Skip to content

Cloud and infrastructure

Cloud providers, orchestration, and observability platforms an agent can inspect and operate. 16 integrations, 255 tools.

Tool names below are the fully qualified names an agent sees once the integration is connected. Where an integration offers more than one connection, the names shown use the primary connection’s prefix; connecting through another variant prefixes its tools with that variant’s own integration ID instead. See Tool Catalog for how tools are granted and named.

6 tools. Credentials are supplied in the connection settings.

ToolDescriptionArguments
aws-shield_describe_attackDescribe a single DDoS attack by its attack id. Returns full attack detail: vectors, traffic counters, properties (top contributors, geos, sources), and applied mitigations.required attack_id
aws-shield_describe_protectionDescribe a single AWS Shield Advanced protection by its protection id OR by the protected resource’s ARN — provide exactly one of the two. Returns the protection’s full metadata.optional protection_id, resource_arn
aws-shield_describe_subscriptionReturn the account’s AWS Shield Advanced subscription details: start/end time, auto-renew status, proactive engagement status, and subscription limits. Useful for billing reviews or expiration checks.—
aws-shield_get_subscription_stateReturn the current AWS Shield Advanced subscription state for the account: ‘ACTIVE’ or ‘INACTIVE’. Use this as the fast preflight before any other Shield tool — most Shield APIs require an active subscription.—
aws-shield_list_attacksList DDoS attack summaries observed by AWS Shield Advanced in a time window, optionally filtered by resource ARN. Returns lightweight attack metadata (id, target, vectors, start/end). Use describe_attack for full detail.optional end_time, max_results, next_token, resource_arns, start_time
aws-shield_list_protectionsList AWS Shield Advanced protections in the account, optionally filtered by resource ARN, protection name, or AWS resource type. Returns protection metadata (id, name, resource ARN, health check associations). Paginate via next_token.optional max_results, next_token, protection_names, resource_arns, resource_types

15 tools. Connect with Basic auth.

ToolDescriptionArguments
cisco-catalyst_apply_anc_policyApply Adaptive Network Control (ANC) policy to an endpointrequired epId, ancPolicy
optional granularAncPolicy
cisco-catalyst_create_profiling_ruleCreate a new profiling rule for device classificationrequired ruleName, conditions, actions
optional priority
cisco-catalyst_get_acl_statisticsGet performance statistics for a specific ACLrequired deviceId, aclName
optional timeRange
cisco-catalyst_get_anc_policiesList all available ANC policiesoptional limit, offset
cisco-catalyst_get_client_detailsGet detailed information about a network client device or user (macAddress or userId is required)optional macAddress, userId
cisco-catalyst_get_deviceGet detailed information for a specific network devicerequired deviceId
cisco-catalyst_get_device_aclsGet ACLs configured on a specific devicerequired deviceId
optional interfaceType
cisco-catalyst_get_endpoint_detailsGet detailed information about a specific endpointrequired epId
cisco-catalyst_get_issue_detailsGet detailed context and recommended actions for a network issue or alert (issueId or clientMac is required)optional clientMac, issueId
cisco-catalyst_list_devicesList all network devices from Catalyst Center with optional filteringoptional managementIp, serialNumber
cisco-catalyst_list_profiling_rulesList profiling rules with optional filtersoptional limit, offset, ruleType
cisco-catalyst_list_sitesList site hierarchy or filter by site name from Catalyst Centeroptional name
cisco-catalyst_query_endpointsQuery endpoints with optional filtersoptional ipAddress, limit, macAddress, offset, profiling
cisco-catalyst_register_endpointRegister a new endpoint in the systemrequired macAddress
optional profileId, staticGroupAssignment
cisco-catalyst_revoke_anc_policyRevoke ANC policy from an endpointrequired epId

23 tools. Connect with Basic auth.

ToolDescriptionArguments
cisco-fmc_create_access_ruleCreate a new access-control rule inside an AC policy. By default the rule is appended to the bottom of the rule list; set insert_before or insert_after to position it.required policy_id, name, action
optional destination_networks, destination_zones, domain_uuid, enabled, insert_after, insert_before, log_begin, log_end, send_events_to_fmc, source_networks, source_zones
cisco-fmc_create_network_objectCreate a new network-layer object.required name, value, kind
optional description, domain_uuid
cisco-fmc_delete_access_ruleDelete an access-control rule by ID. Does NOT deploy — call deploy_to_devices separately to push the removal to firewalls.required policy_id, rule_id
optional domain_uuid
cisco-fmc_deploy_to_devicesPush pending configuration changes to one or more devices. Returns a task descriptor immediately (deployment is async) — poll get_task_status with the returned id until state is Success or Failed.required device_ids
optional deployment_note, domain_uuid, force_deploy, ignore_warning
cisco-fmc_get_access_policyGet a single AC policy by UUID (default action, inheritance, etc.).required policy_id
optional domain_uuid
cisco-fmc_get_deviceGet full detail for a single managed device (interfaces, HA peer, health, deployment status, etc.) by its FMC UUID.required device_id
optional domain_uuid
cisco-fmc_get_intrusion_policyGet a single intrusion policy by UUID (base policy, rule overrides, etc.).required policy_id
optional domain_uuid
cisco-fmc_get_network_objectGet a single network object by ID. kind selects the underlying type-specific endpoint (Host / Network / Range / FQDN).required object_id, kind
optional domain_uuid
cisco-fmc_get_server_infoGet the FMC server’s version metadata: serverVersion, geoVersion, vdbVersion, sruVersion (some optional depending on the FMC build).—
cisco-fmc_get_task_statusGet the state of an async FMC task (deployment, device push, etc.). State is one of: Pending, Running, Success, Failed, Retry. Returns the full task envelope including any error messages on Failed.required task_id
optional domain_uuid
cisco-fmc_list_access_policiesList access-control (AC) policies in the given domain. AC policies are the top-level rule containers attached to devices.optional domain_uuid, limit
cisco-fmc_list_access_rulesList access-control rules inside one AC policy. Returns the rules in policy-evaluation order.required policy_id
optional domain_uuid, filter_expr, limit
cisco-fmc_list_deployable_devicesList devices with pending (undeployed) configuration changes in the given domain. Each entry includes the device ID and the version that would be deployed.optional domain_uuid, limit
cisco-fmc_list_devicesList managed FTD / Firepower devices in the given FMC domain. Returns ID, name, model, software version, health, and HA / cluster membership for each device. Paginated.optional domain_uuid, limit
cisco-fmc_list_domainsList all FMC domains the current credentials can access. Returns a name → UUID mapping. Domains partition FMC for multi-tenant or segmented (defense) deployments; the result feeds the optional domain_uuid parameter on every other tool.—
cisco-fmc_list_intrusion_policiesList Snort 2 / Snort 3 intrusion-prevention policies in the given domain. Read-only — intrusion-rule CRUD lives in a separate admin workflow.optional domain_uuid, limit
cisco-fmc_list_network_groupsList network groups (named collections of network objects + inline IP/CIDR literals) in the given domain.optional domain_uuid, limit, name_filter
cisco-fmc_list_network_objectsList network-layer objects (Hosts, Networks, Ranges, FQDNs) in the given domain.optional domain_uuid, limit, name_filter
cisco-fmc_list_policy_assignmentsList policy → device assignments in the given domain. Useful before mutating a policy to know which devices will receive the change on the next deployment.optional domain_uuid, limit
cisco-fmc_list_security_zonesList security zones in the given domain. Zone object IDs are needed when crafting access-control rules whose match criteria include source / destination zones.optional domain_uuid, limit
cisco-fmc_search_audit_recordsSearch the FMC audit trail. filter_expr accepts FMC audit filter keys joined by ;. Verified live against FMC 7.2.9: username.optional domain_uuid, filter_expr, limit
cisco-fmc_update_access_ruleUpdate fields on an existing access-control rule.required policy_id, rule_id
optional action, destination_networks, domain_uuid, enabled, name, source_networks
cisco-fmc_update_network_group_membersAppend / remove / replace members of an existing network group.required group_id, op
optional domain_uuid, literals, object_ids

25 tools. Credentials are supplied in the connection settings.

ToolDescriptionArguments
cisco-secure-workload_count_inventoryCount workloads matching an inventory filter. Faster than search when only the count is needed.required filter_query
optional scope_name
cisco-secure-workload_create_alertCreate a new alert with a name, severity level, and trigger filter. Alerts notify when specific conditions are met in the workload environment.required name, severity, alert_filter
cisco-secure-workload_create_applicationCreate a new application (workspace) within a scope. Applications are containers for security policies.required app_scope_id, name
optional description, primary
cisco-secure-workload_create_policyCreate a new micro-segmentation policy within an application. Defines traffic rules between consumer (source) and provider (destination) inventory filters with ALLOW or DENY action.required application_id, consumer_filter_id, provider_filter_id, policy_action
optional priority, rank, version
cisco-secure-workload_create_scopeCreate a new scope under a parent scope. Scopes use filter queries to define which workloads belong to them (e.g. by subnet or label).required short_name, parent_app_scope_id
optional short_query
cisco-secure-workload_delete_policyDelete a policy by its ID.required policy_id
cisco-secure-workload_disable_enforcementDisable policy enforcement for an application. This deactivates micro-segmentation rules without deleting policies.required application_id
cisco-secure-workload_enable_enforcementEnable policy enforcement for an application. This activates micro-segmentation rules on workloads in the scope.required application_id
cisco-secure-workload_get_alertGet details of a specific alert by its ID.required alert_id
cisco-secure-workload_get_applicationGet details of a specific application (workspace) by its ID.required application_id
cisco-secure-workload_get_application_detailsGet full details of an application including its policies, clusters, and enforcement status. More comprehensive than get_application.required application_id
cisco-secure-workload_get_policyGet details of a specific policy by its ID.required policy_id
cisco-secure-workload_get_scopeGet details of a specific scope by its ID.required scope_id
cisco-secure-workload_get_sensorGet details of a specific sensor (software agent) by its ID.required sensor_id
cisco-secure-workload_get_top_flowsGet the top N flows ranked by a metric (packets, bytes) for a given dimension (source IP, destination port, protocol). Useful for identifying top talkers or busiest connections.required filter_query, start_time, end_time, dimension
optional metric, threshold
cisco-secure-workload_get_workloadGet detailed information about a specific workload including hostname, OS, interfaces, labels, and running processes.required workload_id
cisco-secure-workload_get_workload_vulnerabilitiesGet known vulnerabilities (CVEs) for a specific workload. Returns vulnerability details based on installed packages.required workload_id
cisco-secure-workload_list_alertsList all configured alerts in Cisco Secure Workload.—
cisco-secure-workload_list_applicationsList all applications (workspaces) in Cisco Secure Workload. Applications group policies for a given scope.—
cisco-secure-workload_list_policiesList all policies for an application. Policies define allowed or denied traffic between consumer and provider inventory filters.required application_id
optional version
cisco-secure-workload_list_scopesList all scopes (organizational groupings) in Cisco Secure Workload. Scopes define the boundaries for policy enforcement and visibility.—
cisco-secure-workload_list_sensorsList all sensors (software agents) deployed on workloads. Shows sensor status, version, and host information.—
cisco-secure-workload_search_change_logsSearch the audit change logs for API operations performed on the Cisco Secure Workload instance. Useful for tracking who made what changes and when.required start_time, end_time
optional limit, method, uri
cisco-secure-workload_search_flowsSearch network flow records with filters. Returns flow data including source/destination IPs, ports, protocols, byte/packet counts, and policy decisions.required filter_query, start_time, end_time
optional limit, offset
cisco-secure-workload_search_inventorySearch the workload inventory using filter queries. Returns matching hosts, VMs, and containers with their attributes (IP, hostname, OS, labels, tags).required filter_query
optional limit, offset, scope_name

13 tools. Connect with Basic auth.

ToolDescriptionArguments
cisco-wireless-lan-controller_create_wlanCreate a new WLAN/SSID on the controller. Requires a unique profile name, a WLAN ID (1-4096), and the broadcast SSID. The WLAN is created disabled unless ‘enabled’ is set to true.required profile_name, wlan_id, ssid
optional enabled
cisco-wireless-lan-controller_delete_wlanDelete a WLAN/SSID from the controller by its profile name.required profile_name
cisco-wireless-lan-controller_get_access_pointGet a single access point’s CAPWAP operational data by its radio MAC address (wtp-mac), e.g. ‘aaaa.bbbb.cccc’ or ‘aa:bb:cc:dd:ee:ff’.required wtp_mac
cisco-wireless-lan-controller_get_clientGet a single wireless client’s operational data by its MAC address (client-mac list key).required client_mac
cisco-wireless-lan-controller_get_controller_summaryGet controller-wide AP operational summary (AP join statistics, per-band radio counts, predownload status) from ap-global-oper-data.optional depth
cisco-wireless-lan-controller_get_wlanGet a single WLAN/SSID configuration by its profile name.required profile_name
cisco-wireless-lan-controller_list_access_pointsList access points joined to the Catalyst 9800 controller (CAPWAP operational data: AP name, radio MAC, model, IP, join state). RESTCONF returns the full AP list; use ‘fields’/‘depth’ to trim the payload and ‘limit’ to cap results.optional depth, fields, limit
cisco-wireless-lan-controller_list_clientsList wireless clients currently associated to the controller (common operational data: client MAC, AP name/MAC, WLAN ID, association state). Use ‘fields’/‘depth’ to trim and ‘limit’ to cap.optional depth, fields, limit
cisco-wireless-lan-controller_list_rogue_apsList rogue access points detected by the controller, including classification, RSSI, and containment state.optional depth, fields, limit
cisco-wireless-lan-controller_list_rrm_radio_dataList Radio Resource Management (RRM) / RF operational data per AP radio. Choose a category: ‘auto-rf’ (channel/tx-power neighbor data), ‘radar’ (DFS radar events), ‘spectrum’ (spectrum analysis), or ‘radio-slot’ (per-slot radio info).optional category, limit
cisco-wireless-lan-controller_list_wlansList configured WLAN/SSID entries on the controller (profile name, WLAN ID, SSID, admin status, security settings).optional depth, fields, limit
cisco-wireless-lan-controller_reset_access_pointReset (reboot) an access point via the ap-reset RPC. Identify the AP by EITHER its name or its MAC address (provide exactly one). This is a disruptive operation: the AP and its clients drop while it reboots.optional ap_name, mac_addr
cisco-wireless-lan-controller_update_wlanUpdate an existing WLAN by profile name. Only the provided fields are changed (PATCH/merge). Use ‘enabled’ to toggle admin status, ‘ssid’ to rename the broadcast SSID.required profile_name
optional enabled, ssid

35 tools. Connect with API key.

ToolDescriptionArguments
cloudflare-api_export_all_rulesExport combined IP access, legacy firewall, custom WAF, lockdown, and UA rules.optional account_id, output_format, zone_id
cloudflare-api_export_custom_rulesExport custom WAF rules from the http_request_firewall_custom entrypoint.optional output_format, zone_id
cloudflare-api_export_ip_access_rulesExport all zone and account IP access rules as JSON or CSV.optional account_id, output_format, zone_id
cloudflare-api_get_account_ip_access_ruleGet a specific account-level IP access rule (account_id required).required rule_id, account_id
cloudflare-api_get_account_rulesetsList account-level rulesets (all accounts or one account_id).optional account_id, summary_only
cloudflare-api_get_dns_query_analyticsDNS query analytics via GraphQL (Pro+ / analytics entitlements often required). Cross-references low-traffic query names with configured DNS records.optional days, query_threshold, zone_id
cloudflare-api_get_dns_recordGet a DNS record by ID (zone_id required).required zone_id, record_id
cloudflare-api_get_dns_statisticsAggregate DNS record counts by type and proxied vs DNS-only.optional zone_id
cloudflare-api_get_dnssec_statusDNSSEC status and configuration for zone(s).optional zone_id
cloudflare-api_get_rule_statisticsSecurity posture overview: aggregated rule counts by category per zone.optional zone_id
cloudflare-api_get_ruleset_detailsFetch one ruleset by ID (tries each zone if zone_id omitted).required ruleset_id
optional zone_id
cloudflare-api_get_security_levelGet zone security_level setting (off/low/medium/high/under_attack).optional zone_id
cloudflare-api_get_ssl_settingsGet SSL/TLS mode (off/flexible/full/strict) for zone(s).optional zone_id
cloudflare-api_get_ssl_verification_statusSSL certificate verification / DCV status for zone(s).optional zone_id
cloudflare-api_get_tls_versionGet minimum TLS version setting for zone(s).optional zone_id
cloudflare-api_get_ua_ruleGet a User-Agent rule by ID (searches zones if zone_id omitted).required rule_id
optional zone_id
cloudflare-api_get_waf_package_rulesList rules inside a legacy WAF package (paginated internally).required package_id
optional summary_only, zone_id
cloudflare-api_get_waf_rule_detailsGet a single legacy WAF rule (tries all zones if zone_id omitted).required package_id, rule_id
optional zone_id
cloudflare-api_get_zone_ip_access_ruleGet one zone IP access rule by ID (searches zones if zone_id omitted).required rule_id
optional zone_id
cloudflare-api_get_zone_lockdownGet one Zone Lockdown by ID (searches zones if zone_id omitted).required lockdown_id
optional zone_id
cloudflare-api_get_zone_security_settingsReturn all zone settings (includes security-related keys).optional summary_only, zone_id
cloudflare-api_list_account_ip_access_rulesList account-wide IP access rules (paginated per account).optional account_id, summary_only
cloudflare-api_list_accountsList Cloudflare accounts visible to the API token (paginated internally).optional summary_only
cloudflare-api_list_custom_rulesList custom WAF rules from the http_request_firewall_custom entrypoint ruleset.optional summary_only, zone_id
cloudflare-api_list_dns_recordsList DNS records for zone(s); optional type/name filters.optional name, record_type, summary_only, zone_id
cloudflare-api_list_firewall_rulesList legacy firewall rules for a zone (deprecated API; read-only).optional summary_only, zone_id
cloudflare-api_list_legacy_rate_limitsList legacy rate limit rules (deprecated /rate_limits) per zone.optional summary_only, zone_id
cloudflare-api_list_managed_rulesetsList rulesets configured on a zone (WAF managed rules entrypoints).optional summary_only, zone_id
cloudflare-api_list_rate_limit_rulesList new ruleset-based rate limit rules (http_ratelimit entrypoint).optional summary_only, zone_id
cloudflare-api_list_ssl_certificatesList SSL certificate packs for zone(s).optional summary_only, zone_id
cloudflare-api_list_ua_rulesList User-Agent blocking rules for a zone.optional summary_only, zone_id
cloudflare-api_list_waf_packagesList legacy WAF packages for a zone (or all zones if zone_id omitted).optional summary_only, zone_id
cloudflare-api_list_zone_ip_access_rulesList zone-level IP access rules (allow/block) with internal pagination.optional summary_only, zone_id
cloudflare-api_list_zone_lockdownsList Zone Lockdown rules for a zone (or all zones).optional summary_only, zone_id
cloudflare-api_list_zonesList Cloudflare zones (domains) in scope for the token, or all if not filtered.optional summary_only

36 tools. Connect with API key.

ToolDescriptionArguments
datadog_cancel_downtimeCancel a Datadog downtimerequired downtime_id
datadog_create_dashboardCreate a new Datadog dashboardrequired title, layout_type, widgets
optional description, notify_list, tags, template_variables
datadog_create_downtimeCreate a downtime in Datadogrequired scope, start
optional end, message, monitor_id, monitor_tags, recurrence, timezone
datadog_create_eventCreate an event in Datadogrequired title, text
optional aggregation_key, alert_type, date_happened, host, priority, related_event_id, source_type_name, tags
datadog_create_monitorCreate a new Datadog monitorrequired name, monitor_type, query
optional message, options, priority, tags
datadog_delete_dashboardDelete a Datadog dashboardrequired dashboard_id
datadog_delete_monitorDelete a Datadog monitorrequired monitor_id
optional force
datadog_get_dashboardGet details of a specific Datadog dashboardrequired dashboard_id
datadog_get_downtimeGet details of a specific Datadog downtimerequired downtime_id
datadog_get_eventGet details of a specific Datadog eventrequired event_id
datadog_get_logs_aggregatesGet aggregated logs data from Datadogrequired query, from_time, to
optional compute, group_by, timezone
datadog_get_metric_metadataGet metadata for a specific metricrequired metric_name
datadog_get_monitorGet details of a specific Datadog monitorrequired monitor_id
optional group_states, with_downtimes
datadog_get_usage_analyzed_logsGet analyzed logs usage from Datadogrequired start_hr
optional end_hr
datadog_get_usage_hostsGet host usage from Datadogrequired start_hr
optional end_hr
datadog_get_usage_logsGet logs usage from Datadogrequired start_hr
optional end_hr
datadog_get_usage_network_hostsGet network hosts usage from Datadogrequired start_hr
optional end_hr
datadog_get_usage_summaryGet usage summary from Datadogrequired start_month
optional end_month, include_org_details
datadog_get_usage_syntheticsGet synthetics usage from Datadogrequired start_hr
optional end_hr
datadog_get_usage_timeseriesGet timeseries usage from Datadogrequired start_hr
optional end_hr
datadog_list_dashboardsList all Datadog dashboardsoptional count, filter_deleted, filter_shared, start
datadog_list_downtimesList all Datadog downtimesoptional current_only, with_creator
datadog_list_eventsList events in Datadogrequired start, end
optional exclude_aggregate, page, priority, sources, tags, unaggregated
datadog_list_metricsList available metrics in Datadogoptional query
datadog_list_monitorsList all Datadog monitorsoptional group_states, id_offset, monitor_tags, name, page, page_size, tags, with_downtimes
datadog_query_metricsQuery metrics from Datadogrequired query, from_ts, to
datadog_query_timeseries_pointsQuery timeseries data points from Datadogrequired query, from_ts, to
optional interval
datadog_search_logsSearch for logs in Datadogrequired query, from_time, to
optional paginate, sort, timezone
datadog_submit_logsSubmit logs to Datadogrequired logs
datadog_submit_metricsSubmit metrics to Datadogrequired series
datadog_submit_service_checksSubmit multiple service checks to Datadogrequired service_checks
datadog_update_dashboardUpdate an existing Datadog dashboardrequired dashboard_id, title, layout_type, widgets
optional description, notify_list, tags, template_variables
datadog_update_downtimeUpdate an existing Datadog downtimerequired downtime_id
optional end, message, monitor_id, monitor_tags, scope, start, timezone
datadog_update_metric_metadataUpdate metadata for a specific metricrequired metric_name
optional description, metric_type, per_unit, short_name, statsd_interval, unit
datadog_update_monitorUpdate an existing Datadog monitorrequired monitor_id
optional message, monitor_type, name, options, priority, query, tags
datadog_validate_monitorValidate a Datadog monitor definition (type and query)required monitor_type, query

0 tools. Available as 2 connections: Dynatrace (OAuth) (OAuth 2.0 client credentials), Dynatrace (Platform Token) (API key).

13 tools. Connect with API key.

ToolDescriptionArguments
firemon_create_policy_planner_ticketCreate a new policy change request ticket (packet) in FireMon Policy Planner under a specific workflowrequired workflow_id, subject, requester_name, requester_email
optional domain_id, due_date, priority
firemon_get_collectorGet detailed information and status for a specific FireMon data collectorrequired collector_id
firemon_get_deviceGet detailed information about a specific FireMon managed device by ID, including management IP, vendor, and statusrequired device_id
optional domain_id
firemon_get_device_statusGet connectivity and retrieval status for a specific FireMon managed devicerequired device_id
optional domain_id
firemon_get_latest_revisionGet the most recent successful configuration revision for a FireMon managed devicerequired device_id
optional domain_id
firemon_get_policy_planner_ticketGet detailed information about a specific FireMon policy planner ticket (packet) by IDrequired ticket_id, workflow_id
optional domain_id
firemon_get_rule_usageGet rule hit count and usage statistics for a FireMon managed device. Returns total rule usage stats.required device_id
optional domain_id, page, page_size
firemon_list_collectorsList data collectors and their status in FireMon—
firemon_list_device_revisionsList configuration revisions for a FireMon managed devicerequired device_id
optional domain_id, page, page_size
firemon_list_devicesList managed devices (firewalls, routers, switches) in FireMon with filtering by name, vendor, or IPoptional domain_id, mgmt_ip, name, page, page_size, vendor
firemon_list_domainsList configured domains in FireMon Security Manageroptional page, page_size
firemon_list_policy_planner_ticketsList policy planner tickets (packets) for a specific workflow in FireMon. Requires a workflow ID.required workflow_id
optional domain_id, page, page_size
firemon_search_security_rulesSearch security rules across devices using FireMon’s SIQL (Security Intelligence Query Language). Examples: ‘action = allow’, ‘source network = 10.0.0.0/8’, ‘rule unused > 90’required query
optional domain_id, page, page_size

21 tools. Connect with API key.

ToolDescriptionArguments
grafana_get_dashboardGet dashboard configuration and panel details by UIDrequired uid
grafana_get_data_sourceGet specific data source details by ID. This tool is vital to conduct any Grafana investigation, as data source UIDs are required to run any queries.required id
grafana_get_healthCheck Grafana instance health and availability—
grafana_get_trace_by_idGet detailed information about a specific trace by its IDrequired dataSourceUid, traceId
grafana_list_dashboardsList available dashboards with optional search filteringoptional limit, query
grafana_list_data_sourcesList all configured data sources in Grafana. This tool is vital to conduct any Grafana investigation, as data source UIDs are required to run any queries.—
grafana_list_foldersList dashboard folders for organization structureoptional limit
grafana_list_loki_label_namesList all available label names in Loki within an optional time rangerequired dataSourceUid
optional end, start
grafana_list_loki_label_valuesGet available values for a specific label name in Lokirequired dataSourceUid, labelName
optional end, start
grafana_list_prometheus_label_namesList label names in Prometheus with optional filtering by series selectors and time rangerequired dataSourceUid
optional endRfc3339, limit, matches, startRfc3339
grafana_list_prometheus_label_valuesGet values for a specific label name in Prometheus with optional filteringrequired dataSourceUid, labelName
optional endRfc3339, limit, matches, startRfc3339
grafana_list_prometheus_metric_metadataGet metadata about Prometheus metrics including type, help text, and unitsrequired dataSourceUid
optional limit, limitPerMetric, metric
grafana_list_prometheus_metric_namesList metric names in Prometheus with optional regex filtering and paginationrequired dataSourceUid
optional limit, page, regex
grafana_query_loki_logsExecute LogQL queries to retrieve logs from Loki. Returns log entries with timestamps, labels, and either log lines or metric values. Supports full LogQL syntaxrequired dataSourceUid, logQL
optional direction, end, limit, start
grafana_query_loki_statsGet statistics about a LogQL query including bytes and lines processedrequired dataSourceUid, logQL
optional end, start
grafana_query_prometheusQuery Prometheus using PromQL expressions. Supports both instant queries (single point in time) and range queries (time series).required dataSourceUid, expr, startTime
optional endTime, queryType, stepSeconds
grafana_query_tempoQuery traces from Tempo using TraceQL. Returns matching traces with their spansrequired dataSourceUid, query, start, end
optional limit, spss, step
grafana_search_annotationsSearch for annotations and events for APM correlationoptional alertId, dashboardId, from, limit, panelId, tags, to
grafana_search_metricsSearch available metrics and resourcesrequired query
optional limit, type
grafana_search_tempo_tag_valuesGet available values for a specific tag in Temporequired dataSourceUid, tagName
optional end, query, start
grafana_search_tempo_tagsSearch available tags in Temporequired dataSourceUid

11 tools. Connect with API key.

ToolDescriptionArguments
harness_abort_pipeline_executionAbort (or mark-as-failed) a running pipeline execution. This is a mutating action that interrupts an in-progress run.required org_id, project_id, plan_execution_id
optional interrupt_type
harness_get_pipelineGet a single pipeline’s metadata and full YAML definition by its identifier.required org_id, project_id, pipeline_id
harness_get_pipeline_executionGet full details of a single pipeline execution by its planExecutionId, including stage/step breakdown and failure info. Use this to debug why a run failed.required org_id, project_id, plan_execution_id
harness_get_pipeline_runtime_inputsFetch the runtime input template (YAML) for a pipeline. The template shows the ’<+input>’ placeholders that must be supplied as inputs_yaml when calling run_pipeline. Call this first when a pipeline has runtime inputs.required org_id, project_id, pipeline_id
harness_list_environmentsList Harness environments in a project (deploy destinations).required org_id, project_id
optional page, search_term, size
harness_list_organizationsList Harness organizations in the account. Use this to discover the orgIdentifier needed by project and pipeline tools.optional page, search_term, size
harness_list_pipeline_executionsList pipeline executions (runs) in a project, optionally filtered by a specific pipeline. Returns execution summaries including status and the planExecutionId used by get_pipeline_execution.required org_id, project_id
optional page, pipeline_id, search_term, size
harness_list_pipelinesList pipelines in a Harness project, with optional search and module (ci/cd) filtering.required org_id, project_id
optional module, page, search_term, size
harness_list_projectsList Harness projects, optionally scoped to an organization. Use this to discover the projectIdentifier needed by pipeline tools.optional org_id, page, search_term, size
harness_list_servicesList Harness services in a project (deployment targets).required org_id, project_id
optional page, search_term, size
harness_run_pipelineTrigger (execute) a pipeline. This is a mutating action that starts a real CI/CD run. If the pipeline has runtime inputs, first call get_pipeline_runtime_inputs and pass the filled-in YAML as inputs_yaml.required org_id, project_id, pipeline_id
optional inputs_yaml, module, notes

18 tools. Available as 4 connections: Microsoft Azure (OAuth 2.0), Microsoft Azure (Application) (OAuth 2.0 client credentials), Microsoft Azure (Government) (OAuth 2.0), Microsoft Azure (Government, Application) (OAuth 2.0 client credentials).

ToolDescriptionArguments
microsoft-azure_get_management_groupGet a single Azure management group by ID. Optionally expand its child management groups and subscriptions recursively.required group_id
optional expand_children
microsoft-azure_get_policy_assignmentGet a single Azure Policy assignment by name at a scope. Returns the assignment’s policy definition reference, parameters, and enforcement mode.required assignment_name
optional scope, subscription_id
microsoft-azure_get_policy_compliance_summarySummarize Azure Policy compliance for a subscription, optionally scoped to a single policy assignment. Returns aggregated compliant vs non-compliant counts by policy assignment and definition.optional policy_assignment_name, subscription_id
microsoft-azure_get_policy_definitionGet a single Azure Policy definition by name within a subscription. Returns the definition’s rule, parameters, and metadata.required definition_name
optional subscription_id
microsoft-azure_get_role_assignmentGet a single Azure RBAC role assignment by name at a scope. Returns the assigned principal, role definition ID, and scope.required role_assignment_name
optional scope, subscription_id
microsoft-azure_get_role_definitionGet a single Azure RBAC role definition by ID at a scope. Returns the role’s name, description, and actions/notActions/dataActions permission sets.required role_definition_id
optional scope, subscription_id
microsoft-azure_get_subscriptionGet details for a single Azure subscription by its subscription ID, including display name, state, and tenant ID.required subscription_id
microsoft-azure_list_management_group_descendantsList the flattened descendant tree of a management group, including nested management groups and subscriptions beneath it.required group_id
optional top
microsoft-azure_list_management_groupsList the Azure management groups visible to the authenticated identity. Management groups organize subscriptions into a governance hierarchy.—
microsoft-azure_list_noncompliant_resourcesList resources that are currently non-compliant with Azure Policy in a subscription. Returns the latest policy state records filtered to ComplianceState eq ‘NonCompliant’.optional subscription_id, top
microsoft-azure_list_policy_assignmentsList Azure Policy assignments at a scope. Provide an explicit ARM scope (subscription, resource group, or management group ID) or fall back to the configured subscription.optional odata_filter, scope, subscription_id, top
microsoft-azure_list_policy_definitionsList Azure Policy definitions (built-in and custom) available at a scope. Provide an explicit ARM scope or fall back to the configured subscription.optional scope, subscription_id, top
microsoft-azure_list_resource_groupsList resource groups in a subscription. Returns each group’s name, location, and tags. Defaults to the connection’s configured subscription when subscription_id is omitted.optional subscription_id
microsoft-azure_list_resourcesList Azure resources in a subscription, optionally narrowed to a single resource group. Supports an OData $filter (e.g. “resourceType eq ‘Microsoft.Compute/virtualMachines’”) and a result cap.optional odata_filter, resource_group, subscription_id, top
microsoft-azure_list_role_assignmentsList Azure RBAC role assignments at a scope. Optionally filter by principal (user/group/service principal object ID) and/or restrict to assignments defined directly at the scope (atScope()).optional at_scope, principal_id, scope, subscription_id, top
microsoft-azure_list_role_definitionsList Azure RBAC role definitions available at a scope. Optionally restrict to custom roles only. Returns role names, descriptions, and their actions/notActions/dataActions permission sets.optional custom_only, scope, subscription_id, top
microsoft-azure_list_subscriptionsList all Azure subscriptions the authenticated identity can access within the tenant. Returns subscription IDs, display names, and state. Use this to discover which subscriptions to target with other tools.—
microsoft-azure_query_resourcesRun an Azure Resource Graph (KQL) query across one or more subscriptions or management groups.required query
optional limit, management_groups, subscriptions, top

14 tools. Connect with API key.

ToolDescriptionArguments
nagios-xi_cancel_downtimeCancel a scheduled downtime entry by its downtime ID (from list_downtime).required downtime_id
nagios-xi_get_contactsGet contact definitions — who gets notified. Omit contact_name for all contacts.optional contact_name
nagios-xi_get_host_status—optional host_name
nagios-xi_get_hostgroupsGet host group definitions. Omit hostgroup_name for all groups.optional hostgroup_name
nagios-xi_get_hostsGet host configuration definitions — address, check settings, templates. Omit host_name for all hosts.optional host_name
nagios-xi_get_log_entriesGet recent monitoring log / alert events. Filter by host_name and a Unix-timestamp time window (start_time / end_time).optional end_time, host_name, start_time
nagios-xi_get_service_status—optional host_name, service_description
nagios-xi_get_servicegroupsGet service group definitions. Omit servicegroup_name for all groups.optional servicegroup_name
nagios-xi_get_servicesGet service configuration definitions. Filter by host_name and/or service_description.optional host_name, service_description
nagios-xi_get_state_historyGet the historical state-change trail for hosts/services — the audit of when state transitions happened. Filter by host_name and/or service_description.optional host_name, service_description
nagios-xi_list_commentsList comments recorded on hosts and services. Filter by host_name and/or service_description.optional host_name, service_description
nagios-xi_list_downtimeList scheduled downtime entries for hosts and services.—
nagios-xi_list_problemsList every host and service NOT in an OK/UP state — the triage workhorse. Returns host_problems and service_problems with counts.optional host_name
nagios-xi_schedule_downtimeSchedule a downtime window on hosts, host groups, and/or service groups. start_time and end_time are Unix timestamps (epoch seconds). At least one target — individual hosts, host groups, or service groups — must be provided.required comment, start_time, end_time
optional host_names, hostgroup_names, servicegroup_names

15 tools. Connect with API key.

ToolDescriptionArguments
palo-alto-ngfw_commit_changesCommit the PAN-OS candidate configuration to running config. Returns the commit job ID for tracking.optional description, force
palo-alto-ngfw_create_address_groupCreate a new PAN-OS address group (static with member list or dynamic with filter)required name
optional description, device_group, dynamic_filter, location, static, tag, vsys
palo-alto-ngfw_create_address_objectCreate a new PAN-OS address object (IP netmask, IP range, or FQDN)required name, address_type, value
optional description, device_group, location, tag, vsys
palo-alto-ngfw_create_nat_ruleCreate a new PAN-OS NAT rule with source/destination translationrequired name, source, destination, source_zone
optional description, destination_translation, destination_zone, device_group, disabled, location, service, source_translation, tag, vsys
palo-alto-ngfw_create_security_ruleCreate a new PAN-OS security policy rule with source, destination, zones, application, service, and actionrequired name, source, destination, source_zone, destination_zone, application, service
optional action, description, device_group, disabled, location, log_end, log_start, tag, vsys
palo-alto-ngfw_delete_address_objectDelete a PAN-OS address object by namerequired name
optional device_group, location, vsys
palo-alto-ngfw_get_job_statusCheck the status of a PAN-OS commit or push job by job IDrequired job_id
palo-alto-ngfw_get_nat_ruleGet a specific PAN-OS NAT rule by namerequired name
optional device_group, location, vsys
palo-alto-ngfw_get_security_ruleGet a specific PAN-OS security rule by namerequired name
optional device_group, location, vsys
palo-alto-ngfw_get_system_infoGet PAN-OS firewall system information including model, software version, serial number, and uptime—
palo-alto-ngfw_list_address_groupsList PAN-OS address groups (static and dynamic)optional device_group, location, vsys
palo-alto-ngfw_list_address_objectsList PAN-OS address objects (IP, FQDN, range) with optional location filteringoptional device_group, location, vsys
palo-alto-ngfw_list_nat_rulesList PAN-OS NAT policy rules with location/vsys/device-group filteringoptional device_group, location, vsys
palo-alto-ngfw_list_security_rulesList PAN-OS security policy rules with location/vsys/device-group filteringoptional device_group, location, vsys
palo-alto-ngfw_update_security_ruleUpdate an existing PAN-OS security rule’s properties (source, destination, action, etc.)required name
optional action, application, description, destination, destination_zone, device_group, disabled, location, log_end, log_start, service, source, source_zone, tag, vsys

0 tools. Connect with OAuth 2.0.

10 tools. Connect with API key.

ToolDescriptionArguments
zabbix_acknowledge_event—required event_ids
optional actions, message, severity
zabbix_get_hostFetch a single host by ID with full interfaces, groups, and tags.required host_id
zabbix_get_item_historyFetch time-series history values for a single item. value_type MUST match the item’s stored value type (see list_items.value_type).required item_id, value_type
optional limit, time_from, time_until
zabbix_get_triggerFetch a single trigger by ID with its expression and host context.required trigger_id
zabbix_list_eventsList historical events with filters for source, time range, host(s), and severity.optional host_ids, limit, min_severity, source, time_from, time_until
zabbix_list_host_groupsList host groups (used as the input filter for list_hosts).optional limit, search
zabbix_list_hostsList monitored hosts. Filter by host group, name search, and monitored/unmonitored status.optional group_ids, limit, search, status
zabbix_list_itemsList monitored items (metrics) for one or more hosts. Each item has a value_type that determines which history table backs it.optional host_ids, limit, only_enabled, search
zabbix_list_problemsList CURRENT open problems (the SOC workhorse view). Filter by host, host group, minimum severity, and acknowledged status.optional acknowledged, group_ids, host_ids, limit, min_severity
zabbix_list_triggersList trigger (alert-rule) definitions. Useful for investigation: ‘why did this fire?’.optional group_ids, host_ids, limit, min_severity, only_enabled, search