MCP servercom.netmon/netmon-demo
Public read-only demo of Netmon's network monitoring tools over a recorded snapshot.
Overview
Score?
UNRATED 0.618
of what a free look can see, on 22 looks
Looks
26
last 5 hr ago
Tools
36
More info
URL
netmon.com/mcp-demo/mcp
streamable-http
Says it is
netmon7-demo 1.0.0
protocol 2025-06-18
In the record since
24 days ago
Among servers18,413 with a card
0median 0.606 · this server 0.618 · highest on record 0.8561
Toolsfrom sha256:127350d513…843d0a
| Tool | Schema |
|---|---|
| agent_disk_usage Path-scoped folder-tree disk usage report from a Netmon agent — the 'D: drive is at 95%, what's eating it?' question. Wraps POST /api/getFolderUsageFromPath which RPCs into the age |
input · no output |
| agent_processes List running processes on an agent-managed device — live read via the agent tunnel. Wraps POST /api/getDeviceProcesses (permission: devices).
Returns rows as reported by GETPS: (p |
input · no output |
| agent_services List Windows services on an agent-managed device — live read via the WMI tunnel. Wraps POST /api/getDeviceServices (permission: devices).
Returns rows of {Name, State, DisplayName |
input · no output |
| alerts_history Authoritative 'what fired and when' stream — wraps the `alert_history` table (one row per incident, both legacy and modern) and `alert_outlet_log` (per-dispatch ledger keyed by his |
input · no output |
| alerts_list List configured alert definitions across both axes of the rule engine. Modern alerts (table `alerts`, class-scoped: syslog_log / event_log / eve_log / device_down / storage) and le |
input · no output |
| arp_lookup Performs an ARP lookup to find the MAC address for a given Local IP address. A suitable network interface is automatically selected. The list of all suitable interfaces found is al |
input · no output |
| arp_table Lists hosts observed on the local LAN(s) via the ARP table — the 'what devices have we seen recently?' question. Wraps POST /api/getArpTable, which collapses arptable + _dns into o |
input · no output |
| capture_get Read-only single-capture detail. Wraps GET /api/captures/{id}. If the capture is still active (status=starting|running) the upstream endpoint refreshes status from netmond's IPC be |
input · no output |
| capture_list Read-only listing of packet captures. Wraps GET /api/captures. Operators see their own captures; admin (sa) sees all. The upstream endpoint returns the 200 most-recent rows ordered |
input · no output |
| device_find Find devices matching a substring of label or ip_address. Convenience wrapper for GET /api/devices?search=<q>; equivalent to device_list({search: q}).
Use device_list directly whe |
input · no output |
| device_get Fetch one device with its related state: tags, alerts, the ping / oid / interface / port / disk trackers configured on it, its SNMP walk trackers, and a netflow rollup. Wraps GET / |
input · no output |
| device_list List monitored devices. Wraps GET /api/devices (permission: devices); user's tag-scope is enforced server-side.
Filters (all optional, combinable):
- tag: tag slug, e.g. "snmp-u |
input · no output |
| device_metric_summary Day / week / month / all-time summary stats for a single device-tracker, by metric type. Multi-backend: pass `metric` to pick which upstream endpoint to hit.
metric='latency' → wr |
input · no output |
| eve_get Fetch a single Suricata EVE event by id, decoded server-side. Wraps GET /api/eve/get/{id} (requires permission: logs). Returns an envelope: summary (signature/category/action/gid:s |
input · no output |
| eve_search Search Suricata EVE-format IDS events. Wraps GET /api/eve/list (permission: logs); tag-scoped server-side.
Severity is Suricata-native: 1=high, 2=medium, 3=low/info — a 3-point sc |
input · no output |
| eventlog_search Search Windows Event Log entries ingested from Netmon agents. Wraps GET /api/eventlog/list (permission: logs); tag-scoped server-side.
Severity is the raw Windows EventRecord.Leve |
input · no output |
| flow_summary Summarize one host's network conversations: top peers, top ports, and a client-vs-service-side split, each with a residual "other" bucket plus overall totals. Wraps GET /api/aggnet |
input · no output |
| get_network_entity_info Retrieves WHOIS, GeoIP and DNS information for a public IP address or hostname. A hostname is resolved to an IP for the GeoIP lookup (`resolved_ip`, when resolution succeeds); an I |
input · no output |
| interfaces_search Cross-device interface metadata listing — answers 'what interfaces are tracked across the fleet, named like X, on device Y?'. Wraps GET /api/interfaces/all, which returns logging-e |
input · no output |
| log_severity_summary Count log events grouped by severity over a time window. One tool, three backends — pass `stream` to pick which.
stream='syslog' → wraps /api/syslog/sevSum (severity 0-7, sysl |
input · no output |
| maintenance_windows_list Lists maintenance windows — the suppression schedules that gate alert dispatch. Use when a user asks 'why didn't this page me' or 'is this device under maintenance right now' — a q |
input · no output |
| netflow_raw_search Search raw NetFlow records (per-flow, not aggregated). Wraps GET /api/netflow/list (permission: vne).
HORIZON — read this before choosing a window: the raw table holds only about |
input · no output |
| netflow_search Search the FULL NetFlow history: the raw flow table (the last ~15 minutes) unioned with the aggregated rollup (4 weeks of history), windowed and pro-rated server-side. Wraps GET /a |
input · no output |
| overwatch_summary High-level network health snapshot for 'how's the network?' style questions. Wraps GET /api/devices?alerts=1&tags=1 (requires permission: devices) and aggregates in-tool: device co |
input · no output |
| ping Ping a target host from the Netmon server. Wraps POST /api/getPingInfo/{target} (permission: tools).
The probe runs ON the netmon server, not on the mcpmond host — so reachability |
input · no output |
| port_map Nmap port scan against a single host from the Netmon server. Wraps POST /api/getPortscanInfo (permission: tools).
Server runs `nmap -oX - -p <ports> --open <ip>` and returns the p |
input · no output |
| search_ip Find every mention of a specific IP across Netmon's log and telemetry streams: syslog, Windows eventlog, Suricata EVE, aggregated NetFlow, and ARP.
Returns one bucket per stream w |
input · no output |
| snmp_test Probe a device for SNMP reachability using the Netmon snmptest binary. Wraps POST /api/testSnmp (requires permission: write_devices). BLOCKING — can run up to 60 seconds while the |
input · no output |
| snmp_walk_last Fetch the most recent stored SNMP walk for a device (cached in tools_walks). Wraps GET /api/getLastWalk/{device} (permission: tools). Cheap single-row read.
Always try this first |
input · no output |
| snmp_walk_run Trigger a FRESH SNMP walk against a device. Wraps POST /api/getSNMPWalkInfo/{deviceId} (permission: tools).
SLOW and SIDE-EFFECTING. Server-side this shells out to walktool with a |
input · no output |
| speedtest_history Recent WAN speedtest results — answers 'is the internet healthy?'. Wraps GET /api/getSpeedTestHistory. Returns rows ordered by timestamp desc.
Each row carries the upstream's Spee |
input · no output |
| syslog_facets Top-N value counts for ONE syslog field over a window — 'what are the top actions/reasons on this FortiGate in the last 2 hours' in a single call, instead of pulling rows and count |
input · no output |
| syslog_search Search syslog messages from network devices. Wraps GET /api/syslog/list (permission: logs); tag-scoped server-side.
Filters (all optional): device_id, severity (name or int 0-7), |
input · no output |
| tags_list List tag definitions. The slug is the stable identifier used everywhere device-tag scoping is enforced (e.g. alert_routing_rules.tag_filters, device_list({tag: ...})). The display |
input · no output |
| top_bandwidth Top NetFlow conversations over the last N minutes — the 'who's eating bandwidth right now?' question. Wraps GET /api/getTopBandwidth/{mins}, the same query that powers the dashboar |
input · no output |
| traceroute Traceroute to a target from the Netmon server. Wraps POST /api/getTracerouteInfo/{target} (permission: tools).
The probe runs ON the netmon server — hops reflect the path FROM net |
input · no output |
Verify it yourself
npx teppi-check https://netmon.com/mcp-demo/mcpcurl -s https://api.teppi.xyz/v1/trust/mcp/mcs_01M24XY58QQ8ZDPB4627CFX8RD