Skip to content

Catalog adapters for a vendor's own MCP server; Splunk first - #830

Merged
keysersoft merged 2 commits into
mainfrom
keysersoft/mcp-adapters-splunk
Oct 3, 2026
Merged

keysersoft merged 2 commits into
mainfrom
keysersoft/mcp-adapters-splunk

Conversation

@keysersoft

@keysersoft keysersoft commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Some vendors now ship an official MCP server. Describing their API again in a REST adapter duplicates what they maintain; bridging their server is better, and what AnythingMCP adds on top (OAuth for Claude/ChatGPT, per-tool roles, audit, response mapping, other systems behind the same endpoint) is the value. First case: a Cisco user bridged the official Splunk MCP Server on 2 Oct and it worked end to end from Claude Desktop.

MCP adapters

  • connector.type: "MCP" in the catalog. At install the tools come from the workspace's server (tools/list), so it gets exactly the tools of its server version. The adapter's tools array is a snapshot: shown in the store, installed as a fallback when the server cannot be reached, and the place for policy.
  • Policy: "enabled": false installs a tool switched off (also honoured for REST adapters); catalog annotations fill the hints the server leaves out (the server's own hints win).
  • Listing the tools is the install check, reported on the form like the probe (403/timeout hints included).
  • Catalog re-sync never adds, rewrites or retires an MCP adapter's tools; instructions and base URL are still compared.
  • ConnectorsService.discoverRemoteMcpTools() with env interpolation and the placeholder guard.

Splunk adapter (intl/splunk.json)

  • Official Splunk MCP Server app (Splunkbase 7931), https://{{SPLUNK_HOST}}:8089/services/mcp, Bearer with the encrypted MCP token.
  • 16 tools as of today's server; the two dashboard writes install switched off. Splunk itself marks splunk_run_query / splunk_run_saved_search as able to write (SPL collect/outputlookup/delete), so the instructions say to use a read-only role.
  • Setup covers the MCP token (a normal user token fails with "invalid token audience"), mcp_tool_execute, and the Splunk Cloud allow list for port 8089.
  • Logo from Simple Icons.

Tests: mcp-adapter.spec.ts (merge policy, install with the server reachable and with a 403 falling back to the snapshot), catalog re-sync for MCP adapters, catalog shape rule for MCP mappings. Adapters + connectors suites pass locally (HANA spec needs the optional hdb module).

Satellite keysersoft/splunk-mcp-gateway (config, prompts, FAQ, auth, troubleshooting, measured topics; not published yet). Satellite generator: optional title (so the repo is not named like Splunk's own "Splunk MCP Server"), and hand-written troubleshooting tables lose their header row whatever it is called (Jev's README showed a stray "Symptom" row).

Counts: 266 adapters. Docs: docs/tool-definition.md has an "MCP adapters" section.

- Adapter type MCP: at install the tools come from the workspace's server
  (tools/list), so it gets exactly what its server version offers; the
  catalog's list is the snapshot shown in the store and the fallback when
  the server cannot be reached. Listing the tools is the install check.
- Catalog policy on top: "enabled": false installs a tool switched off,
  catalog annotations override the server's; catalog updates never rewrite
  or retire an MCP adapter's tools
- Splunk adapter over the official Splunk MCP Server app (16 tools, dashboard
  writes off by default), with setup for the encrypted MCP token,
  mcp_tool_execute and the port 8089 allow list
- 266 adapters
…win over the catalog's

- Satellite config + hand-written prompts, FAQ, auth and troubleshooting;
  topics measured; optional title so the repo is not named like Splunk's
  own product
- The catalog snapshot carries Splunk's annotations again (read/write in the
  store and the satellite); at install the server's hints win and the
  catalog only fills what the server leaves out (the dashboard tools)
- Satellite READMEs: drop the header row of hand-written troubleshooting
  tables whatever it is called (Jev showed a stray 'Symptom' row)
@keysersoft
keysersoft merged commit 431387a into main Oct 3, 2026
13 checks passed
@keysersoft
keysersoft deleted the keysersoft/mcp-adapters-splunk branch October 3, 2026 08:43
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant