Best Splunk MCP Servers
Splunk is a software platform that enables users to search, monitor, and analyze machine-generated data through a web-style interface. It specializes in collecting and indexing massive amounts of data to provide real-time visibility, troubleshooting, and security for IT operations, security, and business analytics.
Why this server?
Allows exporting audit events and GPU metrics to Splunk for security information and event management.
AlicenseAqualityAmaintenanceVibOps MCP is the control plane between your AI agents and your GPU infrastructure. 74 tools covering: GPU fleet management (deploy, scale, monitor across NVIDIA, AMD, Intel, AWS, Google, Groq), Agent Infrastructure Control Plane (per-agent GPU cost, budget enforcement, model policies, dependency graph), governance (AI Act, SOC 2, immutable HMAC audit chain), and GPU FinOps (chargeback, waste..)..7418MITWhy this server?
Converts Sigma rules to Splunk SPL queries for detection in Splunk SIEM.
AlicenseAqualityAmaintenanceSigma detection rule writing, validation, and pySigma-based multi-backend conversion (Splunk, Elastic, Wazuh, Kibana) via 3 MCP tools and 3 Claude Code skills, backed by a 61-rule production corpus across 11 MITRE ATT\&CK tactic categories.32MITWhy this server?
Provides Splunk SPL detection rules for threat detection and hunting across the threat intelligence corpus.
AlicenseAqualityBmaintenanceMCP server for Threadlinqs Intelligence — 49 tools across threat intelligence, detections, IOCs, threat actors, MITRE attack-chains, C2 infrastructure, and Purple-tier composite intelligence. Drop-in for Claude Code, Claude Desktop, Cursor, and any MCP-compatible client.81365MITWhy this server?
Allows querying Splunk logs by converting search patterns to Splunk's query language via the query_external_logs tool.
AlicenseAqualityDmaintenanceMCP server that stream-parses NDJSON log files without loading them into memory — filter by pattern, detect error spikes via Z-score analysis, summarize severity timelines by time window.854MITWhy this server?
Routes USAP security payloads to the Splunk MCP for security monitoring and incident response.
AlicenseAqualityAmaintenanceExposes 79 cybersecurity skills and 12 orchestrator agents over MCP, with a typed 11-field output contract, an enforced resolvable-evidence gate (no verdict without a resolvable source), and human-approval gating for every mutating action. Apache-2.0, stdlib-only.84Apache 2.0Why this server?
Provides detection lookup files for enrichment in Splunk, enabling efficient lookup operations for threat detection.
AlicenseAqualityCmaintenanceMachine-readable detection lookups for SIEM enrichment and AI agents. Query 800+ LOLBAS and GTFOBins binaries plus process parent-child baselines — get risk levels, abuse categories, and MITRE ATT\&CK mappings without embedding data in prompts.6Apache 2.0Why this server?
Supports Splunk log integration through JSON log format output, allowing structured logging events to be consumed by Splunk's log aggregation platform.
AlicenseAqualityBmaintenanceEnables AI assistants to execute shell commands and transfer files via SFTP across remote servers using existing SSH configurations. It supports parallel execution on server groups and provides built-in safety warnings for potentially destructive commands.61Mozilla Public 2.0Why this server?
Provides programmatic access to Splunkbase functionality, allowing users to search for apps, retrieve app information, check compatibility with Splunk versions, and download apps from Splunkbase.
AlicenseBqualityDmaintenanceA Machine Control Protocol server providing programmatic access to Splunkbase functionality, allowing users to search, download, and manage Splunkbase apps through a standardized interface.3MITWhy this server?
Provides comprehensive SOC investigation tools including IP pivoting, lateral movement detection, data exfiltration analysis, attack timeline reconstruction, and threat intelligence enrichment by querying Splunk indexes and security data.
AlicenseBqualityDmaintenanceEnables AI-driven SOC investigations by providing automated Splunk querying, threat intelligence enrichment, and response actions through natural language. Includes tools for IP pivoting, lateral movement detection, and label harvesting.311Apache 2.0