Logs¶
Tools for reading systemd journal logs and log files.
Choosing where to run
All tools on this page require a host parameter (string). Pass
localhost to run the command on the system the MCP server runs on, or
a remote machine to run it there via SSH.
See SSH Configuration for details, and
Host mode for restricting which of
the two a server accepts.
get_journal_logs¶
Get systemd journal logs.
Parameters:
unit(string, default:""): Filter by systemd unit name or patternpriority(string, default:""): Filter by syslog priority level (0-7), name, or rangesince(string, default:""): Filter entries since specified time (absolute or relative)transport("audit","driver","journal","kernel","stdout","syslog", default: none): Filter by journal transport (e.g., 'audit' for audit logs, 'kernel' for kernel messages, 'syslog' for syslog messages)first_lines(integer, default: none): Number of first log lines to retrieve after applying filters (journalctl -n +N). Mutually exclusive with last_lines.last_lines(integer, default: none): Number of last log lines to retrieve after applying filters (journalctl -n N). Default: 100. Mutually exclusive with first_lines.
Returns:
entries(array of string)unit(string or null)path(string or null)lines_count(integer)
read_log_file¶
Read a specific log file.
Parameters:
log_path(string, required): Absolute path to the log file (must be in allowed list)first_lines(integer, default: none): Number of first lines to retrieve from the log file. Mutually exclusive with last_lines.last_lines(integer, default: none): Number of last lines to retrieve from the log file. Default: 100. Mutually exclusive with first_lines.
Returns:
entries(array of string)unit(string or null)path(string or null)lines_count(integer)