splunk-mcp

splunk-mcp

3.5

If you are the rightful owner of splunk-mcp and would like to certify it and/or have it hosted online, please leave a comment on the right or send an email to henry@mcphub.com.

A FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language.

Splunk MCP is a tool designed to facilitate interaction with Splunk Enterprise/Cloud using natural language. It leverages the FastMCP framework to provide a seamless interface for executing searches, managing KV stores, and accessing various Splunk resources. The tool operates in three modes: SSE, API, and STDIO, each catering to different use cases and client types. With features like async support, detailed logging, and comprehensive error handling, Splunk MCP ensures efficient and reliable communication with Splunk instances. It also includes robust testing and debugging capabilities, making it a versatile tool for both development and production environments.

Features

  • Splunk Search: Execute Splunk searches with natural language queries
  • Index Management: List and inspect Splunk indexes
  • User Management: View and manage Splunk users
  • KV Store Operations: Create, list, and manage KV store collections
  • Async Support: Built with async/await patterns for better performance

Tools

  1. Tools Management

    List all available MCP tools

  2. Health Check

    Verify connectivity and server status

  3. User Management

    Manage user information

  4. Index Management

    Manage index information

  5. Search

    Perform a Splunk search

  6. KV Store

    Manage KV storage collections