Splunk Search and Analytics
Unified search and analytics workflow combining SPL search, index management, data inputs, and HTTP Event Collector for SOC analysts, IT operations, and data engineers.
What You Can Do
MCP Tools
list-search-jobs
List current search jobs.
create-search-job
Create a new SPL search job.
get-search-job
Get search job status and details.
delete-search-job
Delete a search job.
control-search-job
Control a search job (pause, unpause, finalize, cancel).
get-search-results
Get results from a completed search job.
get-search-events
Get untransformed events from a search job.
export-search-results
Export search results directly without creating a job.
list-indexes
List all Splunk indexes.
create-index
Create a new Splunk index.
get-index
Get index details and settings.
update-index
Update index settings.
delete-index
Delete an index.
list-monitor-inputs
List file monitor data inputs.
create-monitor-input
Create a file monitor data input.
list-http-input-tokens
List HTTP Event Collector tokens.
create-http-input-token
Create an HTTP Event Collector token.
send-event
Send a JSON event via HTTP Event Collector.
check-ack-status
Check HEC indexing acknowledgment status.