splunk-mcp

MCP.Pizza Chef: livehybrid

Twelve commands are on offer, and every one of them looks rather than changes: run a search over a time window, list indexes and their sourcetypes, inspect a single index, list saved searches and users, show who you are signed in as, and check the connection is alive. Splunk has since released a first-party server, and this community project was archived in 2026 — its own page points readers to the Splunk MCP Server on Splunkbase, app 7931. Signing in uses either a Splunk token or your Splunk username and password.

Archived · The author made this repository read-only on GitHub.
Coding
Data

Use This MCP server To

Search yesterday's logs for a specific error List the indexes my account can actually see Check which sourcetypes live inside an index Review the saved searches my team set up Confirm my Splunk connection is working

README

⚠️ This project is archived — use the official Splunk MCP Server

Thank you to everyone who used, starred, and forked this project! 🙏 It started as a community effort to bring Model Context Protocol (MCP) support to Splunk, well before an official option existed.

Splunk now ships a first-party, fully supported MCP server that has grown beyond what this community project provides. Please migrate to the official server:

This repository is now read-only / archived and will no longer receive updates. The code below is preserved for historical reference. Thanks again! 🚀


Splunk MCP (Model Context Protocol) Tool

A FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resources through an intuitive interface.

Operating Modes

The tool operates in three modes:

  1. SSE Mode (Default)

    • Server-Sent Events based communication
    • Real-time bidirectional interaction
    • Suitable for web-based MCP clients
    • Default mode when no arguments provided
    • Access via /sse endpoint
  2. API Mode

    • RESTful API endpoints
    • Access via /api/v1 endpoint prefix
    • Start with python splunk_mcp.py api
  3. STDIO Mode

    • Standard input/output based communication
    • Compatible with Claude Desktop and other MCP clients
    • Ideal for direct integration with AI assistants
    • Start with python splunk_mcp.py stdio

Features

  • Splunk Search: Execute Splunk searches with natural language queries
  • Index Management: List and inspect Splunk indexes
  • User Management: View and manage Splunk users
  • KV Store Operations: Create, list, and manage KV store collections
  • Async Support: Built with async/await patterns for better performance
  • Detailed Logging: Comprehensive logging with emoji indicators for better visibility
  • SSL Configuration: Flexible SSL verification options for different security requirements
  • Enhanced Debugging: Detailed connection and error logging for troubleshooting
  • Comprehensive Testing: Unit tests covering all major functionality
  • Error Handling: Robust error handling with appropriate status codes
  • SSE Compliance: Fully compliant with MCP SSE specification

splunk-mcp FAQ

Is this still maintained?
No. It was archived in 2026 and is now read-only. Its own page recommends moving to Splunk's official MCP Server, published by Splunk on Splunkbase as app 7931.
Should I use this or the official one?
Start with the official Splunk server. This one is kept for reference, still runs, and has around seventeen issues left open with nobody to close them.
Do I need a key?
You need Splunk sign-in details — the address of your Splunk server plus either a Splunk token or your username and password. They sit in a settings file on the machine running it, so this is your real account login, not a throwaway.
Can I use this to hunt down an error in yesterday's logs?
Yes. You describe what you are looking for, it runs the search across the time window you name, and it brings back the matching events.
Can it change or delete anything in Splunk?
None of its commands are built to. The search command does pass along whatever search you ask for, though, so connect it with a read-only account rather than an administrator one.
The write-up mentions creating and deleting storage collections — can it?
No. The description promises commands for creating and deleting key-value collections, but only the listing command actually exists in the code.
How hard is the setup?
This one is a job for a technical colleague. You download the code, install it with a Python tool, put your Splunk details in a file, and start it in the mode your assistant expects.
Which apps does it work with?
Claude Desktop is the documented one. It can also run as a web-style service for other clients, and it fits anywhere that accepts a standard MCP entry.
Is there a security setting to watch?
Yes. Certificate checking can be switched off with a single setting, which people often do for internal Splunk servers. Leave it on unless someone who knows your network tells you otherwise.
Does it cost anything?
The add-on is free. It needs an existing Splunk Enterprise or Splunk Cloud account, which is not.