Skip the install. Get this working in under 2 minutes.
Start a free trial on cloud.anythingmcp.com, add the Splunk in one click, then point your AI client (Claude, ChatGPT, Copilot or Cursor) at the generated MCP endpoint. No Docker, no git clone, zero engineering experience required.
Summary
Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.
Try asking
Example prompts for Splunk
Click any prompt to copy it. Paste into Claude, ChatGPT, Cursor, Gemini, Copilot or OpenClaw to run it against this connector.
Claude is AI and can make mistakes. Please double-check responses.
💡 No install? Use cloud.anythingmcp.com directly. Sign in, click Connectors → Splunk, paste your credentials, mint an MCP API key — done. No Docker, no
git clone, no local server.
Splunk + Cursor
Search Splunk logs and metrics from Claude, ChatGPT or Copilot through Splunk's official MCP Server: run SPL and saved searches, list indexes, hosts and sources, read knowledge objects, and draft SPL with Splunk AI Assistant.
Prerequisites
See the full setup instructions baked into the connector (visible in the in-app store when you select the connector). The required environment variables for this connector are:
SPLUNK_HOST, SPLUNK_MCP_TOKEN
Step 1 — Get credentials
AnythingMCP bridges the Splunk MCP Server, Splunk's official app (Splunkbase 7931). The tools come from your own Splunk; AnythingMCP adds OAuth for Claude and ChatGPT, per-tool roles and the audit log.
- A Splunk admin installs Splunk MCP Server on the search head and enables token authentication.
- Give the role the AI will use the
mcp_tool_executecapability and only the indexes it may read. Pick a role that cannot write to indexes or lookups: Splunk itself markssplunk_run_queryas able to change data. - In the Splunk MCP Server app, generate an encrypted MCP token for that user. A normal Splunk user token is refused with "invalid token audience".
- On Splunk Cloud Platform, allow the address AnythingMCP calls from on port 8089 (search API allow list in the Admin Config Service). On AnythingMCP Cloud, ask support for the egress IP.
- In AnythingMCP, install Splunk from the catalog with
SPLUNK_HOST(for exampleyourstack.splunkcloud.com, withouthttps://) andSPLUNK_MCP_TOKEN. The install lists the tools your server offers; the two dashboard tools start switched off.
Step 2 — Install the adapter
curl -fsSL https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml -o docker-compose.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -d
Step 3 — Add the connector in Cursor
Your server URL: in AnythingMCP, open MCP Servers → the server this connector is on, and copy its URL (
https://cloud.anythingmcp.com/mcp/…). Use it wherever this guide showsYOUR_SERVER_ID.
Cursor reads MCP servers from ~/.cursor/mcp.json. Add this entry:
{
"mcpServers": {
"anythingmcp": {
"url": "https://cloud.anythingmcp.com/mcp/YOUR_SERVER_ID",
"headers": { "X-API-Key": "YOUR_MCP_API_KEY" }
}
}
}
- Get your MCP API key from AnythingMCP → MCP Servers → your server → API keys.
- Save the file and restart Cursor.
- Open Cursor → Settings → MCP to verify
Splunkis listed and "Connected". - Start chatting — all
Splunktools are now invokable.
Available tools
| Tool | What it does |
|---|---|
saia_ask_splunk_question | Ask natural language questions about Splunk using Splunk AI Assistant |
saia_explain_spl | Explain SPL queries in natural language using Splunk AI Assistant |
saia_generate_spl | Generate SPL from natural language queries using Splunk AI Assistant |
saia_optimize_spl | Optimize SPL (Search Processing Language) queries using Splunk AI Assistant |
splunk_create_dashboard | Creates a new Splunk dashboard using Dashboard Studio JSON in the specified app namespace |
splunk_get_index_info | Get detailed information about a specific Splunk index |
splunk_get_indexes | Get a list of indexes from Splunk |
splunk_get_info | Get comprehensive information about the Splunk instance |
splunk_get_knowledge_objects | Retrieve Splunk knowledge objects by type |
splunk_get_kv_store_collections | Get KV Store collection statistics including size, count, and storage information |
splunk_get_metadata | Retrieve metadata about hosts or sources across one or more indexes in the selected time window |
splunk_get_user_info | Retrieves detailed information about the currently authenticated user including roles and permissions |
splunk_get_user_list | Get a list of users from Splunk |
splunk_run_query | Execute a Splunk search query and return the results |
splunk_run_saved_search | Execute a Splunk saved search by name and return its results |
splunk_update_dashboard | Updates an existing Splunk dashboard's definition using Dashboard Studio JSON |
FAQ
Does Cursor support custom MCP servers on the free tier? Yes — MCP is available on Hobby, Pro and Business plans.
Next steps
Was this guide helpful?