Splunk
Explore Splunk data, discover knowledge objects, and run SPL searches.
Splunk
Explore Splunk data, discover knowledge objects, and run SPL searches. With Lunar.dev MCPX, the MCP Gateway for secure and governed tool access, you connect the Splunk MCP server to Claude, ChatGPT, Cursor, and any MCP client through one gateway that routes, authenticates, and governs every Splunk tool call against your policies.
Why MCPX
MCPX is Lunar.dev's MCP Gateway. It sits between your AI agents and your MCP servers as a single gateway for every tool call, routing, authenticating, and governing traffic against your policies. Connect Splunk once and govern it everywhere: role-based access per agent with on-behalf-of attribution, real-time visibility, and an immutable audit trail of who did what, all deployable inside your own VPC.
Tools content
- list_tools · Read-only
Lists all available MCP tools with their descriptions and parameters. - health_check · Read-only
Returns a list of available Splunk apps to verify connectivity. - ping · Read-only
Simple ping endpoint to verify MCP server is alive. - current_user · Read-only
Returns information about the currently authenticated user. - list_users · Read-only
Returns a list of all users and their roles. - list_indexes · Read-only
Returns a list of all accessible Splunk indexes. - get_index_info · Read-only
Returns detailed information about a specific index. - indexes_and_sourcetypes · Read-only
Returns a comprehensive list of indexes and their sourcetypes. - search_splunk · Read-only
Executes a Splunk search query. - list_saved_searches · Read-only
Returns a list of saved searches in the Splunk instance. - list_kvstore_collections · Read-only
Lists all KV store collections. - create_kvstore_collection · Write
Creates a new KV store collection. - delete_kvstore_collection · Write
Deletes an existing KV store collection.
Frequently asked questions
What is the Splunk MCP server?
Explore Splunk data, discover knowledge objects, and run SPL searches. Through Lunar.dev MCPX, Splunk connects to any MCP-compatible AI client behind a single governed gateway.
How do I connect Splunk to MCPX?
Add the Splunk server in the MCPX control plane or your app.yaml, then point your AI client at your MCPX gateway. MCPX handles Token and routes every Splunk call through the gateway.
Is the Splunk MCP server official?
Yes. Splunk is an official, vendor-published MCP server, and MCPX governs it like any other server in your catalog.
What authentication does Splunk use with MCPX?
Splunk uses Token. MCPX enforces authentication at the gateway with token-based auth, OAuth, and role-based profiles, so you control which agents can invoke it.
How many tools does Splunk expose in MCPX?
Splunk exposes 14 tools. In MCPX you can enable or disable each tool per agent for least-privilege access.
