跳过安装。2 分钟内即可运行。
在 cloud.anythingmcp.com 开始免费试用,一键添加 Splunk,然后将你的 AI 客户端(Claude、ChatGPT、Copilot 或 Cursor)指向生成的 MCP 端点。无需 Docker,无需 git clone,无需任何工程经验。
摘要
通过 Splunk 官方 MCP Server,在 Claude、ChatGPT 或 Copilot 中搜索 Splunk 的日志和指标:运行 SPL 和已保存的搜索,列出索引、主机和来源,读取知识对象,并用 Splunk AI Assistant 编写 SPL。
试试这样问
Splunk 的示例提示
点击任意提示即可复制,然后粘贴到 Claude、ChatGPT、Cursor、Gemini、Copilot 或 OpenClaw 中,在该连接器上运行。
Claude 是 AI,可能会出错。请核对回答。
💡 无需安装? 直接使用 cloud.anythingmcp.com。 登录、点击 Connectors → Splunk、粘贴凭证、生成 MCP API key — 完成。无 Docker、无
git clone、无本地服务器。
Splunk
通过 Splunk 官方 MCP Server,在 Claude、ChatGPT 或 Copilot 中搜索 Splunk 的日志和指标:运行 SPL 和已保存的搜索,列出索引、主机和来源,读取知识对象,并用 Splunk AI Assistant 编写 SPL。
设置
AnythingMCP 接入 Splunk 官方应用 Splunk MCP Server(Splunkbase 7931)。工具来自您自己的 Splunk,AnythingMCP 在此之上为 Claude 和 ChatGPT 提供 OAuth、按工具划分的角色权限和审计日志。
- 由 Splunk 管理员在搜索头上安装 Splunk MCP Server,并启用令牌认证。
- 为 AI 使用的角色授予
mcp_tool_execute能力,并只开放允许读取的索引。请选择无法写入索引和查找表的角色:Splunk 自身将splunk_run_query标记为可能修改数据。 - 在 Splunk MCP Server 应用中为该用户生成加密的 MCP 令牌。普通的 Splunk 用户令牌会因 "invalid token audience" 被拒绝。
- 在 Splunk Cloud Platform 上,需在 8089 端口放行 AnythingMCP 的调用地址(Admin Config Service 中 search API 的 IP 允许列表)。使用 AnythingMCP Cloud 时,请向支持团队获取出口 IP。
- 在 AnythingMCP 中从目录安装 Splunk,填写
SPLUNK_HOST(例如yourstack.splunkcloud.com,不带https://)和SPLUNK_MCP_TOKEN。安装时会导入您的服务器提供的工具,两个仪表板工具默认处于关闭状态。
前提条件: SPLUNK_HOST, SPLUNK_MCP_TOKEN
本地安装连接器
curl -fsSL https://raw.githubusercontent.com/HelpCode-ai/anythingmcp/main/docker-compose.quickstart.yml -o docker-compose.yml
printf 'JWT_SECRET=%s\nENCRYPTION_KEY=%s\n' "$(openssl rand -hex 32)" "$(openssl rand -hex 32)" > .env
docker compose up -d
打开 http://localhost:3000/connectors/store,选择 Splunk 并填入前提条件中列出的环境变量。
可用工具
| Tool | What it does |
|---|---|
saia_ask_splunk_question | Ask natural language questions about Splunk using Splunk AI Assistant |
saia_explain_spl | Explain SPL queries in natural language using Splunk AI Assistant |
saia_generate_spl | Generate SPL from natural language queries using Splunk AI Assistant |
saia_optimize_spl | Optimize SPL (Search Processing Language) queries using Splunk AI Assistant |
splunk_create_dashboard | Creates a new Splunk dashboard using Dashboard Studio JSON in the specified app namespace |
splunk_get_index_info | Get detailed information about a specific Splunk index |
splunk_get_indexes | Get a list of indexes from Splunk |
splunk_get_info | Get comprehensive information about the Splunk instance |
splunk_get_knowledge_objects | Retrieve Splunk knowledge objects by type |
splunk_get_kv_store_collections | Get KV Store collection statistics including size, count, and storage information |
splunk_get_metadata | Retrieve metadata about hosts or sources across one or more indexes in the selected time window |
splunk_get_user_info | Retrieves detailed information about the currently authenticated user including roles and permissions |
splunk_get_user_list | Get a list of users from Splunk |
splunk_run_query | Execute a Splunk search query and return the results |
splunk_run_saved_search | Execute a Splunk saved search by name and return its results |
splunk_update_dashboard | Updates an existing Splunk dashboard's definition using Dashboard Studio JSON |
下一步
这份指南对你有帮助吗?