Does Splunk have an MCP server?

Yes Official

Splunk maintains an official MCP server.

Distributed as an official Splunkbase app; the splunk GitHub org's MCP repo labels itself unofficial, and the leading community repo archived itself in favor of the official app.

Verified 2026-08-10 against vendor docs
Access
Built into the product
Endpoint
Splunkbase app 7931 — in-product
Category
Monitoring
The receipts
In-product Splunkbase app 7931 — in-product

Ships inside Splunk's own product rather than as a standalone server. Documented at help.splunk.com.

Connect it

Ships inside the vendor's own app or CLI rather than as a standalone download.

Add it from the terminal, then restart your session:

terminal
claude mcp add splunk -- npx -y <package-from-readme>

Swap in the exact package and flags from the package page — most servers need an API key passed as an environment variable.

Add --scope user to make it available in every project.

Questions
Does Splunk have an official MCP server?

Yes. Splunk maintains an official MCP server.

How do I connect Splunk to Claude?

Run the server locally and register it in Claude's MCP config. In Claude Code that's a single "claude mcp add" command; in Claude Desktop you add it to claude_desktop_config.json.

How is this verdict verified?

Official MCP Server for Splunk Enterprise and Cloud (v1.1), distributed as Splunkbase app 7931 and documented on help.splunk.com — SPL queries, NL-to-SPL, RBAC. GitHub metadata is refreshed every six hours.

How we know

Official MCP Server for Splunk Enterprise and Cloud (v1.1), distributed as Splunkbase app 7931 and documented on help.splunk.com — SPL queries, NL-to-SPL, RBAC.

  • github data refreshed 2026-08-11, then every 6 hours
  • vendor docs verified on 2026-08-10

Spotted something out of date? Tell us — corrections ship same-day.

Also in Monitoring

See all Monitoring servers →