Use the Splunk MCP Server app to access tools in Splunk Enterprise Security
Use the Splunk MCP Server app to add a curated set of Enterprise Security read-only tools for retrieving investigation context, findings, response plans, risk scores, queue context, and AI analysis. When the Splunk MCP Server app is installed on an Enterprise Security search head, Splunk Enterprise Security automatically registers these tools with the local MCP Server app. MCP clients can then use the registered tools to interact with Splunk Enterprise Security through supported REST APIs.
For more information on setting up the Splunk MCP Server, see Set up the Splunk MCP Server. For more information on the tools provided by the Splunk MCP Server to interact with Splunk software, see MCP Server tools.
- Investigations: List investigations, related investigations, and findings in an investigation.
-
Evidence and context: List artifacts, notes, activity history, and persisted AI analysis.
-
Findings: List findings or a single finding.
-
Response plans: List response plans, Splunk-owned response plans, and task notes.
-
Operations context: List entity risk scores and team-based queues.
Access MCP server tools for Splunk Enterprise Security
Prerequisite:
-
Verify that you have installed Splunk Enterprise Security version 8.7 or higher.
-
Verify that you have installed Splunk MCP Server app version 1.3.x or higher.
-
Verify that you have the required permissions for Splunk Enterprise Security. for more information on user roles and capabilities in Splunk Enterprise Security, see Configure user roles and capabilities in Splunk Enterprise Security.
-
In Splunk Web, select Apps.
-
In Search app by name, search for Splunk MCP Server app.
-
Create an MCP encrypted token to connect the MCP server to your ES client. For more information on creating the encrypted token, see Connecting to the MCP Server and settings.
-
In the MCP Server app, go to Tools and go to Enterprise Security tools.
-
Verify that all the ES-specific tools are registered in Splunk MCP Server and are visible when turned on. For example,
es_get_ai_analysis,es_get_finding,es_get_related_investigations, and so on.Note: Tools are namespaced based on their source software. For example, ES tools in the MCP server are displayed with the prefix ofes_. For more information on namespacing, see Tool namespacing.Note: Thees_get_ai_analysistool is not available if you are on an on-premises Splunk Platform deployment. - (optional) Customize the rate limit or select the roles that can run the tool. For more information on rate limits, see How rate limiting works?
- (optional) Turn on or turn off any of the tools based on your specific requirements.
- Use an AI coding agent to review the descriptive information provided on these tools and identify the specific tool appropriate for your use case and run the tool.