Skip to main content

Log Detective MCP

MCP server implementing core log analysis tools of Log Detective for use by other agents.

The server uses the Drain3 algorithm to cluster log messages into templates and extract a representative subset of snippets, reducing large logs to a manageable size for downstream analysis.

Installation

Requires Python 3.11+.

pip install .

Or with uv:

uv pip install .

Usage

Running the server

logdetective-mcp

Or directly:

python -m logdetective_mcp.main

MCP client configuration

Claude Code

claude mcp add logdetective -- logdetective-mcp

Claude Desktop

Add to your Claude Desktop configuration file:

{
  "mcpServers": {
    "logdetective": {
      "command": "logdetective-mcp"
    }
  }
}

Tools

extract_log_snippets

Extracts representative log snippets using Drain3 clustering. The tool chunks the log into logical messages, clusters similar messages, and returns one representative snippet per cluster.

Log content can be provided in three ways (exactly one must be used):

Parameter Type Description
log_text str Raw log text passed directly.
log_path str Path to a log file on the server's filesystem.
log_url str HTTP(S) URL to fetch log content from.

Optional parameters:

Parameter Type Default Description
max_clusters int 8 Maximum number of snippets to extract.
max_snippet_len int 2000 Maximum character length per snippet.
skip_patterns list[str] null List of regex patterns. Chunks matching any pattern are excluded before clustering.

Returns a list of Snippet objects, each with line_number (position in the original log) and text (the extracted snippet content).

Size limits

All downloaded inputs (via log_url) are limited to 100 MB regardless of format. Downloads are streamed in chunks and aborted as soon as the limit is exceeded.

Archives read via log_path are also checked against the 100 MB limit during decompression.

Compressed file support

Both tools transparently decompress archived log files. Supported formats:

  • Single-file compression: .gz, .bz2, .xz, .lzma
  • Archives: .zip, .tar, .tar.gz, .tar.bz2, .tar.xz

Format is detected from the file extension (or URL path). Archives must contain exactly one file.

Zip bomb protection is enforced via:

  • Maximum decompressed size of 100 MB
  • Maximum compression ratio of 100:1
  • Pre-check of declared sizes in zip/tar headers
  • No recursive decompression (nested archives are not unpacked)

Contributing

All changes to this repository must pass pre-commit checks and tests.

uv run pytest tests/

Metadata

Release files for logdetective-mcp 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for logdetective-mcp 0.5.0
File Size Uploaded
logdetective_mcp-0.5.0.tar.gz 64.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for logdetective-mcp 0.5.0
File Interpreter ABI Platform
logdetective_mcp-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 79.6 kB

Release files / logdetective_mcp-0.5.0.tar.gz

Download URL logdetective_mcp-0.5.0.tar.gz
Size 64.9 kB
Tags Source
SHA-256 checksum
How to use checksums
ce39c4adcb3f290cea5b6bc83ed04b2716e13789cbb35cf89cc066e99365e988
BLAKE2b-256 checksum
How to use checksums
4a5afe46de2600a24911753136063c250ff7ee520c27c5e24f94d4ea9935673e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 30, 2026.

Transparency log

Release files / logdetective_mcp-0.5.0-py3-none-any.whl

Download URL logdetective_mcp-0.5.0-py3-none-any.whl
Size 14.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
94fe615ff0f40d8eb5edbcfa65b6e1ee581042f254da8308385c21c2aaec7054
BLAKE2b-256 checksum
How to use checksums
86ee4246d56588d4c641638c2d3cab05ddb299a3ed3a2171e034505b36f63467
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 30, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.0 This release

2 release files

0.4.0

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page