Best Splunk MCP Servers
Splunk is a software platform that enables users to search, monitor, and analyze machine-generated data through a web-style interface. It specializes in collecting and indexing massive amounts of data to provide real-time visibility, troubleshooting, and security for IT operations, security, and business analytics.
Why this server?
Allows relayed security evidence from Splunk (e.g., EDR silence, change freezes, blast radius) to be supplied to Chokepoint Finder's pre-flight gates with provenance and coverage tracking, informing HOLD/PROCEED decisions.
AlicenseAqualityCmaintenanceReduces thousands of security findings to the smallest set of high-impact remediation actions, with fail-closed safety gates, typed execution plans, and verification that refuses false all-cleans.10MITWhy this server?
Provides Splunk SPL detection rules for threat detection and hunting across the threat intelligence corpus.
AlicenseAqualityAmaintenanceMCP server for Threadlinqs Intelligence — 49 tools across threat intelligence, detections, IOCs, threat actors, MITRE attack-chains, C2 infrastructure, and Purple-tier composite intelligence. Drop-in for Claude Code, Claude Desktop, Cursor, and any MCP-compatible client.73546MITWhy this server?
Provides detection lookup files for enrichment in Splunk, enabling efficient lookup operations for threat detection.
AlicenseAqualityCmaintenanceMachine-readable detection lookups for SIEM enrichment and AI agents. Query 800+ LOLBAS and GTFOBins binaries plus process parent-child baselines — get risk levels, abuse categories, and MITRE ATT\&CK mappings without embedding data in prompts.6Apache 2.0Why this server?
Allows querying Splunk logs by converting search patterns to Splunk's query language via the query_external_logs tool.
AlicenseAqualityBmaintenanceMCP server that stream-parses NDJSON log files without loading them into memory — filter by pattern, detect error spikes via Z-score analysis, summarize severity timelines by time window.827MITWhy this server?
Allows exporting audit events and GPU metrics to Splunk for security information and event management.

vibops-mcpofficial
FlicenseAqualityAmaintenanceVibOps MCP is the control plane between your AI agents and your GPU infrastructure. 74 tools covering: GPU fleet management (deploy, scale, monitor across NVIDIA, AMD, Intel, AWS, Google, Groq), Agent Infrastructure Control Plane (per-agent GPU cost, budget enforcement, model policies, dependency graph), governance (AI Act, SOC 2, immutable HMAC audit chain), and GPU FinOps (chargeback, waste..)..7418Why this server?
Routes USAP security payloads to the Splunk MCP for security monitoring and incident response.
AlicenseAqualityAmaintenanceExposes 79 cybersecurity skills and 12 orchestrator agents over MCP, with a typed 11-field output contract, an enforced resolvable-evidence gate (no verdict without a resolvable source), and human-approval gating for every mutating action. Apache-2.0, stdlib-only.83Apache 2.0Why this server?
Provides comprehensive SOC investigation tools including IP pivoting, lateral movement detection, data exfiltration analysis, attack timeline reconstruction, and threat intelligence enrichment by querying Splunk indexes and security data.
AlicenseBqualityDmaintenanceEnables AI-driven SOC investigations by providing automated Splunk querying, threat intelligence enrichment, and response actions through natural language. Includes tools for IP pivoting, lateral movement detection, and label harvesting.311Apache 2.0Why this server?
Supports Splunk log integration through JSON log format output, allowing structured logging events to be consumed by Splunk's log aggregation platform.
AlicenseAqualityAmaintenanceEnables AI assistants to execute shell commands and transfer files via SFTP across remote servers using existing SSH configurations. It supports parallel execution on server groups and provides built-in safety warnings for potentially destructive commands.62Mozilla Public 2.0Why this server?
Provides tools for querying Cribl Stream and Edge deployments, including retrieval of worker groups, fleets, sources (including Splunk collectors), destinations, pipelines, routes, event breakers, and lookups with full configuration details.
AlicenseAqualityBmaintenanceEnables querying and exploring Cribl Stream and Edge deployments, providing access to worker groups, fleets, sources, destinations, pipelines, routes, event breakers, and lookups through a structured interface.71MIT No Attribution