MCP Server for Splunk

by jkosik

177 downloads Not rated yet

About

An MCP server for Splunk to search, analyze, and visualize machine-generated data from your Splunk instance.

Explore

- list_splunk_saved_searches – List saved searches with pagination.
- list_splunk_alerts – Query alerts, optionally filtered by title.
- list_splunk_fired_alerts – Retrieve fired alerts with time range filter.
- list_splunk_indexes – List Splunk indexes.
- list_splunk_macros – List Splunk macros.
- Includes a prompt to find alerts by keyword and a resource from a local CSV file.

curl -X POST "http://localhost:3001/message?sessionId=YOUR_SESSION_ID" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | jq
``

smithery badge

Dockerfile and smithery.yaml` are used to support hosting this MCP server at [Smithery](https://smithery.ai/server/@jkosik/.

list_splunk_saved_searches

Parameters:

count

(number, optional): Number of results to return (max 100, default 100)

offset

(number, optional): Offset for pagination (default 0)

list_splunk_alerts

Parameters:

title

(string, optional): Case-insensitive substring to filter alert titles

list_splunk_fired_alerts

Parameters:

ss_name

(string, optional): Search name pattern to filter alerts (default "*")

earliest

(string, optional): Time range to look back (default "-24h")

list_splunk_indexes

Parameters:

list_splunk_macros

Parameters:

- list_splunk_saved_searches
- Parameters:
- count (number, optional): Number of results to return (max 100, default 100)
- offset (number, optional): Offset for pagination (default 0)
- list_splunk_alerts
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- title (string, optional): Case-insensitive substring to filter alert titles
- list_splunk_fired_alerts
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- ss_name (string, optional): Search name pattern to filter alerts (default "*")
- earliest (string, optional): Time range to look back (default "-24h")
- list_splunk_indexes
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- list_splunk_macros
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)

echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | go run cmd/mcp-server-splunk/main.go | jq

echo '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_splunk_saved_searches","arguments":{}}}' | go run cmd/mcp-server-splunk/main.go | jq
```

A Go implementation of the MCP server for Splunk.
Supports STDIO and SSE (Server-Sent Events HTTP API). Uses github.com/mark3labs/mcp-go SDK.

MCP Tools implemented

- list_splunk_saved_searches - Parameters: - count (number, optional): Number of results to return (max 100, default 100) - offset (number, optional): Offset for pagination (default 0) - list_splunk_alerts - Parameters: - count (number, optional): Number of results to return (max 100, default 10) - offset (number, optional): Offset for pagination (default 0) - title (string, optional): Case-insensitive substring to filter alert titles - list_splunk_fired_alerts - Parameters: - count (number, optional): Number of results to return (max 100, default 10) - offset (number, optional): Offset for pagination (default 0) - ss_name (string, optional): Search name pattern to filter alerts (default "*") - earliest (string, optional): Time range to look back (default "-24h") - list_splunk_indexes - Parameters: - count (number, optional): Number of results to return (max 100, default 10) - offset (number, optional): Offset for pagination (default 0) - list_splunk_macros - Parameters: - count (number, optional): Number of results to return (max 100, default 10) - offset (number, optional): Offset for pagination (default 0)

MCP Prompts and Resources

- internal/splunk/prompt.go implements an MCP Prompt to find Splunk alerts for a specific keyword (e.g. GitHub or OKTA) and instructs Cursor to utilise multiple MCP tools to review all Splunk alerts, indexes and macros first to provide the best answer. - cmd/mcp/server/main.go implements MCP Resource in the form of local CSV file with Splunk related content, providing further context to the chat.

Usage

STDIO mode (default)

```bash export SPLUNK_URL=https://your-splunk-instance export SPLUNK_TOKEN=your-splunk-token
No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.