View Categories

Connect Nginx, Apache and IIS Logs to Claude with MCP

5 min read

MCP · Web Server Logs to Claude

Ask Claude about your Web Server Logs file, in plain English

Connect Claude, Claude Code, Cursor or any MCP client to Query Streams once. Claude reads the structure of your Web Server Logs file, writes the SQL, runs it read-only through the Agent that already sits with your data, and answers with the rows. No database password ever reaches the AI. About ten minutes, and the Free plan covers it.

About 10 minutes Claude, ChatGPT, Cursor + 11 more clients File stays where it is Read-only, always
Stuck at any point? Just ask us. Open Support in Query Streams (top-right menu → Support) and send us a message. Real people read it, and “I don’t know what this screen is asking for” is a perfectly good question.

What you’ll end up with

Web Server Logs iconA Claude that can answer questions about your nginx, Apache, IIS or Caddy access logs with live, read-only queries over the tables the Agent builds from your files, and tell you which file each answer came from — without ever seeing a login or a file path, and without a firewall change: the Agent already inside your network reads the folder and sends back only the rows. Once the Agent is in place, connecting Claude takes about 90 seconds if you are comfortable with a settings screen. Like this:

Nova, the Query Streams assistant

Rather not wire up an AI client at all? On the Business plan, Nova is the assistant built into Query Streams itself. It has every tool Claude gets here, plus the ones Claude does not: it drafts and validates the SQL against your Schema Intelligence model, turns the answer into a chart, and saves the result as a query your team can run from Excel, Google Sheets or the REST API — no key, no connector, nothing to install. Use MCP when your people already live in Claude, Cursor or ChatGPT; use Nova when you want the answers inside the Portal.

Web Server Logs turns nginx logs, Apache access logs, IIS logs and Caddy logs into a table with one row per request, so Claude can answer questions about traffic and errors. There is no server to connect. The Agent reads the log folder on a computer that can open it and caches the rows there. Files are tailed as they grow, and rotated or gzipped files are recognised so no request is counted twice.

WHERE THE FILES LIVEa computer or file share the Agent can openYour folderof filesfiles stay where they areQuery Streams Agentscans the folder, builds tablesin a local cache, runs the SQLSELECT only, enforced hereQuery StreamsMCP serverchecks key, permissions, rate limit · logs every callWHERE YOU ASKclaude.ai, Claude Desktop, Claude Code, Cursor, ChatGPTYour AI clientholds a key or a connection, never your files
Claude never opens your files. The Agent reads the folder on its own computer, keeps the rows in a local cache and runs the SQL Claude writes there. Only the rows a question needs travel back through Query Streams.

What you’ll need

A Query Streams account

MCP is on every plan, including Free. Free allows one key or one connected app, which is all this guide needs. Sign up at my.querystreams.com.

The Agent on a computer that can open the folder

Version 2.6.0 or later. The folder can be on that computer or on a file share it can reach. The Agent runs as a service, so type shares as \\server\share\folder, not as a mapped drive letter. New to the Agent? Install it on Windows, macOS or Linux.

MCP switched on for you

Creators, owners and admins have it from the start. Everyone else needs an admin to flip the MCP switch beside their name under Account → Access Control. Until then the MCP page says “MCP is disabled for your account”.

An AI client

Claude on the web, Claude Desktop or the Claude mobile apps connect with no key. Claude Code, Cursor, ChatGPT and about ten other tools work too; the Portal has a ready-made recipe for each.

Where does the work happen? On the computer that runs the Agent. It scans the folder, copies the rows into a local cache there, and runs the SQL Claude writes against that cache. The files themselves never leave that computer, and neither does anything Claude did not ask for.

Set it up in four steps

  1. Point the Agent at the folder

    In the portal open Data → Data Agents, find the Agent that can open the folder and click its Add connector button. Under the Files & Folders pill click the Web Server Logs card. The wizard then walks you through Folders, Check, Settings, Realm and Review:

    Folders
    Type the Root folders, one per line, as paths on the Agent’s computer. Scan subfolders is on, Max depth is 8. Include patterns starts with the right glob for this file type; add Exclude patterns if the folder holds files you do not want. A mapped drive letter shows an amber advisory: the Agent cannot see it, so use the \\server\share path instead.
    Check
    The Agent reads a sample of up to 64 files and shows what it will build. Nothing is created yet. Ready to create means every sampled file fits. An amber banner, “{n} of {m} file(s) will be set aside”, lists files that do not fit with Show which files and why; you can create the connector anyway and fix them later. If the folder mixes layouts, a blue panel offers Switch to one table per layout.
    Settings
    Scan interval (every hour by default, from every 5 minutes to daily) is how often the Agent looks for new, changed and vanished files. Watch folder for changes reacts within seconds on local disks. When a file vanishes is Drop its rows by default.
    Realm, Review
    Pick the Data Realm the rows count against, check the summary and click Create connector. The first scan starts right away; the connector’s Manifest tab shows what it built and any files it set aside.
    • Pick the Log type that matches your server. Columns differ by profile, so use one connector per log format.
    • Only the Custom Log Folder card lets you define your own format. Under the list it says: “Need a log type that is not listed? Open a support request and we add it within a few days.”
    • Table name is optional and defaults to events. Backfill (days) is 30 and Keep events for N days is 60.
    • On Check, the Agent reads a sample and shows the files, size and row estimate. If the files do not match the log type, the headline reads “These files are not” followed by the type. Pick another type and click Test again.
  2. See what tables you get

    Requests land in events. The nginx and Apache combined profile gives site, client_ip, auth, method, path, http_version, status, bytes, referrer and agent. The browser string is in agent. IIS W3C logs keep their own names, such as c_ip, cs_uri_stem and sc_status.

    TableWhat it holds
    eventsOne row per request, with event_time, the profile’s columns, _source_file and _line_no.
    events_raw_linesLines that did not parse, kept with the line and a reason such as no-grammar-match.
    filesThe access log files the Agent reads, with path, size and modified time.
    files_eventsFile history, including rotated, rewritten and truncated events. Sort by event_at.
    log_cursorsEach file’s read position and state. A set-aside file shows state parked with the reason in last_error.

    Every folder connector also gives Claude the same bookkeeping tables, all in the fileset schema:

    TableWhat it holds
    filesEvery file currently in the folder: path, name, extension, size, created and modified times. Ask “what is in this folder?” and Claude reads this.
    files_eventsThe change history: one row per file that appeared, was modified, vanished, or was set aside (drift), with the time in event_at and the reason in detail.
    directories, volumesFolder sizes and counts, and the disks or shares the roots live on.
    _source_file, _row_idTwo columns on every data row: which file the row came from, and a stable row id inside that file. Group by _source_file to compare files.
  3. Connect Claude

    Open Streams → Live → MCP. There are two ways in, and they end at the same place:

    Chat apps · no key

    claude.ai, Claude Desktop, ChatGPT

    In Claude, Query Streams is in the Anthropic Connectors Directory: browse connectors, click Connect. Elsewhere you paste one address into the app, https://mcp.querystreams.com/mcp, and connect from a chat. A Query Streams page opens, you pick the organization and the permissions, and click Approve connection. Nothing to copy, nothing to keep secret. The connection appears under Connected Apps and can be revoked there.

    Developer tools · a key

    Claude Code, Cursor, VS Code and friends

    On My Keys click Generate key. Give it a Key name such as “Claude Code on my laptop”, keep Read and Execute ticked, choose an Expiration (Never, 30 days, 90 days or 1 year) and click Generate key. Copy it, then Continue to install: the Connect tab shows the exact snippet for your tool with the key already filled in.

    Both ways use the same three permissions, which you choose on the consent screen or on the key:

    Read
    List connectors, browse tables and columns, read your saved queries and alert rules. Never returns row data.
    Execute
    Run read-only SQL and saved queries through your Agent and return the rows. Without it Claude can describe your data but not answer from it.
    Analyze
    Profile tables, discover relationships and queue a Schema Intelligence run. It spends Nova AI credits and data allowance, so the consent screen never pre-ticks it.

    Lost the key? Open My Keys: the eye icon shows it again and Copy full key copies it. Revoke it there if a laptop goes missing; every client using it fails on its next call, within about five minutes.

    Then pick the recipe for the Claude you use. The server address is the same everywhere: https://mcp.querystreams.com/mcp.

    Claude on the web, Claude Desktop and mobile no key

    1. Open Settings → Connectors and click Browse connectors. Query Streams is listed in the Anthropic Connectors Directory: find Query Streams and click Connect. (Or open the directory listing directly and click Connect there.)
    2. If your organization hides directory connectors, click Add custom connector instead. Name it Query Streams, paste https://mcp.querystreams.com/mcp, leave the OAuth fields empty, click Add, then in any chat click + → Browse connectors → Query Streams → Connect.
    3. A Query Streams tab opens. Sign in if asked, pick the organization, review Read and Execute, optionally Limit to specific connectors, and click Approve connection.
    4. Back in Claude you see “Connected to Query Streams”. The first time Claude uses a tool it asks; choose Always allow.

    If you do add it by hand in Claude Desktop, use Settings → Connectors → Add, not the in-chat Add marketplace option, which expects a git repository. Connectors sync to your Claude account, so the mobile apps and Desktop pick it up automatically. Menu names are Anthropic’s and can move.

    Claude Code key

    One command, with your key from My Keys:

    Terminal
    claude mcp add --transport http querystreams https://mcp.querystreams.com/mcp \
      --header "X-MCP-Key: qsmcp_PASTE_YOUR_KEY_HERE"

    That writes the current project’s .mcp.json. Add --scope user to have Query Streams in every project. Run /mcp inside Claude Code to see it connected.

    Cursor key

    Open Cursor Settings → MCP → Add New MCP Server, or edit .cursor/mcp.json at the root of your workspace:

    .cursor/mcp.json
    {
      "mcpServers": {
        "querystreams": {
          "url": "https://mcp.querystreams.com/mcp",
          "headers": {
            "X-MCP-Key": "qsmcp_PASTE_YOUR_KEY_HERE"
          }
        }
      }
    }

    Restart Cursor or run MCP: Restart Servers; a querystreams badge appears in the MCP status bar.

    Using something else? The Connect tab has ready-to-paste recipes for ChatGPT, VS Code, Visual Studio, OpenAI Codex CLI, Gemini CLI, Windsurf, Zed, Cline, Continue.dev and JetBrains AI, plus a Paste & merge tool that drops the querystreams entry into a config file you already have. Any client that speaks MCP over HTTP works: server https://mcp.querystreams.com/mcp, header X-MCP-Key (an Authorization: Bearer header with the same key also works).

  4. Ask your first question

    Start with something you can check by opening the folder, so you see Claude reach for the right table. Three that work well with your nginx, Apache, IIS or Caddy access logs:

    “Which access log files is the Agent reading, and which rotated this week?”
    Claude lists fileset.files and the rotated rows in files_events, newest event_at first.
    “What are the top 20 paths returning 404 in the last 7 days?”
    Claude filters events on status and event_time, groups by path and returns counts.
    “Were any log lines left unparsed, and why?”
    Claude counts rows in events_raw_lines by reason and shows example lines.

    To confirm the wiring, ask “What Query Streams connectors do I have?”. Claude calls qs_list_connectors, and on My Keys the key’s Last used time updates within a few seconds.

That’s it. Drop a new file in the folder and, after the next scan, Claude can answer from it. The files never left the computer the Agent runs on, and nobody typed a password into an AI.

How new, changed and deleted files show up

New and changed files

On every Scan interval the Agent compares each file’s size and modified time with its ledger. A new file that fits is added; a changed file is re-read whole, so a table never holds two versions of one file. Turn on Watch folder for changes to react within seconds on a local disk.

Deleted files

A file that vanishes drops its rows, unless you chose Keep rows, mark deleted. If a share goes offline and most files vanish at once, the Agent keeps the last good inventory instead of deleting everything.

Set-aside files

A file that does not fit the layout, cannot be opened, or is locked is set aside: none of its rows load, and files_events records which file and why. It is retried automatically the next time it changes. There is no Rescan button.

What Claude sees

The data as of the last scan. No MCP tool triggers a scan, so ask “when was this last updated?” and Claude reads the latest event_at in files_events for you.

What Claude can do once connected

Claude sees nineteen small tools. You never call them yourself; Claude picks the right one for your question. In plain terms:

Understand your data

List connectors, databases and Agents. Read the tables and columns of your Web Server Logs file with descriptions, sample values and relationships when Schema Intelligence has run.

Profile and explore

Profile a column to see its real values before filtering on it. Discover joins between tables that never had a foreign key declared. (Analyze)

Use your saved queries

List the saved, parameterised queries your team trusts and run them with new values. Federated queries that span sources run server-side and come back already joined.

Run read-only SQL

Write and run a SELECT in the right dialect for Web Server Logs. Up to 1,000 rows and 60 seconds by default; Claude can ask for more, up to 50,000 rows and five minutes. (Execute)

Check alerts

List your alert rules, their current state and recent firings. Claude can draft a rule as a dry run; a person arms it on the Alerts page.

Improve the model

Check Schema Intelligence coverage per database and, with your agreement, queue a run so the next answers are better. (Analyze)

The tool names, if you want to recognise them in Claude’s replies
PermissionTools
Readqs_list_organizations qs_list_agents qs_list_connectors qs_get_si_status qs_get_connector_schema qs_get_table_schema qs_get_relationships qs_list_saved_queries qs_get_task_status qs_list_alert_rules qs_get_alert_state qs_list_recent_alerts
Analyzeqs_profile_table qs_discover_relationships qs_request_si_analysis qs_setup_si
Executeqs_run_query qs_run_saved_query qs_create_alert_rule (proposes only; never armed from Claude)

Why Schema Intelligence matters here

Every answer Claude receives is tagged with where the structure came from, and Claude adjusts how much it trusts what it sees.

TierWhat Claude seesResult
Schema IntelligenceDescriptions for every table and column, sample values, enum meanings, declared and discovered joins.Claude writes the right Web Server Logs SQL first time and explains the data in your business terms.
Captured schemaTable and column names, types, keys.Claude works, but infers meaning from names and may ask a follow-up.
Live schemaThe database is outside the connector’s capture selection, so structure is read live on each request (needs the Execute permission; SQL Server, MySQL and PostgreSQL).Queries still run. Claude explores with small selects when it needs more.

If a database matters, run Schema Intelligence on it once from Nova → Intelligence. The My Keys tab shows a coverage panel per connector. How Schema Intelligence works.

What the plans allow

MCP is on every plan, including Free, with no separate fee. What each plan sets is how many keys or connected apps you can hold and how many calls a minute Claude may make:

PlanKeys per userKeys per organizationCalls per minute
Free1130
Personal Core1160
Personal Plus1190
Business Core23120
Business Plus35150
Business Max510240
Enterprise Core525300
Enterprise Plus850450
Enterprise Max10100600

A connected app counts as a key. On top of the per-minute figure, any one key may run at most 10 queries a minute. A query returns up to 1,000 rows and runs for up to 60 seconds unless Claude asks for more, to a ceiling of 50,000 rows and five minutes. The rows Claude receives count against your Data Realm allowance, the same pool your Excel and Sheets queries use, and MCP is measured before compression, so a wide result costs more here than the same rows in a spreadsheet. Schema Intelligence runs started from Claude spend Nova AI credits, exactly as they do from the Portal. See the pricing page for the allowances.

Keeping it safe

Read-only, checked by the Agent

Only SELECT statements run. The check happens on the computer that runs the Agent, before your Web Server Logs file sees the SQL, so nothing Claude writes can change data.

No credentials in the AI

The Web Server Logs login stays on the Agent. Claude holds a Query Streams key or connection, which you can revoke from the MCP page; the change takes effect within about five minutes.

Everything is logged

Every tool call appears on the MCP Activity tab and every query in Query History as client type MCP, attributed to the person whose key or connection made it. The SQL text and the key itself are never written to the activity log.

What the AI provider receives

Table and column names, the Schema Intelligence descriptions including sample values, and the rows of the queries you ask for. Those go to the AI provider you connected, under its terms. Query Streams never sees your chat.

Good next moves

  • Run Schema Intelligence on the connector so Claude gets plain-English descriptions of your own columns. The file tables already carry built-in descriptions.
  • Shorten the Scan interval for fresher traffic answers. The default is every hour, and every 5 minutes is the shortest option.
  • Open the connector’s Files dialog to see each log file and why any is set aside. In the connector list, this connector shows as Log Files.

When something doesn’t work

What you seeWhat it meansFix
Claude shows no Query Streams toolsThe connector was added but never connected from a chat, or the key was pasted into the wrong place.In Claude: + → Browse connectors → Query Streams → Connect. In a developer tool: restart it, then check Last used on My Keys.
MCP_KEY_REQUIRED or 401No key reached the server, usually a stray newline from copy and paste or the key in the wrong header.Copy the key again from My Keys and send it in the X-MCP-Key header.
MCP_USER_DISABLEDAn admin switched MCP off for your user.Ask them to turn the MCP switch back on under Account → Access Control.
MCP_SCOPE_REQUIRED or MCP_SCOPE_DENIEDThe key or connection lacks the permission for that action, usually Execute.Edit the key on My Keys and tick Execute, or reconnect the app and approve it.
MCP_KEY_ORG_LIMIT_EXCEEDEDYour plan’s key limit is used up. On Free that is one key or one connected app.Revoke one you no longer use, or move up a plan.
MCP_AGENT_NOT_CONNECTED or MCP_AGENT_NOT_REGISTEREDThe Agent that owns your Web Server Logs file is not connected right now.Open Data → Data Agents and start the Agent on its computer.
MCP_DATABASE_NOT_CAPTUREDThe database is outside the connector’s capture selection, so there is no stored schema or Schema Intelligence for it. Queries still work.Add it to the capture selection on the connector, then run Schema Intelligence if you want richer answers.
MCP_RATE_LIMITEDToo many calls a minute for your plan, or more than 10 query runs a minute on one key.Wait a moment. Schema Intelligence lets Claude answer in fewer calls.
MCP_QUERY_TIMEOUT or MCP_OUTPUT_TOO_LARGEThe query ran past its timeout or returned more than Claude can take in one reply.Ask for fewer rows or columns, or a date filter. Claude usually suggests this itself.
MCP_DATA_REALM_EXHAUSTEDYour organization’s data allowance for the period is used up.Wait for the allowance to reset or top it up from the Portal.
Read-only violationThe SQL was not a SELECT.By design. Nothing writes through MCP.

Questions people ask

Are rotated and gzipped logs read twice?

No. A rotated file is recognised by its first 4 KB and continues the same stream. Each .gz member is read once, and zip and cab archives are skipped. The files_events table records each rotation as a rotated event.

How far back does the first read go, and how long are requests kept?

The first read goes back 30 days, set by Backfill (days), and reads at most 64 MiB per file. After that, new lines are picked up on each scan. Web Server Logs keeps events for 60 days by default under Keep events for N days.

What happens to lines that do not parse?

They are kept in events_raw_lines with the original line and a reason, such as no-grammar-match. Nothing is dropped. Many unparsed lines usually mean the Log type does not match your server’s log format.

Does Claude read my files?

No. The Agent reads them on its own computer and keeps the rows in a local cache there. Claude sends SQL to Query Streams, the Agent runs it against that cache, and only the rows the question needs travel back. Claude never opens a file and cannot change, move or delete one.

Do I need to open a port or run a VPN?

No. The Agent makes one outbound connection on port 443 and both requests and rows travel over it. If outbound HTTPS works, this works.

Can the folder be on a network share, or in OneDrive or Dropbox?

A share works as long as the Agent’s computer can open it; type it as \\server\share\folder, because the Agent runs as a service and cannot see drives mapped at your login, and add the share login on the folder’s row if it needs one. For a synced cloud folder, set it to keep files on this device; the Agent skips cloud placeholder files.

Does the Free plan really cover this?

Yes. Free is a plan you keep, not a trial that expires. MCP is included on every plan; Free allows one key or one connected app and 30 calls a minute. Folder connectors have no file cap of their own. See exactly what Free includes on the pricing page.

Which AI tools work besides Claude?

Anything that speaks MCP over HTTP: ChatGPT, Cursor, VS Code with Copilot, Visual Studio, OpenAI Codex CLI, Gemini CLI, Windsurf, Zed, Cline, Continue.dev and JetBrains AI all have a ready-made recipe on the Connect tab.

Still stuck? Open Support in Query Streams and tell us which step you are on and what you see. We will get you connected.
The same Web Server Logs connection also feedsExcel and Google SheetsAutomationthe REST APIthe full MCP setup guide
Updated on September 28, 2026

Powered by BetterDocs