Discover available Splunk Common Information Model data models with details on use cases, required tags, and deprecation status. Use to identify which CIM models to apply before referencing specific data.
Execute a Splunk search and get immediate results for quick lookups, simple stats, or ad-hoc checks. No job is created, ideal for small result sets under 30 seconds.
A FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resources
A security-focused MCP server that enables automated log retrieval and threat analysis using LangGraph orchestration and RAG. It allows users to detect suspicious activity and generate structured security insights by integrating LLM reasoning with log data and runbook documentation.
Check Splunk server connectivity and retrieve comprehensive health status including version, connection status, and system information. Use custom connection parameters to test different instances.
Execute any Splunk workflow by ID with full control over time ranges, focus areas, and complexity. Supports parallel task execution for diagnostic troubleshooting.
Update the SIEM push export destination for your organization, supporting Splunk and Datadog. Modify provider, endpoint, or token to configure where audit events are sent.
Retrieve a complete Splunk SPL cheat sheet with commands, regex patterns, and usage examples for quick reference during query development and troubleshooting.
List all accessible data indexes in Splunk to discover which indexes you can query for searches and troubleshooting, filtered by your permissions and excluding internal system indexes.
Discover and enumerate all available data sources in your Splunk environment using the metadata command. Provides a comprehensive inventory for data discovery and troubleshooting.
Retrieve a comprehensive inventory of all installed Splunk applications, including metadata like name, version, and visibility. Ideal for auditing, management, and troubleshooting compatibility issues.
Retrieve details of the currently authenticated Splunk user, including username, roles, and capabilities. Use to verify user context or debug access issues.