Atlas / MCP servers / livehybrid / Splunk Integration

Splunk IntegrationSAFE

mcp/livehybrid/splunk-integration

[ARCHIVED] Community Splunk MCP server — use the official Splunk MCP Server on Splunkbase (app 7931)

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
12 12r · 0w · 0d
Transport
—
License
Apache-2.0
Stars
106
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

# ⚠️ This project is archived — use the official Splunk MCP Server Thank you to everyone who used, starred, and forked this project! 🙏 It started as a community effort to bring Model Context Protocol (MCP) support to Splunk, well before an official option existed. Splunk now ships a first-party, fully supported MCP server that has grown beyond what this community project provides. Please migrate to the official server: - 📦 Splunk MCP Server on Splunkbase (App 7931, by Splunk LLC): https://splunkbase.splunk.com/app/7931 - 📖 Docs — MCP Server for Splunk Platform: https://help.splunk.com/en/splunk-cloud-platform/mcp-server-for-splunk-platform/ This repository is now read-only / archived and will no longer receive updates. The code below is preserved for historical reference. Thanks again! 🚀

A FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resources through an intuitive interface.

Operating Modes

The tool operates in three modes:

  1. SSE Mode (Default)
  2. Server-Sent Events based communication
  3. Real-time bidirectional interaction
  4. Suitable for web-based MCP clients
  5. Default mode when no arguments provided
  6. Access via /sse endpoint
  1. API Mode
  2. RESTful API endpoints
  3. Access via /api/v1 endpoint prefix
  4. Start with python splunk_mcp.py api
  1. STDIO Mode
  2. Standard input/output based communication
  3. Compatible with Claude Desktop and other MCP clients
  4. Ideal for direct integration with AI assistants
  5. Start with python splunk_mcp.py stdio

Features

  • Splunk Search: Execute Splunk searches with natural language queries
  • Index Management: List and inspect Splunk indexes
  • User Management: View and manage Splunk users
  • KV Store Operations: C
Read from source at commit 7e03d8d5faebOBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add splunk-mcp --env SPLUNK_PASSWORD=${SPLUNK_PASSWORD} --env SPLUNK_TOKEN=${SPLUNK_TOKEN} -- uvx splunk-mcp
claude-desktop
{
  "mcpServers": {
    "splunk-mcp": {
      "command": "uvx",
      "args": [
        "splunk-mcp"
      ],
      "env": {
        "SPLUNK_PASSWORD": "${SPLUNK_PASSWORD}",
        "SPLUNK_TOKEN": "${SPLUNK_TOKEN}"
      }
    }
  }
}
03

Exposed tools (12)

12 read · 0 write · 0 destructive.

ToolRiskDescription
current_userread
get_index_inforead
get_indexes_and_sourcetypesread
healthreadGet basic Splunk connection information and list available apps (same as health_check but for endpoint consistency)
health_checkreadGet basic Splunk connection information and list available apps
list_indexesread
list_kvstore_collectionsread
list_saved_searchesread
list_toolsread
list_usersreadList all Splunk users (requires admin privileges)
pingread
search_splunkread
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
UNDECLARED (1 observation(s))
Network
declared (2 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

MEDIUMFilesystem / path · fs.destructive · CWE-22, CWE-59
Dockerfile:13
&& rm -rf /var/lib/apt/lists/* \

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 7e03d8d5faebfull audit observations/trust-audit/mcp-server/livehybrid__splunk-integration.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-077e03d8d5faebSAFEB89first audit
06

Questions

What is the Splunk Integration MCP server?

[ARCHIVED] Community Splunk MCP server — use the official Splunk MCP Server on Splunkbase (app 7931)

What tools does Splunk Integration expose?

12 in total: 12 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Splunk Integration safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.

What credentials does Splunk Integration need?

It reads SPLUNK_PASSWORD and SPLUNK_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How current is this page?

The grade is for one exact copy of the source (7e03d8d5faeb), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement