mcp-server-splunk
Allows searching, managing, and analyzing data in Splunk instances, including executing SPL queries, managing indexes, alerts, saved searches, dashboards, knowledge objects, KV store, data inputs, users and roles, apps, and server operations.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mcp-server-splunkSearch for errors in the last hour"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Splunk MCP Server
A Model Context Protocol server for Splunk. Enables AI assistants like Claude to search, manage, and analyze data in Splunk instances.
Installation
Claude Desktop
Add to your Claude Desktop config:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"splunk": {
"command": "uvx",
"args": ["mcp-server-splunk"],
"env": {
"SPLUNK_HOST": "your-splunk-host",
"SPLUNK_TOKEN": "your-token"
}
}
}
}Claude Code (CLI)
claude mcp add splunk -- uvx mcp-server-splunk \
-e SPLUNK_HOST=your-splunk-host \
-e SPLUNK_TOKEN=your-tokenOpenAI Codex
Add to ~/.codex/config.toml:
[mcp_servers.splunk]
command = "uvx"
args = ["mcp-server-splunk"]
[mcp_servers.splunk.env]
SPLUNK_HOST = "your-splunk-host"
SPLUNK_TOKEN = "your-token"OpenCode
Add to your OpenCode config:
mcp:
splunk:
type: local
command: uvx mcp-server-splunk
env:
SPLUNK_HOST: your-splunk-host
SPLUNK_TOKEN: your-tokenRelated MCP server: Splunk MCP Server
Configuration
Variable | Required | Default | Description |
| Yes | localhost | Splunk server hostname |
| No | 8089 | Splunk management port |
| No | https | Connection scheme (http/https) |
| * | - | Authentication token (recommended) |
| * | - | Username (if not using token) |
| * | - | Password (if not using token) |
*Provide either SPLUNK_TOKEN or both SPLUNK_USERNAME and SPLUNK_PASSWORD.
Getting a Splunk Token
Log into Splunk Web
Go to Settings > Tokens
Click New Token
Copy the token value
Tools
Search & Query
search_splunk- Execute SPL queriessearch_async- Non-blocking searchessearch_realtime- Real-time streamingexport_search_results- Export to filerun_saved_search- Execute saved searches
Index Management
list_indexes/get_index_infocreate_index/update_index/delete_indexsend_event- Ingest events
Alerts
list_alerts/create_alert/update_alert/delete_alertget_alert_history
Saved Searches
list_saved_searches/get_saved_search/run_saved_searchcreate_saved_search/update_saved_search/delete_saved_search
Dashboards
list_dashboards/get_dashboard/create_dashboard/delete_dashboard
Knowledge Objects
list_lookups/get_lookup_data/update_lookup_datalist_macros/get_macro/create_macro/update_macro/delete_macrolist_field_extractions/get_field_summary
KV Store
list_kvstore_collections/create_kvstore_collection/delete_kvstore_collectionquery_kvstore_collection/insert_kvstore_data/update_kvstore_data/delete_kvstore_data
Data Inputs
list_inputs/get_input_infocreate_monitor_input/delete_input
Users & Roles
list_users/get_user_info/create_user/update_user/delete_userlist_roles/get_role_info/create_role/update_role/delete_role
Apps
list_apps/create_app/update_app/delete_app
Server
get_server_info/get_server_settingscheck_restart_required/restart_splunk/refresh_splunklist_jobs/get_job_status/get_job_results/cancel_job
Example Prompts
"Search for errors in the last hour"
"List all indexes and their sizes"
"Create an alert for failed logins"
"Show dashboards in the security app"
Development
# Clone and install
git clone https://github.com/pahar0/mcp-server-splunk.git
cd mcp-server-splunk
uv sync
# Run locally
export SPLUNK_HOST=localhost SPLUNK_TOKEN=your-token
uv run mcp-server-splunk
# Debug with MCP Inspector
npx @modelcontextprotocol/inspector uv run mcp-server-splunkLicense
Apache 2.0
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseBqualityFmaintenanceA FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resourcesLast updated12107Apache 2.0
- Flicense-qualityDmaintenanceEnables AI assistants to interact with Splunk Enterprise and Splunk Cloud instances through standardized MCP interface. Supports executing SPL queries, managing indexes and saved searches, listing applications, and retrieving server information with flexible authentication options.Last updated
- AlicenseAqualityBmaintenanceEnables AI agents to interact seamlessly with Splunk environments through 20+ tools for search, analytics, data discovery, administration, and health monitoring. Features AI-powered troubleshooting workflows and supports multiple Splunk instances with production-ready security.Last updated5327Apache 2.0
- Flicense-quality-maintenanceEnables users to interact with Splunk instances to execute SPL queries, manage saved searches, and monitor system health. It provides a clean interface for listing dashboards, indexes, and logs through the Model Context Protocol.Last updated327
Related MCP Connectors
A comprehensive Model Context Protocol (MCP) server that enables AI assistants to interact with yo…
Search your AI chat history (ChatGPT, Claude, Codex) from any MCP client. Remote, private, read-only
A Model Context Protocol server for Wix AI tools
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/pahar0/mcp-server-splunk'
If you have feedback or need assistance with the MCP directory API, please join our Discord server