MCP Server for Splunk
About
An MCP server for Splunk to search, analyze, and visualize machine-generated data from your Splunk instance.
Explore
- list_splunk_saved_searches – List saved searches with pagination.
- list_splunk_alerts – Query alerts, optionally filtered by title.
- list_splunk_fired_alerts – Retrieve fired alerts with time range filter.
- list_splunk_indexes – List Splunk indexes.
- list_splunk_macros – List Splunk macros.
- Includes a prompt to find alerts by keyword and a resource from a local CSV file.
curl -X POST "http://localhost:3001/message?sessionId=YOUR_SESSION_ID" \
-H "Content-Type: application/json" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | jq
``
Dockerfile and smithery.yaml` are used to support hosting this MCP server at [Smithery](https://smithery.ai/server/@jkosik/.
list_splunk_saved_searches
Parameters:
count
(number, optional): Number of results to return (max 100, default 100)
offset
(number, optional): Offset for pagination (default 0)
list_splunk_alerts
Parameters:
title
(string, optional): Case-insensitive substring to filter alert titles
list_splunk_fired_alerts
Parameters:
ss_name
(string, optional): Search name pattern to filter alerts (default "*")
earliest
(string, optional): Time range to look back (default "-24h")
list_splunk_indexes
Parameters:
list_splunk_macros
Parameters:
- list_splunk_saved_searches
- Parameters:
- count (number, optional): Number of results to return (max 100, default 100)
- offset (number, optional): Offset for pagination (default 0)
- list_splunk_alerts
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- title (string, optional): Case-insensitive substring to filter alert titles
- list_splunk_fired_alerts
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- ss_name (string, optional): Search name pattern to filter alerts (default "*")
- earliest (string, optional): Time range to look back (default "-24h")
- list_splunk_indexes
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- list_splunk_macros
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
echo '{"jsonrpc":"2.0","id":1,"method":"tools/list","params":{}}' | go run cmd/mcp-server-splunk/main.go | jq
echo '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"list_splunk_saved_searches","arguments":{}}}' | go run cmd/mcp-server-splunk/main.go | jq
```
A Go implementation of the MCP server for Splunk.
Supports STDIO and SSE (Server-Sent Events HTTP API). Uses github.com/mark3labs/mcp-go SDK.
MCP Tools implemented
-list_splunk_saved_searches
- Parameters:
- count (number, optional): Number of results to return (max 100, default 100)
- offset (number, optional): Offset for pagination (default 0)
- list_splunk_alerts
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- title (string, optional): Case-insensitive substring to filter alert titles
- list_splunk_fired_alerts
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- ss_name (string, optional): Search name pattern to filter alerts (default "*")
- earliest (string, optional): Time range to look back (default "-24h")
- list_splunk_indexes
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
- list_splunk_macros
- Parameters:
- count (number, optional): Number of results to return (max 100, default 10)
- offset (number, optional): Offset for pagination (default 0)
MCP Prompts and Resources
-internal/splunk/prompt.go implements an MCP Prompt to find Splunk alerts for a specific keyword (e.g. GitHub or OKTA) and instructs Cursor to utilise multiple MCP tools to review all Splunk alerts, indexes and macros first to provide the best answer.
- cmd/mcp/server/main.go implements MCP Resource in the form of local CSV file with Splunk related content, providing further context to the chat.
Usage
STDIO mode (default)
```bash export SPLUNK_URL=https://your-splunk-instance export SPLUNK_TOKEN=your-splunk-tokenSign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.


