Cribl MCP Server
Most developer tooling work still happens through a UI a human drives. Cribl MCP server moves it into the conversation instead. Cribl MCP Server.
A Model Context Protocol (MCP) server that enables AI interactions with the Cribl API.
The server ships on npm as @pebbletek/cribl-mcp, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.
The server publishes 5 tools. What each one is for:
Prompt — what sources are we ingesting?Response — "Let me examine the functions that are processing the Palo Alto traffic in more detail:Filter — sourcetype!='pan:traffic'Description — Short-circuits (skips) all events that are NOT of sourcetype 'pan'Prerequisites — You can install Node.js from https://nodejs.orgConfiguration is passed through the environment: CRIBL_BASE_URL, CRIBL_CLIENT_ID, CRIBL_CLIENT_SECRET. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.
To run this server ensure the following: - Node.js is installed (version 16 or later recommended) - Internet access is available (to fetch the MCP server package from npm) You can install Node.js from https://nodejs.org. To verify your setup:
Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Cribl's toolset — Prompt, Response, Filter and 2 more — is a fair guide to whether it matches your workflow. It is maintained by pebbletek; worth a glance at recent repository activity before you build anything load-bearing on it.
We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.
| Tool | What it does |
|---|---|
| Prompt | what sources are we ingesting? |
| Response | "Let me examine the functions that are processing the Palo Alto traffic in more detail: |
| Filter | sourcetype!='pan:traffic' |
| Description | Short-circuits (skips) all events that are NOT of sourcetype 'pan' |
| Prerequisites | You can install Node.js from [https://nodejs.org](https://nodejs.org). |
{
"mcpServers": {
"cribl": {
"command": "npx",
"args": ["-y", "@pebbletek/cribl-mcp"],
"env": {
"CRIBL_BASE_URL": "your-value",
"CRIBL_CLIENT_ID": "your-value",
"CRIBL_CLIENT_SECRET": "your-value"
}
}
}
}Add to claude_desktop_config.json, then restart Claude Desktop.
To run this server ensure the following: - Node.js is installed (version 16 or later recommended) - Internet access is available (to fetch the MCP server package from npm) You can install Node.js from https://nodejs.org. To verify your setup:
| Variable | Description | Required |
|---|---|---|
| CRIBL_BASE_URL | Endpoint or connection string the server talks to. | Yes |
| CRIBL_CLIENT_ID | Configuration value read at startup. | Optional |
| CRIBL_CLIENT_SECRET | Credential the server authenticates with. | Yes |
Kill hallucinated APIs — version-accurate, up-to-date library documentation injected straight into context.
Microsoft's official browser automation server — drive a real browser through the accessibility tree, no screenshots needed.
GitHub's official server — repos, issues, pull requests, Actions and code security, straight from your assistant.
Issue tracking at the speed of conversation — Linear's official hosted server with OAuth and zero install.
Local repository surgery — status, diffs, commits, branches and history for any repo on disk.
Timezone sanity for AI — current time anywhere and correct conversions, without the model doing date math.