Before you begin
Verify the following prerequisites before registering and using ITSI MCP tools.
Splunk and ITSI prerequisites
- Splunk Cloud Platform 10.4 or later.
- Splunk IT Service Intelligence 5.0.1 or later installed and configured.
- ITSI episode data available for validation. For more information about how episodes are used during investigation, see Investigate episodes in ITSI.
- User role with access to ITSI episodes and related episode detail APIs.
- User role with the
mcp_tool_executecapability. Theitoa_adminrole includes this capability by default; non-admin users require explicit assignment. - Event iQ Diagnose configured if users need stored AI-generated episode summaries. The integration also works when summarization is not enabled, but summary-specific output is unavailable. For setup details, see Use Event iQ Diagnose to analyze episodes with AI.
MCP Server prerequisites
- Splunk MCP Server 1.3.0 or later installed and available in the Splunk environment.
- ITSI MCP tools registered and enabled in Splunk MCP Server.
- Network and environment access that allows the configured MCP-compatible client to reach the MCP Server endpoint.
For MCP Server setup and platform behavior, see About MCP Server for Splunk platform, Connecting to the MCP Server and settings, and MCP Server release notes.