跳过安装。2 分钟内即可运行。
在 cloud.anythingmcp.com 开始免费试用,一键添加 Splunk,然后将你的 AI 客户端(Claude、ChatGPT、Copilot 或 Cursor)指向生成的 MCP 端点。无需 Docker,无需 git clone,无需任何工程经验。
摘要
通过 Splunk 官方 MCP Server,在 Claude、ChatGPT 或 Copilot 中搜索 Splunk 的日志和指标:运行 SPL 和已保存的搜索,列出索引、主机和来源,读取知识对象,并用 Splunk AI Assistant 编写 SPL。
试试这样问
Splunk 的示例提示
点击任意提示即可复制,然后粘贴到 Claude、ChatGPT、Cursor、Gemini、Copilot 或 OpenClaw 中,在该连接器上运行。
Claude 是 AI,可能会出错。请核对回答。
💡 无需安装? 直接使用 cloud.anythingmcp.com。 登录、点击 Connectors → Splunk、粘贴凭证、生成 MCP API key — 完成。无 Docker、无
git clone、无本地服务器。
Splunk + ChatGPT
通过 Splunk 官方 MCP Server,在 Claude、ChatGPT 或 Copilot 中搜索 Splunk 的日志和指标:运行 SPL 和已保存的搜索,列出索引、主机和来源,读取知识对象,并用 Splunk AI Assistant 编写 SPL。
前提条件
完整的设置说明已内置在连接器中 (在 store 中选择连接器时可见)。所需环境变量:
SPLUNK_HOST, SPLUNK_MCP_TOKEN
步骤 1 — 获取凭证
AnythingMCP 接入 Splunk 官方应用 Splunk MCP Server(Splunkbase 7931)。工具来自您自己的 Splunk,AnythingMCP 在此之上为 Claude 和 ChatGPT 提供 OAuth、按工具划分的角色权限和审计日志。
- 由 Splunk 管理员在搜索头上安装 Splunk MCP Server,并启用令牌认证。
- 为 AI 使用的角色授予
mcp_tool_execute能力,并只开放允许读取的索引。请选择无法写入索引和查找表的角色:Splunk 自身将splunk_run_query标记为可能修改数据。 - 在 Splunk MCP Server 应用中为该用户生成加密的 MCP 令牌。普通的 Splunk 用户令牌会因 "invalid token audience" 被拒绝。
- 在 Splunk Cloud Platform 上,需在 8089 端口放行 AnythingMCP 的调用地址(Admin Config Service 中 search API 的 IP 允许列表)。使用 AnythingMCP Cloud 时,请向支持团队获取出口 IP。
- 在 AnythingMCP 中从目录安装 Splunk,填写
SPLUNK_HOST(例如yourstack.splunkcloud.com,不带https://)和SPLUNK_MCP_TOKEN。安装时会导入您的服务器提供的工具,两个仪表板工具默认处于关闭状态。
步骤 2 — 安装 adapter
curl -fsSL https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml -o docker-compose.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -d
步骤 3 — 在 ChatGPT 中添加连接器
你的服务器 URL: 在 AnythingMCP 中打开 MCP Servers → 此连接器所在的服务器,复制它的 URL(
https://cloud.anythingmcp.com/mcp/…)。本指南中出现YOUR_SERVER_ID的地方都用它替换。
ChatGPT 通过开发者模式(Developer mode)将 MCP 服务器作为自定义应用接入,仅付费套餐可用,免费套餐不可用。在 Business 和 Enterprise 工作区中,可能需要管理员先开启。
- 在 ChatGPT 中打开 Settings → Security and login,开启 Developer mode。
- 前往 chatgpt.com/plugins,点击 +。
- 填写名称和简短描述,例如 Name:
Splunk。 - 在 Connection 下填入 MCP 服务器 URL
https://cloud.anythingmcp.com/mcp/YOUR_SERVER_ID,然后创建连接。 - ChatGPT 提示时,登录 AnythingMCP(OAuth)并允许访问。
可用工具
| Tool | What it does |
|---|---|
saia_ask_splunk_question | Ask natural language questions about Splunk using Splunk AI Assistant |
saia_explain_spl | Explain SPL queries in natural language using Splunk AI Assistant |
saia_generate_spl | Generate SPL from natural language queries using Splunk AI Assistant |
saia_optimize_spl | Optimize SPL (Search Processing Language) queries using Splunk AI Assistant |
splunk_create_dashboard | Creates a new Splunk dashboard using Dashboard Studio JSON in the specified app namespace |
splunk_get_index_info | Get detailed information about a specific Splunk index |
splunk_get_indexes | Get a list of indexes from Splunk |
splunk_get_info | Get comprehensive information about the Splunk instance |
splunk_get_knowledge_objects | Retrieve Splunk knowledge objects by type |
splunk_get_kv_store_collections | Get KV Store collection statistics including size, count, and storage information |
splunk_get_metadata | Retrieve metadata about hosts or sources across one or more indexes in the selected time window |
splunk_get_user_info | Retrieves detailed information about the currently authenticated user including roles and permissions |
splunk_get_user_list | Get a list of users from Splunk |
splunk_run_query | Execute a Splunk search query and return the results |
splunk_run_saved_search | Execute a Splunk saved search by name and return its results |
splunk_update_dashboard | Updates an existing Splunk dashboard's definition using Dashboard Studio JSON |
FAQ
ChatGPT 免费套餐能用自定义 MCP 连接器吗? 不能。自定义 MCP 连接需要开发者模式,只有付费套餐提供。
下一步
这份指南对你有帮助吗?