splunk-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| VERIFY_SSL | No | Enable/disable SSL verification | true |
| SERVER_MODE | No | Server mode (sse, api, stdio) | sse |
| SPLUNK_HOST | Yes | Your Splunk host address | |
| SPLUNK_PORT | No | Splunk management port | 8089 |
| SPLUNK_TOKEN | No | Splunk authentication token (optional; if set, used instead of username/password) | |
| SPLUNK_SCHEME | No | Connection scheme | https |
| SPLUNK_PASSWORD | No | Your Splunk password | |
| SPLUNK_USERNAME | No | Your Splunk username | |
| FASTMCP_LOG_LEVEL | No | Logging level | INFO |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Server capabilities have not been inspected yet.
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_splunkB | |
| list_indexesB | |
| get_index_infoB | |
| list_saved_searchesB | |
| current_userA | |
| list_usersA | List all Splunk users (requires admin privileges) |
| list_kvstore_collectionsB | |
| health_checkA | Get basic Splunk connection information and list available apps |
| get_indexes_and_sourcetypesA | |
| list_toolsB | |
| healthA | Get basic Splunk connection information and list available apps (same as health_check but for endpoint consistency) |
| pingA | |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 12 tools
There is significant overlap between several tools, which could cause confusion. For example, 'health' and 'health_check' appear to be duplicates, and 'list_indexes', 'get_indexes_and_sourcetypes', and 'get_index_info' all relate to indexes with unclear boundaries. However, descriptions help differentiate some tools, such as 'search_splunk' being distinct for query execution.
Naming is inconsistent with mixed conventions. Some tools use verb_noun patterns like 'list_indexes' and 'search_splunk', while others use noun-only forms like 'health' and 'ping'. There are also deviations like 'get_indexes_and_sourcetypes' using 'and' in the name, and 'list_tools' is an outlier as it's meta to the server itself.
With 12 tools, the count is reasonable for a Splunk MCP server, covering user management, indexing, searches, and health checks. It's slightly heavy due to redundant tools like 'health' and 'health_check', but overall well-scoped for the domain without being overwhelming.
The toolset covers core Splunk operations like searching, indexing, and user management, but has notable gaps. For example, there are tools to list saved searches but no way to create, update, or delete them, and similar gaps exist for KV store collections and indexes. This could lead to dead ends for agents trying to perform full lifecycle management.