Skip to main content

MCP server for Splunk On-Call (VictorOps) incident management

Project description

mcp-server-splunk-oncall

PyPI version License: MIT Python 3.10+

MCP server for the Splunk On-Call (VictorOps) API. Full coverage of the REST API with automatic read-only detection.

Tools (45)

Access

Tool Description
get_access_mode Check if API key is full-access or read-only

Incidents

Tool Description
list_incidents List all current incidents
acknowledge_incidents Acknowledge incidents by number
resolve_incidents Resolve incidents by number
acknowledge_all_incidents Acknowledge all triggered incidents
resolve_all_incidents Resolve all triggered incidents
reroute_incidents Reroute incidents to another user or policy
get_incident_timeline Get event timeline for an incident

On-Call

Tool Description
get_oncall Who is currently on call across all teams
get_team_oncall_schedule On-call schedule for a team
get_user_oncall_schedule On-call schedule for a user

Teams

Tool Description
list_teams List all teams
get_team Get team details
create_team Create a new team
update_team Update a team name
delete_team Delete a team
get_team_members List members of a team
add_team_member Add a user to a team
remove_team_member Remove a user from a team
get_team_admins List team admins
get_team_policies List escalation policies for a team

Users

Tool Description
list_users List all users
get_user Get user details
create_user Invite a new user
delete_user Delete a user (with replacement)
get_user_contact_methods List contact methods (phone, email, SMS)
get_user_devices List push notification devices
get_user_oncall_schedule User on-call schedule
get_user_policies User escalation policies
get_user_teams User team memberships

Routing Keys

Tool Description
list_routing_keys List routing keys and their policies
create_routing_key Create a routing key
delete_routing_key Delete a routing key

Escalation Policies

Tool Description
list_policies List all escalation policies
get_policy Get escalation policy details
create_policy Create an escalation policy
delete_policy Delete an escalation policy

Maintenance

Tool Description
list_maintenance List maintenance windows
get_maintenance Get maintenance window details
create_maintenance Create a maintenance window
end_maintenance End a maintenance window early

Organization

Tool Description
get_org_info Get organization information
get_org_timeline Organization-wide event timeline

Alerts and Reporting

Tool Description
list_alerts List recent alerts
get_incident_history Historical incident data
get_oncall_report On-call report for a team

Installation

uvx mcp-server-splunk-oncall

Or install from PyPI:

pip install mcp-server-splunk-oncall

Configuration

The server requires two environment variables:

  • SPLUNK_ONCALL_API_ID - Your Splunk On-Call API ID
  • SPLUNK_ONCALL_API_KEY - Your Splunk On-Call API key

Claude Code

Add to your Claude Code MCP settings:

{
  "mcpServers": {
    "splunk-oncall": {
      "command": "uvx",
      "args": ["mcp-server-splunk-oncall"],
      "env": {
        "SPLUNK_ONCALL_API_ID": "your-api-id",
        "SPLUNK_ONCALL_API_KEY": "your-api-key"
      }
    }
  }
}

Read-Only Mode

The server automatically detects whether the API key is read-only or full-access on first use. When a read-only key is provided, write operations return a clear error message instead of failing with a 403. Use get_access_mode to check.

You can also force read-only mode with a full-access key by setting:

"SPLUNK_ONCALL_READ_ONLY": "true"

This is useful when you want to use a full-access key but prevent accidental writes.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

mcp_server_splunk_oncall-0.3.3.tar.gz (10.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

mcp_server_splunk_oncall-0.3.3-py3-none-any.whl (9.9 kB view details)

Uploaded Python 3

File details

Details for the file mcp_server_splunk_oncall-0.3.3.tar.gz.

File metadata

  • Download URL: mcp_server_splunk_oncall-0.3.3.tar.gz
  • Upload date:
  • Size: 10.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for mcp_server_splunk_oncall-0.3.3.tar.gz
Algorithm Hash digest
SHA256 fc96a33bae75151259b9ef7fefdc9d7d4b422c5a4954a1a75a8949f2885de823
MD5 fe9b4d39696298d2d7b9f701898af635
BLAKE2b-256 72e51b6000c2ae413e6ddb5be4045451ec9582defe18bfcd2f99a2c84cdd7cd6

See more details on using hashes here.

Provenance

The following attestation bundles were made for mcp_server_splunk_oncall-0.3.3.tar.gz:

Publisher: publish.yml on arnstarn/mcp-server-splunk-oncall

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file mcp_server_splunk_oncall-0.3.3-py3-none-any.whl.

File metadata

File hashes

Hashes for mcp_server_splunk_oncall-0.3.3-py3-none-any.whl
Algorithm Hash digest
SHA256 ae7171fdc9752ca58216057051c8e6058eaadc389c4b91704cd2e3a79aece20a
MD5 f63e7580024f72e3950add8b305c79e1
BLAKE2b-256 8a12d1bb4ce37523f5ffce2c2c49f6615ac6998527beee52c7a2c16941765150

See more details on using hashes here.

Provenance

The following attestation bundles were made for mcp_server_splunk_oncall-0.3.3-py3-none-any.whl:

Publisher: publish.yml on arnstarn/mcp-server-splunk-oncall

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page