Splunk
The official Splunk MCP Server is a Splunk-supported application that provides a standardized, secure, and scalable interface for connecting AI assistants, agents, and other intelligent systems with data in the Splunk platform. Available as a Splunkbase app (ID 7931), it runs within your Splunk instance and exposes an HTTP/SSE endpoint on the management port (8089) at `/services/mcp`. The server provides six core tools: `generate_spl` for converting natural language to SPL queries using AI, `run_splunk_query` for executing SPL searches with configurable time ranges and result limits, `get_splunk_info` for retrieving instance metadata, `get_indexes` and `get_index_info` for index discovery and metadata, and `get_saved_searches` for knowledge object discovery. All interactions respect existing Splunk role-based access control (RBAC), ensuring users can only access data their roles permit. Authentication uses encrypted bearer tokens generated within the MCP Server app, and the server supports both Splunk Enterprise (on-premises) and Splunk Cloud Platform deployments across versions 8.0 through 10.2. Clients connect using the `mcp-remote` npm package as a proxy, and administrators can enable or disable individual tools at the server level. The server is also available on the Azure Marketplace and AWS Marketplace for cloud deployments.
Composite of vulnerability cleanliness, spec conformance, provenance, stability, and usage signals — scanned and weighted by Cognium. Human and agent signals are tracked separately. Last scanned 2026-09-28.
Scan details: Circle-IR · 2026-09-28 · Appeal
View full trust & usage report →Metadata
- Version
- 1.0.0
- Skill type
- atomic
- Execution layer
- mcp-remote
- Category
- cloud-infra
- Source
- PulseMCP
- Author type
- human
- Last scanned
- 2026-09-28
- Updated
- 2026-09-28
Use via MCP
Resolve Splunk from your agent
Streamable HTTP transport at https://api.skillsregistry.net/mcp. No auth for read tools. Discovery: .well-known/mcp.json.
One command in your shell — Claude Code wires it up and verifies the connection. Run /mcp in any session to confirm.
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp --scope user for --scope project to commit it to .mcp.json.