# Splunk

> Use this tool when you need to integrate AI assistants or agents with your Splunk platform, providing a secure and scalable interface to access and query data. It solves problems related to natural language querying, data discovery, and access control, with core tools for converting language to SPL queries, executing searches, and retrieving instance metadata. The tool accepts HTTP/SSE requests and returns query results, instance information, and other relevant data, making it ideal for use cases that require programmatic access to Splunk data.

Canonical page: https://skillsregistry.net/skills/splunk  
JSON: https://api.skillsregistry.net/v1/skills/splunk

## Description

The official Splunk MCP Server is a Splunk-supported application that provides a standardized, secure, and scalable interface for connecting AI assistants, agents, and other intelligent systems with data in the Splunk platform. Available as a Splunkbase app (ID 7931), it runs within your Splunk instance and exposes an HTTP/SSE endpoint on the management port (8089) at `/services/mcp`.

The server provides six core tools: `generate_spl` for converting natural language to SPL queries using AI, `run_splunk_query` for executing SPL searches with configurable time ranges and result limits, `get_splunk_info` for retrieving instance metadata, `get_indexes` and `get_index_info` for index discovery and metadata, and `get_saved_searches` for knowledge object discovery. All interactions respect existing Splunk role-based access control (RBAC), ensuring users can only access data their roles permit.

Authentication uses encrypted bearer tokens generated within the MCP Server app, and the server supports both Splunk Enterprise (on-premises) and Splunk Cloud Platform deployments across versions 8.0 through 10.2. Clients connect using the `mcp-remote` npm package as a proxy, and administrators can enable or disable individual tools at the server level. The server is also available on the Azure Marketplace and AWS Marketplace for cloud deployments.

## Trust

- **Trust score (0–1):** 1.00
- **Verification tier:** verified
- **Last scanned:** 2026-09-28

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** cloud-infra
- **Updated:** 2026-09-28

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/splunk)
- **Repository:** <https://github.com/ciscodevnet/splunk-mcp-server-official>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "splunk"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/splunk` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/splunk/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
