splunkguard

64johnlee/splunkguard
★ 0 stars Python 💻 Code/Dev Tools Updated 5d ago
AI-powered Splunk incident investigation using Gemini 2.0 Flash + Splunk MCP Server
View on GitHub → Try with Claude — $10 free →

Quick Install

Copy the config for your editor. Some servers may need additional setup — check the README.

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "splunkguard": {
      "command": "uvx",
      "args": [
        "splunkguard"
      ]
    }
  }
}

Or install with pip: pip install splunkguard

README Excerpt

> AI-powered Splunk incident investigation using Gemini 2.0 Flash + Splunk MCP Server SplunkGuard connects Gemini to your Splunk environment. When an incident occurs, it: 1. **Explores** available indexes and metadata via Splunk MCP tools 2. **Queries** Splunk autonomously — writing and executing SPL to surface patterns

Tools (8)

authentication_failuredata_pipeline_failureerror_spikelatency_degradationnetwork_anomalyresource_exhaustionsecurity_threatservice_down