Triagic + Splunk: ticket investigations over your logs, errors and metrics, read-only
Run SPL searches and read index and knowledge-object metadata. Needs the MCP Server app (Splunkbase 7931) installed on the instance. Triagic connects to Splunk from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Splunk.
What you can ask
- Check Splunk for errors from the checkout service in the last hour and group them by message
- In Splunk, did latency for the import worker change after the 16:02 deploy?
- Find every Splunk event that mentions request id 7f3a-…-c2 and put them in order
- Is the alert in Splunk for the export queue still firing, and since when?
- What did Splunk record for the pod that restarted at 11:31?
What the agent can do
These are the 14 tools Triagic exposes from the Splunk MCP server. Anything else the server lists is dropped at connect time.
- splunk_get_info
- splunk_get_indexes
- splunk_get_index_info
- splunk_get_metadata
- splunk_get_user_info
- splunk_get_user_list
- splunk_get_kv_store_collections
- splunk_get_knowledge_objects
- saia_generate_spl
- saia_explain_spl
- saia_optimize_spl
- saia_ask_splunk_question
- splunk_run_query
- splunk_run_saved_search
Connect in three steps
- 1
Mint a read-only credential in Splunk
Create a dedicated user or token that can only read. A hosted endpoint inside your own Splunk instance; an allowlist of the get and search tools, and the token's capabilities bound the rest.
- 2
Add it in the Triagic portal
Integrations, then Add shared data source, then Splunk.
- Splunk URL: The management port, usually 8089, not the web UI on 8000.
- Authentication token: Splunk → Settings → Tokens → New Token, with its audience set to “mcp”. Searches run under this token's role, so a read-only role keeps it read-only.
- 3
Let a desktop pick it up
Saving validates the shape of what you typed. The first desktop app to sync starts Splunk locally and reports running or degraded with the error text.
Field-by-field setup, TLS options and the error table: Splunk in the docs.
Read-only, by construction
A hosted endpoint inside your own Splunk instance; an allowlist of the get and search tools, and the token's capabilities bound the rest.
FAQ
- Can Triagic change anything in Splunk?
- No. A hosted endpoint inside your own Splunk instance; an allowlist of the get and search tools, and the token's capabilities bound the rest. Give it a read-only credential as well, so the guarantee does not rest on one layer.
- What do I need to connect Splunk?
- Splunk URL, Authentication token. The desktop app on a member's machine starts the connection; the portal never holds a live process.
- Does Splunk cost extra?
- No. Every connector is included in the seat price. Start a 14-day trial without a card.
Related integrations
Try it on your own Splunk
No card. Install the desktop app, connect Splunk read-only, and triage a real ticket this afternoon.