Tracecat

Splunk MCP server

Search indexes and triage notable events on Splunk Cloud or Splunk Enterprise.

SIEM / datalake
stdio
Official docs

About

Connect Tracecat to Splunk to drive SPL searches and notable event triage from agents working alongside SOC analysts and detection engineers. You can run one-shot or long-running SPL jobs against any indexed sourcetype so agents pivot through related events without an analyst writing the query by hand. From there, agents can walk through notable events in Enterprise Security, pull saved searches and accelerated data models, and pass enriched context to the rest of your security stack with the connected user's role permissions enforced throughout.

Setup

  1. 1

    Create a bearer token

    The Splunk MCP server authenticates with a JSON Web Token (JWT) and your Splunk REST endpoint URL. The base URL is configurable so the same setup works for Splunk Cloud Platform and on-prem Splunk Enterprise. The token inherits the role permissions of the user that created it.

  2. 2

    Select the Splunk tile in the Tracecat MCP catalog

    Open the MCP catalog in your workspace, select the Splunk tile, and paste your bearer token.

  3. 3

    Enable Splunk in your agent

    In your ai.agent action or Agents tools tab, select Splunk from the MCP integrations dropdown.

Tools

run_oneshot_searchRun a one-shot SPL search against any indexed sourcetype and return the events.
run_search_jobSubmit a long-running SPL search job and poll for completion.
get_search_resultsFetch the results of a previously-submitted search job by SID.
list_indexesList indexes available to the authenticated user, with retention and bucket stats.
list_sourcetypesList sourcetypes seen in a given index and time window.
get_notable_eventsRetrieve notable events from Splunk Enterprise Security for triage.
list_saved_searchesList saved searches and reports the user has access to.
list_data_modelsEnumerate accelerated data models for use in tstats queries.

Deploy the Splunk MCP server in minutes

Connect your security agents to 50+ hosted MCP servers.

Self-host free