Set up the Splunk MCP Server
Follow these steps to set up the Splunk MCP Server for your deployment.
Prerequisites
You must allow for API access and token authentication:
-
Splunk Cloud Platform: Allow REST API access for your Splunk platform deployment. For more information, see the Accessing the Splunk Cloud Platform REST API.
-
All deployments: Allow token authentication for all Splunk platform instance deployments. For more information, see Enable token authentication for a Splunk platform instance.
Set up steps
Complete the following steps to download, install, and configure the Splunk MCP Server app.
Step 1: Download and install the Splunk MCP Server app from Splunkbase
The Splunk MCP Server app is available on Splunkbase. The Splunk MCP Server app can be installed on your Splunk Search Head (SH) or Search Head Cluster (SHC).
For Splunk Cloud Platform installation steps, see Install an add-on in Splunk Cloud Platform. For Splunk Enterprise, follow installation procedures from Installing Splunk add-ons.
Step 2: Establish role-based access
The MCP Server app adds 2 new capabilities for role-based access control:
| Capability | Description |
|---|---|
mcp_tool_execute |
Grants users access to use the MCP server tools. |
mcp_tool_admin |
Grants administrative access for tool management and token creation. |
Add the mcp_tool_execute capability to any new or existing roles that need access to MCP server functionality. Access the APIs is also required.
(Optional) Map roles to MCP tools
Splunk MCP Server version 1.3 or higher includes the option for administrators to map specific Splunk roles to MCP Server tools. Your MCP users can then only view or execute a tool when they have a role mapped to that tool.
These mappings are managed from the MCP Server app and the Tools tab. The following image shows an example MCP instance:
The Tools tab is selected and the tool of splunk_get_indexes has been expanded to view its details. Admins can select Edit option for Roles allowed and make changes as needed.
Step 3: (Optional) Install Splunk AI Assistant
To make AI tools such as generate_spl, explain_spl, optimize_spl, and ask_splunk_question available in the MCP server, Splunk AI Assistant must be installed. To learn more see About Splunk AI Assistant.