Skip to main content

MCP server for Splunk On-Call (VictorOps) incident management

Project description

mcp-server-splunk-oncall

PyPI version License: MIT Python 3.10+

MCP server for the Splunk On-Call (VictorOps) API. Full coverage of the REST API with automatic read-only detection.

Tools (45)

Access

Tool Description
get_access_mode Check if API key is full-access or read-only

Incidents

Tool Description
list_incidents List all current incidents
acknowledge_incidents Acknowledge incidents by number
resolve_incidents Resolve incidents by number
acknowledge_all_incidents Acknowledge all triggered incidents
resolve_all_incidents Resolve all triggered incidents
reroute_incidents Reroute incidents to another user or policy
get_incident_timeline Get event timeline for an incident

On-Call

Tool Description
get_oncall Who is currently on call across all teams
get_team_oncall_schedule On-call schedule for a team
get_user_oncall_schedule On-call schedule for a user

Teams

Tool Description
list_teams List all teams
get_team Get team details
create_team Create a new team
update_team Update a team name
delete_team Delete a team
get_team_members List members of a team
add_team_member Add a user to a team
remove_team_member Remove a user from a team
get_team_admins List team admins
get_team_policies List escalation policies for a team

Users

Tool Description
list_users List all users
get_user Get user details
create_user Invite a new user
delete_user Delete a user (with replacement)
get_user_contact_methods List contact methods (phone, email, SMS)
get_user_devices List push notification devices
get_user_oncall_schedule User on-call schedule
get_user_policies User escalation policies
get_user_teams User team memberships

Routing Keys

Tool Description
list_routing_keys List routing keys and their policies
create_routing_key Create a routing key
delete_routing_key Delete a routing key

Escalation Policies

Tool Description
list_policies List all escalation policies
get_policy Get escalation policy details
create_policy Create an escalation policy
delete_policy Delete an escalation policy

Maintenance

Tool Description
list_maintenance List maintenance windows
get_maintenance Get maintenance window details
create_maintenance Create a maintenance window
end_maintenance End a maintenance window early

Organization

Tool Description
get_org_info Get organization information
get_org_timeline Organization-wide event timeline

Alerts and Reporting

Tool Description
list_alerts List recent alerts
get_incident_history Historical incident data
get_oncall_report On-call report for a team

Installation

uvx mcp-server-splunk-oncall

Or install from PyPI:

pip install mcp-server-splunk-oncall

Configuration

The server requires two environment variables:

  • SPLUNK_ONCALL_API_ID - Your Splunk On-Call API ID
  • SPLUNK_ONCALL_API_KEY - Your Splunk On-Call API key

Claude Code

Add to your Claude Code MCP settings:

{
  "mcpServers": {
    "splunk-oncall": {
      "command": "uvx",
      "args": ["mcp-server-splunk-oncall"],
      "env": {
        "SPLUNK_ONCALL_API_ID": "your-api-id",
        "SPLUNK_ONCALL_API_KEY": "your-api-key"
      }
    }
  }
}

Read-Only Mode

The server automatically detects whether the API key is read-only or full-access on first use. When a read-only key is provided, write operations return a clear error message instead of failing with a 403. Use get_access_mode to check.

You can also force read-only mode with a full-access key by setting:

"SPLUNK_ONCALL_READ_ONLY": "true"

This is useful when you want to use a full-access key but prevent accidental writes.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mcp_server_splunk_oncall-0.4.0.tar.gz (10.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mcp_server_splunk_oncall-0.4.0-py3-none-any.whl (10.1 kB view details)

Uploaded Python 3

File details

Details for the file mcp_server_splunk_oncall-0.4.0.tar.gz.

File metadata

  • Download URL: mcp_server_splunk_oncall-0.4.0.tar.gz
  • Upload date:
  • Size: 10.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for mcp_server_splunk_oncall-0.4.0.tar.gz
Algorithm Hash digest
SHA256 9ac7510bbd7465c68abeb71d3e483a48164704a6f217803c207fc5547459dda8
MD5 8f34a028be77865dfe16cc157960f172
BLAKE2b-256 c315e9df9f9b9a1750643ef2217ac80a07dddbb2452f26caf468349aaee9de4b

See more details on using hashes here.

Provenance

The following attestation bundles were made for mcp_server_splunk_oncall-0.4.0.tar.gz:

Publisher: publish.yml on arnstarn/mcp-server-splunk-oncall

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file mcp_server_splunk_oncall-0.4.0-py3-none-any.whl.

File metadata

File hashes

Hashes for mcp_server_splunk_oncall-0.4.0-py3-none-any.whl
Algorithm Hash digest
SHA256 ef3316f6f32c3514fb25ddcc0c32a8971acceee6eeb10eb3a2bc14a9878d6907
MD5 4e50c298c6812bae1be386cbe7703f4a
BLAKE2b-256 59fae041f0f66e8d9bb58cd2af89150487d54e27ea809d368f9e80e15dd7d666

See more details on using hashes here.

Provenance

The following attestation bundles were made for mcp_server_splunk_oncall-0.4.0-py3-none-any.whl:

Publisher: publish.yml on arnstarn/mcp-server-splunk-oncall

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page