CONNECT APP
Build with Splunk
Get visibility and insights across your whole organization, powering actions that improve security, reliability and innovation velocity.
Data Analytics
- API key
MCP
Give your agent Splunk tools
Every Splunk action is exposed as an MCP tool on Pipedream's remote server. Point a client at it with your end user's ID and Connect resolves that user's Splunk account for each tool call — you store no tokens.
// accessToken: mint a short-lived token with the Connect SDK — see the MCP guide
const transport = new StreamableHTTPClientTransport(
new URL("https://remote.mcp.pipedream.net/v3"),
{
requestInit: {
headers: {
Authorization: `Bearer ${accessToken}`,
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", // any stable ID for this user in your system
"x-pd-app-slug": "splunk",
},
},
},
)
const mcp = new Client({ name: "my-agent", version: "1.0.0" })
await mcp.connect(transport)
const { tools } = await mcp.listTools()
// e.g. run Create Event:
const result = await mcp.callTool({
name: "splunk-create-event",
arguments: {
indexName: "Index Name",
eventData: "Event Data",
},
})# access_token: mint a short-lived token with the Connect SDK — see the MCP guide
headers = {
"Authorization": f"Bearer {access_token}",
"x-pd-project-id": "{project_id}",
"x-pd-environment": "production",
"x-pd-external-user-id": "{external_user_id}", # any stable ID for this user in your system
"x-pd-app-slug": "splunk",
}
async with streamablehttp_client("https://remote.mcp.pipedream.net/v3", headers=headers) as (read, write, _):
async with ClientSession(read, write) as session:
await session.initialize()
tools = await session.list_tools()
# e.g. run Create Event:
result = await session.call_tool("splunk-create-event", {
"indexName": "Index Name",
"eventData": "Event Data",
})SDK
Run Splunk actions from your backend
Connect a user's Splunk account once, then run Create Event on their behalf from your own code — TypeScript, Python, or plain HTTP.
import { PipedreamClient } from "@pipedream/sdk"
const pd = new PipedreamClient({
projectId: process.env.PIPEDREAM_PROJECT_ID!,
clientId: process.env.PIPEDREAM_CLIENT_ID!,
clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
projectEnvironment: "production",
})
const result = await pd.actions.run({
id: "splunk-create-event",
externalUserId: "{external_user_id}", // any stable ID for this user in your system
configuredProps: {
splunk: { authProvisionId: "apn_xxxxxxx" },
indexName: "Index Name",
eventData: "Event Data",
},
})from pipedream import Pipedream
pd = Pipedream(
client_id="{oauth_client_id}",
client_secret="{oauth_client_secret}",
project_id="{project_id}",
project_environment="production",
)
result = pd.actions.run(
id="splunk-create-event",
external_user_id="{external_user_id}", # any stable ID for this user in your system
configured_props={
"splunk": {"authProvisionId": "apn_xxxxxxx"},
"indexName": "Index Name",
"eventData": "Event Data",
},
)curl -X POST https://api.pipedream.com/v1/connect/{project_id}/actions/run \
-H "Content-Type: application/json" \
-H "X-PD-Environment: production" \
-H "Authorization: Bearer {access_token}" \
-d '{
"external_user_id": "{external_user_id}",
"id": "splunk-create-event",
"configured_props": {
"splunk": { "authProvisionId": "apn_xxxxxxx" },
"indexName": "Index Name",
"eventData": "Event Data"
}
}'TOOLS
Splunk actions
On-demand operations your product or agent can configure and run on behalf of a connected user.
-
Create Event
actionSends a new event to a specified Splunk index. See the documentationWritev0.0.2 -
Get Search Job Status
actionRetrieve the status of a previously executed Splunk search job. See the documentationRead-onlyv0.0.2 -
List Index Name Options
actionRetrieves available options for the Index Name field.Read-onlyv0.0.1 -
List Saved Search Name Options
actionRetrieves available options for the Saved Search Name field.Read-onlyv0.0.1 -
List Search ID Options
actionRetrieves available options for the Search ID field.Read-onlyv0.0.1 -
Run Search
actionExecutes a Splunk search query and returns the results. See the documentationWritev0.0.2
-
New Alert Fired (Instant)
triggerEmit new event when a new alert is triggered in Splunk. See the documentationInstantv0.0.2 -
New Search Event
triggerEmit new event when a new search event is created. See the documentationv0.0.1 -
New Search Result
triggerEmit new events when a search returns results in Splunk. See the documentationv0.0.1
MULTI-APP
Use Splunk with other popular apps
Most products don't stop at one integration. Pair Splunk with the other apps your users rely on, and ship use cases that span both.
- App slug
- splunk
- Authentication
- API key
- Categories
- Data Analytics
- Actions
- 6
- Triggers
- 3
- API proxy
- Not available