Does Splunk have an MCP server?
Splunk maintains an official MCP server.
Distributed as an official Splunkbase app; the splunk GitHub org's MCP repo labels itself unofficial, and the leading community repo archived itself in favor of the official app.
- Access
- Built into the product
- Endpoint
- Splunkbase app 7931 — in-product
- Category
- Monitoring
Ships inside Splunk's own product rather than as a standalone server. Documented at help.splunk.com.
Ships inside the vendor's own app or CLI rather than as a standalone download.
Add it from the terminal, then restart your session:
claude mcp add splunk -- npx -y <package-from-readme>Swap in the exact package and flags from the package page — most servers need an API key passed as an environment variable.
Add --scope user to make it available in every project.
Open Settings → Developer → Edit Config and add the server to claude_desktop_config.json:
{
"mcpServers": {
"splunk": {
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
],
"env": {
"API_KEY": "…"
}
}
}
}Restart Claude Desktop after saving.
Add to .cursor/mcp.json in your project, or ~/.cursor/mcp.json for
every project:
{
"mcpServers": {
"splunk": {
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
],
"env": {
"API_KEY": "…"
}
}
}
}A green dot in Settings → MCP means it connected.
Add to .vscode/mcp.json:
{
"servers": {
"splunk": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"<package-from-readme>"
]
}
}
}Then pick the server from the tools menu in Copilot's agent mode.
Does Splunk have an official MCP server?
Yes. Splunk maintains an official MCP server.
How do I connect Splunk to Claude?
Run the server locally and register it in Claude's MCP config. In Claude Code that's a single "claude mcp add" command; in Claude Desktop you add it to claude_desktop_config.json.
How is this verdict verified?
Official MCP Server for Splunk Enterprise and Cloud (v1.1), distributed as Splunkbase app 7931 and documented on help.splunk.com — SPL queries, NL-to-SPL, RBAC. GitHub metadata is refreshed every six hours.
Official MCP Server for Splunk Enterprise and Cloud (v1.1), distributed as Splunkbase app 7931 and documented on help.splunk.com — SPL queries, NL-to-SPL, RBAC.
- github data refreshed 2026-08-11, then every 6 hours
- vendor docs verified on 2026-08-10
Spotted something out of date? Tell us — corrections ship same-day.