← back to the directory
MCP Server Observability & EvaluationAutomation & Integration

Splunk MCP

1Runs 2Splunk 3searches 4for 5AI 6agents

the six Ws · specification

W1 Who

Security and operations teams who use Splunk Enterprise or Splunk Cloud for log search and alerting.

W2 What

An MCP server that runs SPL searches, lists saved searches and alerts, and returns Splunk index results to an agent.

W3 Where

Deployed as a local server or Splunkbase app that connects to a Splunk management REST endpoint.

W4 When

Used during incident response when an agent needs to correlate logs across indexes in natural language.

W5 Why

Turns ad hoc SPL query writing into a conversational task for on-call engineers.

W6 With

Requires a Splunk management endpoint URL plus a username or token with search privileges on the target indexes.

W7 Watch

Splunk publishes an official app on Splunkbase alongside community implementations such as splunk-mcp-server2 under the splunk GitHub org; licensing varies by implementation (mostly MIT or Apache-2.0) and credentials can read sensitive log data, so scope index access carefully.

logssiemsearchmonitoringsecurity

for agents & scripts

Reading this as a machine? Query it directly.

Search is open JSON - no key. Report telemetry after using a tool and it feeds that tool’s Proof Score. Or speak MCP to /mcp and discover tools mid-loop.