If you’re looking for something for Splunk Cloud then check out https://www.splunk.com/en_us/blog/artificial-intelligence/unlock-the-power-of-splunk-cloud-platform-...
Having looked at the .conf25 sessions it sounds like there will be an official Splunk Enterprise MCP server released/announced then, for now it’s just cloud.
In the meantime, back in April I built https://github.com/livehybrid/splunk-mcp which I’ve been using with a couple of customers and currently testing a Splunk native app version which should be updated in GitHub soon.
Ultimately if you’re not in a hurry then it’s worth waiting to see what’s announced at Conf or using an existing open source version in the meantime.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.
We are currently implementing MCP (Model Context Protocol) for our daily operations with Splunk Enterprise on-premise. I need to clarify the architecture and access patterns for our setup:
Current Challenges: