# Triagic + Splunk: ticket investigations over your logs, errors and metrics, read-only

> Splunk in Triagic: Run SPL searches and read index and knowledge-object metadata. Read-only, with a credential you configure.

Source: https://triagic.com/integrations/splunk

## What you can ask

- Check Splunk for errors from the checkout service in the last hour and group them by message
- In Splunk, did latency for the import worker change after the 16:02 deploy?
- Find every Splunk event that mentions request id 7f3a-…-c2 and put them in order
- Is the alert in Splunk for the export queue still firing, and since when?
- What did Splunk record for the pod that restarted at 11:31?

## What the agent can do

- `splunk_get_info`
- `splunk_get_indexes`
- `splunk_get_index_info`
- `splunk_get_metadata`
- `splunk_get_user_info`
- `splunk_get_user_list`
- `splunk_get_kv_store_collections`
- `splunk_get_knowledge_objects`
- `saia_generate_spl`
- `saia_explain_spl`
- `saia_optimize_spl`
- `saia_ask_splunk_question`
- `splunk_run_query`
- `splunk_run_saved_search`

## Connect in three steps

1. **Mint a read-only credential in Splunk.** Create a dedicated user or token that can only read. A hosted endpoint inside your own Splunk instance; an allowlist of the get and search tools, and the token's capabilities bound the rest.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then Splunk. Fill in: Splunk URL (required): The management port, usually 8089, not the web UI on 8000.; Authentication token (required): Splunk → Settings → Tokens → New Token, with its audience set to “mcp”. Searches run under this token's role, so a read-only role keeps it read-only.
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts Splunk locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/observability#splunk

## Read-only, by construction

A hosted endpoint inside your own Splunk instance; an allowlist of the get and search tools, and the token's capabilities bound the rest.

## FAQ

**Can Triagic change anything in Splunk?**
No. A hosted endpoint inside your own Splunk instance; an allowlist of the get and search tools, and the token's capabilities bound the rest. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect Splunk?**
Splunk URL, Authentication token. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does Splunk cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [Sentry](https://triagic.com/integrations/sentry)
- [Prometheus](https://triagic.com/integrations/prometheus)
- [OpenSearch](https://triagic.com/integrations/opensearch)
- [Elasticsearch](https://triagic.com/integrations/elasticsearch)
