Splunk MCP Server

A Go implementation of the MCP server for Splunk. Supports STDIO and SSE (Server-Sent Events HTTP API). Uses github.com/mark3labs/mcp-go SDK.

Local serverstdioGo

What is the Splunk MCP server?

A Go implementation of the MCP server for Splunk. Supports STDIO and SSE (Server-Sent Events HTTP API). Uses github.com/mark3labs/mcp-go SDK. The splunk mcp server wraps that behind the Model Context Protocol, so an assistant can use it through 5 defined tools rather than through you.

Its toolset

Everything the assistant can do here goes through one of these:

  • list_splunk_saved_searches — Parameters:
  • list_splunk_alerts — Parameters:
  • list_splunk_fired_alerts — Parameters:
  • list_splunk_indexes — Parameters:
  • list_splunk_macros — Parameters:

Adding it to your client

Setup follows the usual MCP pattern — install or clone the server, register it in your client's configuration file, restart the client. The configuration blocks on this page cover the common clients.

Configuration

You will need 3 environment variables: SPLUNK_URL, SPLUNK_TOKEN, YOUR_SESSION_ID. The server will not start without them, which is usually why the tools fail to appear on a first run. Keep credentials in your client's env block or a secrets manager rather than in a file you might commit.

When to reach for it

This sits in the developer tooling group, where several servers overlap in what they claim to do but differ sharply once you actually set them up. Splunk's toolset — list_splunk_saved_searches, list_splunk_alerts, list_splunk_fired_alerts and 2 more — is a fair guide to whether it matches your workflow. It is maintained by jkosik; worth a glance at recent repository activity before you build anything load-bearing on it.

We check each listing at SyncDev against the project's documentation before it goes live — if something here drifts out of date, it is a bug worth reporting.

Caveats

  • It runs with your machine's permissions. That is convenient and also the reason to think about what you point it at before you approve a tool call.
  • Missing credentials fail quietly in some clients — if no tools show up, check the environment block first.
  • MCP clients confirm each tool call by default. Leave that on until you have watched what the splunk mcp server does with a few real requests.

Available tools

ToolWhat it does
list_splunk_saved_searchesParameters:
list_splunk_alertsParameters:
list_splunk_fired_alertsParameters:
list_splunk_indexesParameters:
list_splunk_macrosParameters:

How to install the Splunk MCP server

{
  "mcpServers": {
    "splunk_sse": {
      "name": "Splunk MCP Server (SSE)",
      "description": "MCP server for Splunk integration (SSE mode)",
      "type": "sse",
      "url": "http://localhost:3001/sse"
    }
  }
}

Configuration as documented by the project. Restart the client after saving.

Configuration

VariableDescriptionRequired
SPLUNK_URLEndpoint or connection string the server talks to.Yes
SPLUNK_TOKENCredential the server authenticates with.Yes
YOUR_SESSION_IDConfiguration value read at startup.Optional

Example prompts to try

  • Use Splunk to list splunk saved searches.
  • Use Splunk to list splunk alerts.
  • Use Splunk to list splunk fired alerts.

Frequently asked questions

It connects Splunk to MCP-compatible AI assistants such as Claude and Cursor, exposing 5 tools (list_splunk_saved_searches, list_splunk_alerts, list_splunk_fired_alerts, and more) that the assistant can call on your behalf. Instead of copying data back and forth by hand, the assistant works with Splunk directly.