Back to the MCP Gateway catalog

MCP Gateway · Catalog

Splunk icon

Splunk MCP server

Official

Splunk MCP is the official Model Context Protocol server for Splunk, with API key authentication and tools that let agents run SPL queries and inspect indexes, metadata, users, and knowledge objects. Connect it through the Speakeasy MCP Gateway and agents such as Claude, Cursor, and ChatGPT get one governed URL for it, with SSO, RBAC, and a full audit trail.

Infrastructure9 toolsAuth: api key

Behind the MCP Gateway

Run Splunk MCP behind the MCP Gateway

One URL for every agent, sign-in through your IdP, RBAC down to the tool, and every Splunk call inspected and logged.

Deploy on MCP Gateway

Tools · 9

Each tool below can be allowed or denied per team and role at the MCP Gateway, and every call is inspected and logged.

splunk_get_info

Get comprehensive information about the Splunk instance. Retrieves system information including version, hardware specs, and operational status.

splunk_get_indexes

Get a list of indexes from Splunk. Indexes are data repositories where machine data is stored and organized.

splunk_get_index_info

Get detailed information about a specific Splunk index. Returns comprehensive configuration and status information for the specified index.

splunk_get_user_list

Get a list of users from Splunk. Retrieves information about all users including authentication details, roles, and account status.

splunk_get_user_info

Retrieves detailed information about the currently authenticated user including roles and permissions. Returns comprehensive user profile data for the current session.

splunk_run_query

Execute a Splunk search query and return the results. This is the primary tool for running Splunk searches using SPL (Search Processing Language). Use this to retrieve log data, perform aggregations, analyze events, and extract insights from your Splunk environment.

splunk_get_metadata

Retrieve metadata about hosts, sources, or sourcetypes across one or more indexes in the selected time window.

splunk_get_kv_store_collections

Get KV Store collection statistics including size, count, and storage information. Retrieves comprehensive metrics about all KV Store collections in the Splunk instance.

splunk_get_knowledge_objects

Retrieve Splunk knowledge objects by type. Supports various knowledge object types including saved searches, alerts, field extractions, lookups, macros, data models, and more.

Questions

What is a Splunk MCP server?
A Splunk MCP server exposes Splunk to AI agents as Model Context Protocol tools. Instead of a custom integration per agent, any MCP client can connect to the server and call tools such as splunk_get_info or splunk_get_indexes to work with Splunk. The server in this catalog is the official Splunk MCP server, which authenticates with an API key.
What can you do with Splunk MCP?
Agents can run SPL queries and inspect indexes, metadata, users, and knowledge objects. The catalog lists 9 tools for this server, including splunk_get_info, splunk_get_indexes, and splunk_get_index_info. The full list with descriptions is on this page.
Why put Splunk MCP behind an MCP gateway?
Connecting the Splunk MCP server directly to each client means a separate credential per developer, no inventory of who can reach Splunk through an agent, and no record of what agents did with it. An MCP gateway sits between every agent and the Splunk server, so sign-in runs through your identity provider, role-based access decides which teams can call which Splunk tools, and every call is inspected and logged in one place. The Speakeasy MCP Gateway applies those controls to Splunk and to every other server in your catalog.
How do you connect Splunk MCP through a gateway?
Add the Splunk server from the Speakeasy MCP catalog and every agent reaches it through one gateway URL, next to the rest of your approved servers. Authentication uses OAuth 2.1 with PKCE and dynamic client registration, sign-in runs through your identity provider, and role-based access controls decide which teams can use which Splunk tools. Every prompt, response, and tool call is inspected and logged at the gateway.
How is this different from an unofficial Splunk MCP?
Community-built Splunk MCP servers wrap the same Splunk surface but are not vendor-maintained. This catalog lists the official Splunk MCP server. Running it behind the Speakeasy MCP Gateway adds SSO, role-based access controls, and an audit trail of every call, whichever credential the server itself uses.

AI everywhere.

Control here.