Splunk is Not Agent-Ready to agents.
Discry independently scored how well an AI agent can discover and understand the Splunk API from what’s public — not whether it’s usable. Below: every signal we checked, what’s costing the score, and what to change.
SCORED UNDER RUBRIC 1.2 · A full re-launch under Discry Score 2.5 — a new behavioral instrument, not comparable to these scores — is in progress.
Discovery
45% of score · 26/100Comprehension
55% of score · 50/100What we found
- Splunk has strong MCP registry presence with an official server on PulseMCP plus community servers on Glama and Smithery for SPL query execution
- The developer portal at dev.splunk.com renders entirely via JavaScript — robots.txt and llms.txt both return HTML/JS instead of plain text
- An OpenAPI spec exists only for the Splunk Cloud ACS API, not the broader Enterprise REST API
- Multiple community MCP servers enable natural language to SPL query translation, showing strong agent demand
- Documentation is extensive but scattered across Enterprise, Cloud, and Observability products
What to change
Prioritized by impact on discoverability. You (or your docs platform) deploy these — Discry never touches your API.
- 01Fix dev.splunk.com to serve robots.txt and llms.txt as proper plain text files
- 02Create a unified OpenAPI spec for the Splunk Enterprise REST API
- 03Add llms.txt covering core search, indexing, and admin API capabilities
- 04Consolidate documentation across Enterprise/Cloud/Observability for consistent agent consumption
- 05Add .well-known/mcp.json pointing to the official Splunk MCP server
Execution coverage · INFORMATIONAL, UNSCORED
Whether an agent can actually complete a call and recover from errors is the deeper Audit layer — documented here, but not part of the Discry Score.
Splunk uses session tokens, API keys, and OAuth2. JSON/XML error responses. Rate limits for Cloud ACS API documented. Pagination varies by endpoint.