← azure-query-mcp

azure-query-mcp cf63e3a5167bda3f0e683bb1a0a4f8fab6bda444

source_git · kapetanios55/azure-query-mcp · current release

5
Tools
0
Resources
0
Templates
0
Prompts

Observation

Observed 2026-08-25T18:20:46.527Z using mcpSecurity-inventory. Status: succeeded. Negotiated protocol: 2025-06-18.

Server capabilities
{
  "tools": {
    "listChanged": true
  }
}

Tools 5

ToolCategoryAnnotationsRisk
describe_tableGet the canonical schema and retention metadata for a Log Analytics table.
Input schema
{
  "type": "object",
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "workspaceResourceId": {
      "type": "string",
      "description": "Full ARM resource ID of the workspace."
    },
    "tableName": {
      "type": "string",
      "minLength": 1,
      "maxLength": 260,
      "description": "Case-sensitive table name."
    }
  },
  "required": [
    "workspaceResourceId",
    "tableName"
  ]
}
Annotations
{
  "readOnlyHint": true,
  "destructiveHint": false,
  "idempotentHint": true,
  "openWorldHint": true
}
Read only · Non-destructive
list_workspacesList Azure Log Analytics workspaces accessible in a subscription.
Input schema
{
  "type": "object",
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "subscriptionId": {
      "type": "string",
      "format": "uuid",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
      "description": "Azure subscription ID."
    }
  },
  "required": [
    "subscriptionId"
  ]
}
Annotations
{
  "readOnlyHint": true,
  "destructiveHint": false,
  "idempotentHint": true,
  "openWorldHint": true
}
Read only · Non-destructive
query_azure_resourcesUse for Azure resource inventory, configuration, tags, policy, health, and cross-subscription discovery through Azure Resource Graph. Do not use for telemetry, logs, events, or time-series analysis; use query_workspace for those.
Input schema
{
  "type": "object",
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "subscriptionIds": {
      "minItems": 1,
      "maxItems": 100,
      "type": "array",
      "items": {
        "type": "string",
        "format": "uuid",
        "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$"
      },
      "description": "One or more Azure subscription IDs that bound the query scope."
    },
    "query": {
      "type": "string",
      "minLength": 1,
      "maxLength": 5000,
      "description": "Read-only Azure Resource Graph KQL beginning with an ARG table such as Resources."
    },
    "maxResults": {
      "default": 100,
      "description": "Maximum rows returned in this page.",
      "type": "integer",
      "minimum": 1,
      "maximum": 1000
    },
    "skipToken": {
      "description": "Opaque continuation token returned by the preceding identical query.",
      "type": "string",
      "minLength": 1,
      "maxLength": 4096
    }
  },
  "required": [
    "subscriptionIds",
    "query"
  ]
}
Annotations
{
  "readOnlyHint": true,
  "destructiveHint": false,
  "idempotentHint": true,
  "openWorldHint": true
}
Read only · Non-destructive
query_workspaceUse for telemetry, logs, events, metrics, and time-series data stored in a Log Analytics workspace. Run bounded, read-only KQL against one workspace. Do not use for Azure resource inventory or configuration; use query_azure_resources for those.
Input schema
{
  "type": "object",
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "workspaceId": {
      "type": "string",
      "format": "uuid",
      "pattern": "^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$",
      "description": "Log Analytics workspace customer ID."
    },
    "query": {
      "type": "string",
      "minLength": 1,
      "maxLength": 5000,
      "description": "Read-only KQL with a result-limiting operator."
    },
    "timespan": {
      "type": "string",
      "maxLength": 100,
      "pattern": "^P(?!$).+",
      "description": "ISO 8601 duration, such as PT1H."
    }
  },
  "required": [
    "workspaceId",
    "query",
    "timespan"
  ]
}
Annotations
{
  "readOnlyHint": true,
  "destructiveHint": false,
  "idempotentHint": true,
  "openWorldHint": true
}
Read only · Non-destructive
search_tablesList or search tables in a Log Analytics workspace using ARM metadata.
Input schema
{
  "type": "object",
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "properties": {
    "workspaceResourceId": {
      "type": "string",
      "description": "Full ARM resource ID of the workspace."
    },
    "search": {
      "description": "Optional name or description substring.",
      "type": "string",
      "maxLength": 200
    }
  },
  "required": [
    "workspaceResourceId"
  ]
}
Annotations
{
  "readOnlyHint": true,
  "destructiveHint": false,
  "idempotentHint": true,
  "openWorldHint": true
}
Read only · Non-destructive

Resources 0

Resource templates 0

Prompts 0

Let’s talk about MCP security.

Share your details and our security team will contact you.