[{"id":123926,"app":7931,"name":"2.0.0","product":{"name":"splunk","display_name":"Splunk"},"release_notes":"**Splunk MCP Server 2.0.0**\n\nSplunk MCP Server 2.0.0 adds tools for investigating alerts and discovering sourcetypes. It also introduces paginated results, improved MCP and OAuth compatibility, stronger security for custom tools, and enhanced telemetry.\n\n**What's New**\n\n**Alert Investigation**\n\nAdded six tools for investigating Splunk alerts:\n\n* splunk\\_list\\_alerts\n* splunk\\_get\\_alert\\_details\n* splunk\\_list\\_fired\\_alerts\n* splunk\\_get\\_fired\\_alert\\_details\n* splunk\\_get\\_alert\\_throttle\n* splunk\\_list\\_active\\_throttles\n\nUse these tools to find alerts, investigate fired alerts, and view configured or active alert throttles.\n\n**Sourcetype Discovery**\n\n* Added the splunk\\_get\\_sourcetypes tool for discovering sourcetypes that contain indexed data.\n* Results include event counts, time coverage, indexes, and configuration details. You can filter results by index and time range.\n\n**Paginated Results**\n\nAdded pagination to the following tools:\n\n* splunk\\_get\\_indexes\n* splunk\\_get\\_sourcetypes\n* splunk\\_list\\_alerts\n* splunk\\_list\\_fired\\_alerts\n* splunk\\_get\\_fired\\_alert\\_details\n* splunk\\_list\\_active\\_throttles\n\nPaginated responses include the total number of results, offset, and page size. They also follow the configured default and maximum row limits.\n\n**MCP and OAuth Improvements**\n\n* Improved MCP-compatible tool error responses.\n* Added the openid scope to OAuth discovery.\n* Added the openWorldHint annotation to all built-in tools.\n\n**Search and Splunk AI Assistant Improvements**\n\n* Increased the maximum prompt and query length to 10,000 characters for splunk\\_run\\_query and Splunk AI Assistant tools.\n* Changed the default splunk\\_run\\_query time range from 24 hours to 6 hours.\n\n**Issues Fixed**\n\n* Fixed saved search arguments that contain escaped nested quotes.\n* Fixed an incompatible authentication scheme used by detached searches.\n* Improved error messages for missing MCP capabilities, search timeouts, and Splunk AI Assistant data discovery tool.\n\n**Upgrade Considerations**\n\n* splunk\\_get\\_metadata no longer supports sourcetype discovery. Use splunk\\_get\\_sourcetypes instead.\n* Calls to splunk\\_run\\_query without a time range now search the last 6 hours instead of the last 24 hours.\n* splunk\\_get\\_indexes now returns paginated results and uses name instead of title for the index identifier.\n* The Splunk AI Assistant data discovery tool requires Splunk AI Assistant 2.2.0 or later with Agent Mode enabled.","CIM_versions":[],"product_versions":["10.5","10.4","10.3","10.2","10.1","10.0","9.4","9.3"],"created_datetime":"2026-09-03T05:01:28.154080Z","published_datetime":"2026-09-03T05:01:28.153683Z","size":4195181,"filename":"splunk-mcp-server_200.tgz","platform":"independent","install_method_single":"simple","install_method_distributed":"appmgmt_phase","fedramp_validation":"no","fips_compatibility":false,"cloud_compatible":true},{"id":123191,"app":7931,"name":"1.3.1","product":{"name":"splunk","display_name":"Splunk"},"release_notes":"<p>App improvements and bug fixes.</p>Updated MCP protocol version to 2025-11-25","CIM_versions":[],"product_versions":["10.5","10.4","10.3","10.2","10.1","10.0","9.4","9.3"],"created_datetime":"2026-08-03T07:12:48.147044Z","published_datetime":"2026-08-03T07:12:48.146703Z","size":4167485,"filename":"splunk-mcp-server_131.tgz","platform":"independent","install_method_single":"simple","install_method_distributed":"appmgmt_phase","fedramp_validation":"no","fips_compatibility":false,"cloud_compatible":true},{"id":122879,"app":7931,"name":"1.3.0","product":{"name":"splunk","display_name":"Splunk"},"release_notes":"Splunk MCP Server App 1.3 introduces Allowed SPL Commands management, a Custom Tools UI for creating and managing user-defined tools, Role-Based Access Control for MCP tools, and multiple UI and dashboard improvements.\n\n**What's New**\n\nAllowed SPL Commands Management\n\nAdded a new Allowed SPL Commands section within the Guardrails tab. Administrators can add or remove SPL commands that are permitted for MCP tool execution. Non-admin users see a read-only view of Splunk Native, Custom, and Builtin commands.\n\n\n\n**Custom Tools UI**\n\nAdministrators can now create, update, enable, disable, and delete custom MCP tools directly from the UI. Supports both SPL-type and API-type custom tools. Custom tools are grouped by app for easier navigation. Users without the mcp\\_tool\\_admin capability see the Create tool button disabled.\n\n\n\n**Role-Based Access Control for MCP Tools**\n\nMCP tools now support role-based access control, ensuring tools are only accessible to users with the appropriate roles and permissions.\n\n\n\n**App Parameter in run\\_splunk\\_query**\n\nAdded an app parameter to run\\_splunk\\_query tool arguments, allowing users to specify the app context for query execution.\n\n\n\n**Saved Search Descriptions in Knowledge Objects**\n\nThe get\\_knowledge\\_objects tool now returns saved search descriptions when querying saved searches.\n\n\n\n**Workload Management Support for run\\_splunk\\_query**\n\nMCP tool run\\_splunk\\_query now supports Splunk workload pool assignment for better resource management.\n\n\n\n**SAIA Data Discovery Tool**\n\nAdded a new SAIA data discovery tool. This tool requires Splunk AI Assistant version 2.2.0 or later.\n\n\n\n**MCP Dashboard Updates**\n\nAdded a new tools and roles panel in the Governance tab to show tool access by role.&#x20;\n\n\n\n**UI Updates**\n\nMCP version is now displayed on the Configuration page.\n\nAdded MCP Tool Annotations to identify read-only and write-capable tools.\n\nRow limit and Time range rows are no longer shown per tool.\n\nUsers cannot set a per-tool rate limit beyond the global rate limit.\n\nUsers cannot set the global rate limit below an existing per-tool rate limit.\n\nAdded an MCP Server heartbeat modular input to prevent Splunk from recycling the MCP handler process.\n\n\n\n**Issues Fixed**\n\nFixed an issue where custom \\`mcp.conf\\` settings were not replicated correctly across search head cluster members.\n\n\n\n**Notes and Considerations**\n\nAdministrators who previously managed SPL command restrictions through manual configuration should review the new Allowed SPL Commands section in the Guardrails tab.","CIM_versions":[],"product_versions":["10.5","10.4","10.3","10.2","10.1","10.0","9.4","9.3"],"created_datetime":"2026-07-23T05:37:32.708692Z","published_datetime":"2026-07-23T05:37:32.708350Z","size":4170933,"filename":"splunk-mcp-server_130.tgz","platform":"independent","install_method_single":"simple","install_method_distributed":"appmgmt_phase","fedramp_validation":"no","fips_compatibility":false,"cloud_compatible":true},{"id":122097,"app":7931,"name":"1.2.1","product":{"name":"splunk","display_name":"Splunk"},"release_notes":"<p>Splunk MCP Server App 1.2.1 introduces a new MCP Telemetry Dashboard for monitoring MCP usage, authentication, consumption, and errors. This release also moves MCP tool execution limits and rate controls into a new Guardrails section in the UI, adds a new Splunk AI Assistant timeout setting, improves configuration validation, and includes telemetry and permissions-related fixes.</p>\n<p>**What's New**</p>\n<p>MCP Telemetry Dashboard</p>\n<p>Added a new MCP Telemetry Dashboard in the Splunk MCP Server app to help administrators quickly understand MCP activity across their environment. The dashboard helps answer questions such as:</p>\n<p>- Who is using MCP and how are they authenticating?</p>\n<p>- What are users and agents doing, and how much are they consuming?</p>\n<p>- Is anything broken?</p>\n<p>New Guardrails section for MCP controls</p>\n<p>Moved MCP server limits and rate controls for MCP tool execution to a new Guardrails section on the MCP landing page.</p>\n<p>UI-based Guardrails management</p>\n<p>Administrators can now update MCP app Guardrails settings directly from the UI. These changes do not require a splunkd restart.</p>\n<p>Splunk AI Assistant timeout setting</p>\n<p>Added a new Guardrails setting, Splunk AI Assistant timeout, which controls the maximum number of seconds before a Splunk AI Assistant tool call times out.</p>\n<p>Improved configuration specification coverage</p>\n<p>Added entries to mcp.conf.spec for eight previously undocumented \\[server] configuration keys that were causing btool validation errors.</p>\n<p>**Fixed Issues**</p>\n<p>Improved tool management permission errors</p>\n<p>When a user does not have the mcp\\_tool\\_admin capability, the app now displays a specific error message instead of a generic fallback error: \"You do not have the mcp\\_tool\\_admin capability required to manage tools.\"</p>\n<p>Saved search telemetry reliability</p>\n<p>Fixed an issue in saved search telemetry that caused some events to be dropped.</p><p>Fixed MCP encrypted token compatibility when reading stored credentials.</p>\n<p>**Notes / Considerations**</p>\n<p>- Guardrails settings can now be updated from the MCP app UI without restarting splunkd.</p>\n<p>- The Splunk AI Assistant timeout setting applies to Splunk AI Assistant tool calls and controls the maximum time allowed before a call times out.</p>\n<p>- Administrators who previously managed MCP server limits and rate controls through configuration should review the new Guardrails section on the MCP landing page.</p>\n<p />","CIM_versions":[],"product_versions":["10.5","10.4","10.3","10.2","10.1","10.0","9.4","9.3"],"created_datetime":"2026-06-25T05:03:41.447403Z","published_datetime":"2026-06-25T05:03:41.447062Z","size":3971169,"filename":"splunk-mcp-server_121.tgz","platform":"independent","install_method_single":"simple","install_method_distributed":"appmgmt_phase","fedramp_validation":"no","fips_compatibility":false,"cloud_compatible":true}]