List units and identifiers within specific time ranges
Installation
# Install dependencies
uv sync
Usage
Run as non-root: Give the user systemd-journal group access usermod -aG systemd-journal $USER
Run the server with:
uv run server.py [OPTIONS]
CLI Options
--transport: Transport protocol to use (stdio,sse, orstreamable-http). Default:stdio--port: Port to listen on for HTTP transport (ignored forstdiotransport). Default:3002--log-level: Logging level (DEBUG,INFO,WARNING,ERROR,CRITICAL). Default:INFO
Examples
-
Run with stdio transport (default, for MCP clients that communicate via stdin/stdout):
python server.py -
Run with HTTP transport on custom port:
python server.py --transport streamable-http --port 8080 -
Run with SSE transport:
python server.py --transport sse --port 3000 -
Run with debug logging:
python server.py --log-level DEBUG
MCP Integration
The server provides the following MCP resources and tools:
Resources
journal://units: List unique systemd units from journal logs (all accessible time)journal://syslog-identifiers: List unique syslog identifiers from journal logs (all accessible time)journal://first-entry-datetime: Get the datetime of the first entry in the journaljournal://units/{since}/{until}: List unique systemd units within a specified time rangejournal://syslog-identifiers/{since}/{until}: List unique syslog identifiers within a specified time range
Tools
-
get_journal_entries: Get journal entries with datetime filtering- Parameters:
since(optional),until(optional),unit(optional),identifier(optional),message_contains(optional),limit(default: 100) - Returns: List of entries with timestamp, unit, identifier, and message
- Example: Get logs from last 2 hours containing "error":
since="2 hours ago", message_contains="error"
- Parameters:
-
get_recent_logs: Get recent journal logs from the last N minutes- Parameters:
minutes(default: 60),unit(optional),limit(default: 50) - Returns: Formatted string of recent log messages
- Parameters:
Datetime Input Format
The server uses natural language datetime parsing via the dateparser library. Supported formats include:
- Relative times: "2 hours ago", "yesterday at 3pm", "last week", "now"
- Absolute times: "2024-01-15 14:30", "2024-01-15T14:30:00"
- Mixed: "today at 9am", "tomorrow 3pm"
All times are interpreted as UTC and returned in human-readable format: "YYYY-MM-DD HH:MM:SS UTC"
Development
This project uses:
- Python 3.12+
- MCP FastMCP
- systemd-python for journal access
- Click for CLI interface
- dateparser for natural language datetime parsing
Project Structure
journald-mcp-server/
├── journald_mcp_server/ # Main package
│ ├── __init__.py
│ ├── server.py # MCP server implementation
│ └── datetime_utils.py # Datetime parsing and formatting utilities
├── tests/ # Test suite
│ ├── __init__.py
│ └── test_server.py
├── server.py # Entry point wrapper
├── pyproject.toml
└── README.md
Running Tests
python -m pytest tests/
相關伺服器
Proxenio MCP Server
MCP server for the Proxenio verified intent network enabling AI agents to retrieve verified matches and accept introductions with inherited trust controls.
mycop
AI code security scanner with 100 built-in rules covering OWASP Top 10 and CWE Top 25
Pokemon MCP
An MCP server for Pokemon-related functionality.
Spawnpay
USDC wallets, payments, and referral earnings for AI agents on Base L2
AgentBazaar
A2A marketplace with 1800+ AI agents. Search, invoke, trade capabilities, datasets, prompts.
Google My Business MCP
Connect Google My Business to Claude or ChatGPT via Two Minute Reports MCP. Analyze profile views, customer actions, and top-performing locations to improve visibility and conversions.
mlp-tax
Deterministic MLP tax computation engine. 6 tools: basis projection, estate planning, sell vs hold comparison, MLP vs ETF tax analysis, distribution stress test, and MLP reference data. Returns IRS-cited calculations for K-1 basis tracking, §751 recapture, and §199A QBI.
BTC & SOL Futures Analiz Dashboard
A real-time dashboard for comprehensive analysis of Bitcoin and Solana futures markets.
mcp-server-openai-bridge
Bridge to OpenAI API. Access GPT, GPT-o and other OpenAI models through MCP.
Ingero
eBPF-based GPU causal observability agent with MCP server. Traces CUDA Runtime/Driver APIs via uprobes and host kernel events via tracepoints to build causal chains explaining GPU latency. 7 MCP tools for AI-assisted GPU debugging and root cause analysis. <2% overhead, production-safe.