Best Splunk MCP Servers
Splunk is a software platform that enables users to search, monitor, and analyze machine-generated data through a web-style interface. It specializes in collecting and indexing massive amounts of data to provide real-time visibility, troubleshooting, and security for IT operations, security, and business analytics.
Why this server?
Supports Splunk log integration through JSON log format output, allowing structured logging events to be consumed by Splunk's log aggregation platform.
AlicenseAqualityCmaintenanceEnables AI assistants to execute shell commands and transfer files via SFTP across remote servers using existing SSH configurations. It supports parallel execution on server groups and provides built-in safety warnings for potentially destructive commands.Last updated61Mozilla Public 2.0Why this server?
Provides tools for querying Cribl Stream and Edge deployments, including retrieval of worker groups, fleets, sources (including Splunk collectors), destinations, pipelines, routes, event breakers, and lookups with full configuration details.
AlicenseAqualityDmaintenanceEnables querying and exploring Cribl Stream and Edge deployments, providing access to worker groups, fleets, sources, destinations, pipelines, routes, event breakers, and lookups through a structured interface.Last updated71MIT No AttributionWhy this server?
Enables AI agents to interact with Splunk Enterprise/Cloud environments, providing comprehensive tools for search and analytics, data discovery, administration, health monitoring, and AI-powered troubleshooting workflows. Includes capabilities for natural language to SPL conversion, real-time search management, metadata exploration, user and app management, system health monitoring, and automated diagnostic procedures.
AlicenseAqualityBmaintenanceEnables AI agents to interact seamlessly with Splunk environments through 20+ tools for search, analytics, data discovery, administration, and health monitoring. Features AI-powered troubleshooting workflows and supports multiple Splunk instances with production-ready security.Last updated5322Why this server?
Allows for interacting with Splunk Enterprise/Cloud through natural language queries. Supports executing Splunk searches, managing indexes, viewing users, and performing KV store operations.
AlicenseBqualityCmaintenanceA FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resourcesLast updated12102Apache 2.0Why this server?
Provides detection lookup files for enrichment in Splunk, enabling efficient lookup operations for threat detection.
AlicenseAqualityBmaintenanceMachine-readable detection lookups for SIEM enrichment and AI agents. Query 800+ LOLBAS and GTFOBins binaries plus process parent-child baselines — get risk levels, abuse categories, and MITRE ATT\&CK mappings without embedding data in prompts.Last updated6Apache 2.0Why this server?
Provides programmatic access to Splunkbase functionality, allowing users to search for apps, retrieve app information, check compatibility with Splunk versions, and download apps from Splunkbase.
AlicenseBqualityCmaintenanceA Machine Control Protocol server providing programmatic access to Splunkbase functionality, allowing users to search, download, and manage Splunkbase apps through a standardized interface.Last updated3MITWhy this server?
Allows interaction with Splunk services including support for Splunk HEC (HTTP Event Collector) as a data source within Cribl Stream.
Why this server?
Enables SQL queries against Splunk machine data analytics through CData's JDBC driver
Alicense-qualityCmaintenanceKintone MCP Server by CDataLast updated1MITWhy this server?
Enables SQL-based access to Splunk logs and analytics data.
Alicense-qualityCmaintenanceActive Directory MCP Server by CDataLast updated4MIT