Skip to main content
Glama
649,985 tools. Updated 2026-10-10 18:03

"Splunk" matching MCP tools:

  • Configure and manage streaming of audit events to SIEM destinations such as Splunk, Datadog, EventBridge, or webhooks. Check status, test connectivity, or forward events.
    MIT
  • Update the SIEM push export destination for your organization, supporting Splunk and Datadog. Modify provider, endpoint, or token to configure where audit events are sent.
    MIT
  • Pull recent live log events for a pattern from Splunk, Datadog, Elasticsearch, or CloudWatch, grouped by templateHash with extracted slot values. Use for 24-hour event evidence.
    MIT
  • Templatizes a batch of log events locally and returns per-pattern triage with frequency, severity, and slot distributions. Runs in-process without Kubernetes or a Log10x account.
    MIT
  • Validate environment config documents for schema and cross-field errors, providing severity and remediation to ensure coherent settings before downstream use.
    MIT

Matching MCP Servers

  • A
    license
    B
    quality
    D
    maintenance
    A FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resources
    12
    106
    Apache 2.0
  • F
    license
    Not graded
    quality
    D
    maintenance
    A security-focused MCP server that enables automated log retrieval and threat analysis using LangGraph orchestration and RAG. It allows users to detect suspicious activity and generate structured security insights by integrating LLM reasoning with log data and runbook documentation.
    -
  • Before muting, dropping, or deleting logs, scan your SIEM/observability stack to find every monitor, saved search, dashboard, and alert rule that depends on a pattern.
    MIT
  • Retrieve the SIEM push export configuration for your organization, including provider, destination endpoint, and token status.
    MIT
  • Send audit log events to your configured SIEM (Splunk HEC or Datadog Logs API) in a batched request. Returns the number of events pushed and the provider used.
    MIT
  • Execute Splunk searches as tracked jobs with progress and stats. Use for complex or long-running queries needing job status, counts, and reliable result retrieval beyond 30 seconds.
    Apache 2.0
  • Check server availability and get basic information like version and server time to verify connectivity without complex API calls.
    Apache 2.0
  • Retrieve information about the currently authenticated Splunk user, including roles, permissions, and capabilities. Use it to verify user context and debug access issues in Splunk environments.
    Apache 2.0
  • Discover available documentation topics, admin guides, SPL commands, and URI patterns. Use this to find relevant docs by category before requesting specific content.
    Apache 2.0
  • List common Splunk configuration files with brief descriptions. Use this to identify available config files and then call get_config_spec() for detailed specifications.
    Apache 2.0
  • Check Splunk server connectivity and retrieve server health, version, and system info. Test custom connection parameters to validate configurations and troubleshoot connectivity issues.
    Apache 2.0
  • Discover available Splunk KV Store collections with schema details like fields and replication. Filter by app to find collections for lookups, configuration, or caching.
    Apache 2.0
  • List saved searches with ownership, schedule, visibility, and permission metadata. Filter by app, owner, sharing, or name, and paginate through results.
    Apache 2.0