Skip to main content
Feedback

Splunk MCP connector

Updated 

Splunk is a data platform for searching, monitoring, and analyzing machine-generated data across an organization's systems and infrastructure. The Splunk MCP connector allows AI agents to create and manage search jobs, retrieve search results, and track job status directly from a Splunk instance. It also supports creating, updating, and deleting saved searches, giving agents ongoing visibility into recurring queries and their outcomes.

Authentication type

  • API Key - Requires a static API key to be configured before the agent can connect to the service.

Uses

Use the Splunk MCP connector to perform the following actions:

  • Search machine-generated data across the organization in real time
  • Monitor security incidents by tracking fired alerts as they occur
  • Automate recurring searches with saved search jobs and schedules
  • Investigate operational issues by running and reviewing search job results
  • Manage Splunk user accounts and access permissions from one workflow
  • Track search job status and cancel long-running or stalled jobs
  • Retrieve historical alert data to support compliance and audits
  • Standardize saved search management across teams and dashboards

Example prompts

Use the following example prompts to invoke Splunk MCP connector tools from your AI assistant or Boomi Connect workflow:

  • Show me all failed login attempts from Splunk in the last 24 hours.
  • Create a new search job in Splunk for server errors this week.
  • List all the saved searches we have set up in Splunk.
  • Get the status of my current Splunk search job.
  • Show me all alerts that fired in Splunk yesterday.
  • Add a new user account to Splunk for our new analyst.
  • Run the saved search for suspicious network activity in Splunk.
  • Cancel the search job that's been running too long in Splunk.
  • Update the saved search for daily error reports in Splunk.
  • List all users who currently have access to Splunk.

Splunk MCP connector tools

The Splunk MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.

ToolDescription
createSearchJobCreate a search job
listSearchJobsList search jobs
getSearchJobGet search job status
deleteSearchJobCancel search job
getSearchResultsGet search results
listSavedSearchesList saved searches
createSavedSearchCreate a saved search
getSavedSearchGet saved search
updateSavedSearchUpdate saved search
deleteSavedSearchDelete saved search
executeSavedSearchExecute saved search
listUsersList users
createUserCreate user
getUserGet user
updateUserUpdate user
deleteUserDelete user
getAlertsGet fired alerts
On this Page