Splunk

Splunk

Official
Observability & Security
Token

Explore Splunk data, discover knowledge objects, and run SPL searches.

Splunk

Explore Splunk data, discover knowledge objects, and run SPL searches. With Lunar.dev MCPX, the MCP Gateway for secure and governed tool access, you connect the Splunk MCP server to Claude, ChatGPT, Cursor, and any MCP client through one gateway that routes, authenticates, and governs every Splunk tool call against your policies.

Why MCPX

MCPX is Lunar.dev's MCP Gateway. It sits between your AI agents and your MCP servers as a single gateway for every tool call, routing, authenticating, and governing traffic against your policies. Connect Splunk once and govern it everywhere: role-based access per agent with on-behalf-of attribution, real-time visibility, and an immutable audit trail of who did what, all deployable inside your own VPC.

Tools content

  • list_tools · Read-only
    Lists all available MCP tools with their descriptions and parameters.
  • health_check · Read-only
    Returns a list of available Splunk apps to verify connectivity.
  • ping · Read-only
    Simple ping endpoint to verify MCP server is alive.
  • current_user · Read-only
    Returns information about the currently authenticated user.
  • list_users · Read-only
    Returns a list of all users and their roles.
  • list_indexes · Read-only
    Returns a list of all accessible Splunk indexes.
  • get_index_info · Read-only
    Returns detailed information about a specific index.
  • indexes_and_sourcetypes · Read-only
    Returns a comprehensive list of indexes and their sourcetypes.
  • search_splunk · Read-only
    Executes a Splunk search query.
  • list_saved_searches · Read-only
    Returns a list of saved searches in the Splunk instance.
  • list_kvstore_collections · Read-only
    Lists all KV store collections.
  • create_kvstore_collection · Write
    Creates a new KV store collection.
  • delete_kvstore_collection · Write
    Deletes an existing KV store collection.

Frequently asked questions

What is the Splunk MCP server?

Explore Splunk data, discover knowledge objects, and run SPL searches. Through Lunar.dev MCPX, Splunk connects to any MCP-compatible AI client behind a single governed gateway.

How do I connect Splunk to MCPX?

Add the Splunk server in the MCPX control plane or your app.yaml, then point your AI client at your MCPX gateway. MCPX handles Token and routes every Splunk call through the gateway.

Is the Splunk MCP server official?

Yes. Splunk is an official, vendor-published MCP server, and MCPX governs it like any other server in your catalog.

What authentication does Splunk use with MCPX?

Splunk uses Token. MCPX enforces authentication at the gateway with token-based auth, OAuth, and role-based profiles, so you control which agents can invoke it.

How many tools does Splunk expose in MCPX?

Splunk exposes 14 tools. In MCPX you can enable or disable each tool per agent for least-privilege access.

Server details

CategoryObservability & Security
AuthToken
ConnectionSSE
Tools14 available