Tracecat

Databricks MCP server

Run Databricks SQL, Genie spaces, and Unity Catalog functions from your AI agents.

SIEM / datalake
http
Official docs

About

Connect Tracecat to Databricks to read and reason over the data already governed by your lakehouse for SOC analysts and detection engineers running security pipelines on Delta tables. You can query Databricks SQL for historical events from a workflow with no separate credentials to manage. From there, ask a Genie space a natural-language question, run Vector Search over indexed data, and invoke Unity Catalog functions with every call attributed to the connected principal in your Databricks audit logs.

Setup

  1. 1

    Sign in with OAuth

    You'll authorize Tracecat to access Databricks on your behalf. No API keys to manage.

  2. 2

    Select the Databricks tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the Databricks tile, and complete the OAuth flow.

  3. 3

    Enable Databricks in your agent

    In your ai.agent action or Agents tools tab, select Databricks from the MCP integrations dropdown.

Tools

Vector SearchQuery Databricks Vector Search indexes for semantic retrieval over indexed data.
Genie SpacesAsk natural-language questions against a Genie space and get SQL-grounded answers.
Databricks SQLExecute SQL against a Databricks SQL warehouse through the AI Gateway.
Unity Catalog functionsInvoke Unity Catalog functions registered as MCP tools, governed by Unity Catalog grants.

Deploy the Databricks MCP server in minutes

Connect your security agents to 50+ hosted MCP servers.

Self-host free