Cribl MCP Server

Cribl MCP Server

Local serverstdio

What is the Cribl MCP server?

Most developer tooling work still happens through a UI a human drives. Cribl MCP server moves it into the conversation instead. Cribl MCP Server.

The short version

A Model Context Protocol (MCP) server that enables AI interactions with the Cribl API.

Getting it running

The server ships on npm as @pebbletek/cribl-mcp, so your MCP client can launch it on demand — there is no separate build step. Add the server block to your client's configuration, restart it, and the tools register themselves.

The tools it exposes

The server publishes 5 tools. What each one is for:

  • Prompt — what sources are we ingesting?
  • Response — "Let me examine the functions that are processing the Palo Alto traffic in more detail:
  • Filter — sourcetype!='pan:traffic'
  • Description — Short-circuits (skips) all events that are NOT of sourcetype 'pan'
  • Prerequisites — You can install Node.js from https://nodejs.org

What it needs from you

Configuration is passed through the environment: CRIBL_BASE_URL, CRIBL_CLIENT_ID, CRIBL_CLIENT_SECRET. Treat anything key-shaped as a real credential — scope it to the minimum the server needs, and rotate it if it ever lands in a shared config.

To run this server ensure the following: - Node.js is installed (version 16 or later recommended) - Internet access is available (to fetch the MCP server package from npm) You can install Node.js from https://nodejs.org. To verify your setup:

Things to watch

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • Keep per-call confirmation enabled while you learn its behaviour; it is the cheapest safeguard you have.

How it compares

Among the developer tooling options, the useful question is rarely "what can it do" but "what does it cost you to run" — permissions, credentials, and how much of your context its toolset consumes. Cribl's toolset — Prompt, Response, Filter and 2 more — is a fair guide to whether it matches your workflow. It is maintained by pebbletek; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Available tools

ToolWhat it does
Promptwhat sources are we ingesting?
Response"Let me examine the functions that are processing the Palo Alto traffic in more detail:
Filtersourcetype!='pan:traffic'
DescriptionShort-circuits (skips) all events that are NOT of sourcetype 'pan'
PrerequisitesYou can install Node.js from [https://nodejs.org](https://nodejs.org).

How to install the Cribl MCP server

{
  "mcpServers": {
    "cribl": {
      "command": "npx",
      "args": ["-y", "@pebbletek/cribl-mcp"],
      "env": {
        "CRIBL_BASE_URL": "your-value",
        "CRIBL_CLIENT_ID": "your-value",
        "CRIBL_CLIENT_SECRET": "your-value"
      }
    }
  }
}

Add to claude_desktop_config.json, then restart Claude Desktop.

Configuration

To run this server ensure the following: - Node.js is installed (version 16 or later recommended) - Internet access is available (to fetch the MCP server package from npm) You can install Node.js from https://nodejs.org. To verify your setup:

VariableDescriptionRequired
CRIBL_BASE_URLEndpoint or connection string the server talks to.Yes
CRIBL_CLIENT_IDConfiguration value read at startup.Optional
CRIBL_CLIENT_SECRETCredential the server authenticates with.Yes

Example prompts to try

  • Use Cribl to Prompt.
  • Use Cribl to Response.
  • Use Cribl to Filter.

Frequently asked questions

Node.js version 16 or later and internet access (to fetch the package from npm).