A FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resources
A security-focused MCP server that enables automated log retrieval and threat analysis using LangGraph orchestration and RAG. It allows users to detect suspicious activity and generate structured security insights by integrating LLM reasoning with log data and runbook documentation.
Discover available Splunk CIM data models with names, descriptions, use cases, required tags, and deprecation status. Use this to identify which models to query with get_cim_reference.
Check Splunk server connectivity and retrieve comprehensive health status including version and system information. Supports custom connection parameters for testing different instances.
Execute a specific Splunk workflow by ID with adjustable parameters, time windows, and focus hosts. Supports core and contrib workflows for targeted troubleshooting.
Discover accessible Splunk data indexes to build searches or troubleshoot data availability. Returns customer indexes based on current user permissions.