Splunk IntegrationSAFE
[ARCHIVED] Community Splunk MCP server — use the official Splunk MCP Server on Splunkbase (app 7931)
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
# ⚠️ This project is archived — use the official Splunk MCP Server Thank you to everyone who used, starred, and forked this project! 🙏 It started as a community effort to bring Model Context Protocol (MCP) support to Splunk, well before an official option existed. Splunk now ships a first-party, fully supported MCP server that has grown beyond what this community project provides. Please migrate to the official server: - 📦 Splunk MCP Server on Splunkbase (App 7931, by Splunk LLC): https://splunkbase.splunk.com/app/7931 - 📖 Docs — MCP Server for Splunk Platform: https://help.splunk.com/en/splunk-cloud-platform/mcp-server-for-splunk-platform/ This repository is now read-only / archived and will no longer receive updates. The code below is preserved for historical reference. Thanks again! 🚀
A FastMCP-based tool for interacting with Splunk Enterprise/Cloud through natural language. This tool provides a set of capabilities for searching Splunk data, managing KV stores, and accessing Splunk resources through an intuitive interface.
Operating Modes
The tool operates in three modes:
- SSE Mode (Default)
- Server-Sent Events based communication
- Real-time bidirectional interaction
- Suitable for web-based MCP clients
- Default mode when no arguments provided
- Access via
/sseendpoint
- API Mode
- RESTful API endpoints
- Access via
/api/v1endpoint prefix - Start with
python splunk_mcp.py api
- STDIO Mode
- Standard input/output based communication
- Compatible with Claude Desktop and other MCP clients
- Ideal for direct integration with AI assistants
- Start with
python splunk_mcp.py stdio
Features
- Splunk Search: Execute Splunk searches with natural language queries
- Index Management: List and inspect Splunk indexes
- User Management: View and manage Splunk users
- KV Store Operations: C
7e03d8d5faebOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add splunk-mcp --env SPLUNK_PASSWORD=${SPLUNK_PASSWORD} --env SPLUNK_TOKEN=${SPLUNK_TOKEN} -- uvx splunk-mcp{
"mcpServers": {
"splunk-mcp": {
"command": "uvx",
"args": [
"splunk-mcp"
],
"env": {
"SPLUNK_PASSWORD": "${SPLUNK_PASSWORD}",
"SPLUNK_TOKEN": "${SPLUNK_TOKEN}"
}
}
}
}Exposed tools (12)
12 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
current_user | read | |
get_index_info | read | |
get_indexes_and_sourcetypes | read | |
health | read | Get basic Splunk connection information and list available apps (same as health_check but for endpoint consistency) |
health_check | read | Get basic Splunk connection information and list available apps |
list_indexes | read | |
list_kvstore_collections | read | |
list_saved_searches | read | |
list_tools | read | |
list_users | read | List all Splunk users (requires admin privileges) |
ping | read | |
search_splunk | read |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- UNDECLARED (1 observation(s))
- Network
- declared (2 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
&& rm -rf /var/lib/apt/lists/* \
Gates applied: no_behavioural_pass.
7e03d8d5faebfull audit observations/trust-audit/mcp-server/livehybrid__splunk-integration.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 7e03d8d5faeb | SAFE | B | 89 | first audit |
Questions
What is the Splunk Integration MCP server?
[ARCHIVED] Community Splunk MCP server — use the official Splunk MCP Server on Splunkbase (app 7931)
What tools does Splunk Integration expose?
12 in total: 12 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Splunk Integration safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does Splunk Integration need?
It reads SPLUNK_PASSWORD and SPLUNK_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (7e03d8d5faeb), read on 2026-10-07. The repository is watched and re-audited when it changes.