Splunk Enterprise

Splunk MCP Server

Narendra_Rao
Loves-to-Learn Lots
I'm working on observability tooling and have built a MCP bridge that routes queries / Admin activities for splunk along with several other tools .

How do i get if their is some existing MCP's built already for splunk and move way ahead?

Happy to collab!
Labels (2)
Tags (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @Narendra_Rao 

If you’re looking for something for Splunk Cloud then check out https://www.splunk.com/en_us/blog/artificial-intelligence/unlock-the-power-of-splunk-cloud-platform-...

Having looked at the .conf25 sessions it sounds like there will be an official Splunk Enterprise MCP server released/announced then, for now it’s just cloud.
 

In the meantime, back in April I built https://github.com/livehybrid/splunk-mcp which I’ve been using with a couple of customers and currently testing a Splunk native app version which should be updated in GitHub soon. 

Ultimately if you’re not in a hurry then it’s worth waiting to see what’s announced at Conf or using an existing open source version in the meantime. 

 

 

🌟 Did this answer help you? If so, please consider:

    • Adding karma to show it was useful
    • Marking it as the solution if it resolved your issue
    • Commenting if you need any clarification

 

 

Your feedback encourages the volunteers in this community to continue contributing.

0 Karma

Narendra_Rao
Loves-to-Learn Lots

We are currently implementing MCP (Model Context Protocol) for our daily operations with Splunk Enterprise on-premise. I need to clarify the architecture and access patterns for our setup:

Current Challenges:

  1. Token Provisioning: How should admins provision tokens to different teams for MCP access?
  2. MCP Splunk Hosting: What's the recommended approach to host MCP server for Splunk integration?
  3. Cross-Team Access: How can we enable other teams to access our MCP Splunk instance?
  4. VS Code Integration: What's the proper way to connect VS Code → Augment → Splunk MCP?

    Any Help on this ?
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...