Connector guide3-minute read16 MCP tools7 languages

How to Connect Splunk to Cursor — via MCP

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

HCBy HelpCode teamUpdated 3 min read Open-source on GitHub

No credit card · 7-day trial · Self-host alternative available

Splunk

Splunk

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

tools

16

Region

INTL

Category

Monitoring

Authentication

Bearer Token

Required env vars

SPLUNK_HOSTSPLUNK_MCP_TOKEN
Install in one click on Cloud

7-day free trial · No credit card

  • 7-day free trial
    No credit card required
  • GDPR & SOC 2 ready
    EU data residency, audit logs
  • Open-source on GitHub
    Open source · AGPL-3.0
  • Works with ChatGPT, Claude, Gemini
    Any MCP-compatible client

Skip the install. Get this working in under 2 minutes.

Start a free trial on cloud.anythingmcp.com, add the Splunk in one click, then point your AI client (Claude, ChatGPT, Copilot or Cursor) at the generated MCP endpoint. No Docker, no git clone, zero engineering experience required.

Start free trial

Summary

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

Try asking

Example prompts for Splunk

Click any prompt to copy it. Paste into Claude, ChatGPT, Cursor, Gemini, Copilot or OpenClaw to run it against this connector.

Splunk · live via MCP
Share
Opus 4.7

Claude is AI and can make mistakes. Please double-check responses.

💡 No install? Use cloud.anythingmcp.com directly. Sign in, click Connectors → Splunk, paste your credentials, mint an MCP API key — done. No Docker, no git clone, no local server.

Splunk + Cursor

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

Prerequisites

See the full setup instructions baked into the connector (visible in the in-app store when you select the connector). The required environment variables for this connector are:

SPLUNK_HOST, SPLUNK_MCP_TOKEN

Step 1 — Get credentials

AnythingMCP bridges the Splunk MCP Server, Splunk's official app (Splunkbase 7931). The tools come from your own Splunk; AnythingMCP adds OAuth for Claude and ChatGPT, per-tool roles and the audit log.

  1. A Splunk admin installs Splunk MCP Server on the search head and enables token authentication.
  2. Give the role the AI will use the mcp_tool_execute capability and only the indexes it may read. Pick a role that cannot write to indexes or lookups: Splunk itself marks splunk_run_query as able to change data.
  3. In the Splunk MCP Server app, generate an encrypted MCP token for that user. A normal Splunk user token is refused with "invalid token audience".
  4. On Splunk Cloud Platform, allow the address AnythingMCP calls from on port 8089 (search API allow list in the Admin Config Service). On AnythingMCP Cloud, ask support for the egress IP.
  5. In AnythingMCP, install Splunk from the catalog with SPLUNK_HOST (for example yourstack.splunkcloud.com, without https://) and SPLUNK_MCP_TOKEN. The install lists the tools your server offers; the two dashboard tools start switched off.

Step 2 — Install the adapter

curl -fsSL https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml -o docker-compose.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -d

Step 3 — Add the connector in Cursor

Your server URL: in AnythingMCP, open MCP Servers → the server this connector is on, and copy its URL (https://cloud.anythingmcp.com/mcp/…). Use it wherever this guide shows YOUR_SERVER_ID.

Cursor reads MCP servers from ~/.cursor/mcp.json. Add this entry:

{
  "mcpServers": {
    "anythingmcp": {
      "url": "https://cloud.anythingmcp.com/mcp/YOUR_SERVER_ID",
      "headers": { "X-API-Key": "YOUR_MCP_API_KEY" }
    }
  }
}
  1. Get your MCP API key from AnythingMCP → MCP Servers → your server → API keys.
  2. Save the file and restart Cursor.
  3. Open Cursor → Settings → MCP to verify Splunk is listed and "Connected".
  4. Start chatting — all Splunk tools are now invokable.

Available tools

ToolWhat it does
saia_ask_splunk_questionAsk natural language questions about Splunk using Splunk AI Assistant
saia_explain_splExplain SPL queries in natural language using Splunk AI Assistant
saia_generate_splGenerate SPL from natural language queries using Splunk AI Assistant
saia_optimize_splOptimize SPL (Search Processing Language) queries using Splunk AI Assistant
splunk_create_dashboardCreates a new Splunk dashboard using Dashboard Studio JSON in the specified app namespace
splunk_get_index_infoGet detailed information about a specific Splunk index
splunk_get_indexesGet a list of indexes from Splunk
splunk_get_infoGet comprehensive information about the Splunk instance
splunk_get_knowledge_objectsRetrieve Splunk knowledge objects by type
splunk_get_kv_store_collectionsGet KV Store collection statistics including size, count, and storage information
splunk_get_metadataRetrieve metadata about hosts or sources across one or more indexes in the selected time window
splunk_get_user_infoRetrieves detailed information about the currently authenticated user including roles and permissions
splunk_get_user_listGet a list of users from Splunk
splunk_run_queryExecute a Splunk search query and return the results
splunk_run_saved_searchExecute a Splunk saved search by name and return its results
splunk_update_dashboardUpdates an existing Splunk dashboard's definition using Dashboard Studio JSON

FAQ

Does Cursor support custom MCP servers on the free tier? Yes — MCP is available on Hobby, Pro and Business plans.

Next steps

Was this guide helpful?

Your Splunk agent is one click away.

Install the connector, paste the key, prompt Cursor. Free for 7 days, no credit card.

Related guides

Connectors

How to Connect Splunk to ChatGPT — via MCP

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

Connectors

How to Connect Splunk to Claude — via MCP

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

Connectors

How to Connect Splunk to Gemini — via MCP

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

Connectors

Splunk to MCP — Drive Splunk from any AI Agent

Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.

OJ
Connectors

How to Connect Odoo 14-18 (JSON-RPC) to Cursor — via MCP

Odoo ERP 14 to 18 over the classic JSON-RPC endpoint: search, read, create and update any model, plus partners, sales orders, invoices and products. For Odoo Online, Odoo.sh and self-hosted Odoo older than 19 (works on 19 too). API key + user id.

Connectors

How to Connect Firma.dev to Cursor — via MCP

Firma.dev e-signature from any AI agent: templates, signing requests from a template, sending and reminders, recipient status, audit trail and signed PDFs. 13 tools, API-key auth, with free test keys.