Splunk Observability Cloud

Connect agents to Splunk Observability Cloud for metrics, SignalFlow, APM, traces, and alert triage

Splunk Observability Cloud

Splunk Observability Cloud (o11y) connects Deslicer AI agents to your metrics, APM services, distributed traces, and alerts through Splunk's hosted MCP Gateway.


What It Does

The Splunk Observability integration gives agents read access to your Observability Cloud environment. Agents can discover metric names, run SignalFlow programs, inspect APM service dependencies, analyze latency and errors, fetch exemplar traces, and search alerts or incidents — all grounded in live data from your realm.

The integration uses Splunk's hosted MCP Gateway. Deslicer derives the correct regional gateway URL from your Observability realm, so you only need to provide your realm and access token.

Setup

  1. Go to SettingsIntegrationsSplunk Observability Cloud.
  2. Select your realm (for example, eu1, us0, us1). Deslicer maps the realm to the correct regional MCP Gateway endpoint.
  3. Enter your Splunk Observability access token — an org access token with API authentication scope. Deslicer sends it as the X-SF-TOKEN header.
  4. Optionally provide an MCP Gateway URL override if your realm is not in the supported list or you use a self-hosted gateway.
  5. Test the connection and save.

Sensitive fields are masked in the integration editor. Leave the token field unchanged to keep the stored value.

Supported Realms

RealmRegion
eu0Dublin
eu1Frankfurt
eu2London
us0US East
us1, us3US West
jp0Tokyo
au0Sydney
sg0Singapore

If your realm is not listed, provide an explicit MCP Gateway URL in the override field.

Tool Capabilities

Agents with this integration can:

CategoryWhat Agents Can Do
Metrics & SignalFlowSearch metric names, read metadata, generate and execute SignalFlow programs
APMList environments and services, map dependencies, analyze latency and errors, fetch exemplar traces
AlertingSearch alerts and incidents for triage

Read-Only by Design

Splunk Observability MCP tools are read and analysis only. Agents cannot create detectors, SLOs, synthetic tests, dashboards, or Metrics Pipeline Management rules through MCP. Purpose-built Observability agents deliver create/update recommendations as Observability UI handoffs — exact steps and deeplinks you follow in the Splunk Observability console.

Pair this integration with Splunk MCP when agents need to pivot from Observability signals into Splunk Enterprise or ITSI logs for root-cause evidence.

Purpose-Built Agents

Three public agents ship pre-configured with Splunk Observability Cloud and matching skills:

AgentFocus
Observability SRE CopilotOn-call triage — alerts, APM, traces, RUM, synthetics
Observability Platform BuilderDashboards, SLOs, and synthetic test design
Observability Cost & Cardinality StewardMetric volume, cardinality, and MPM rule recommendations

Clone any of these from the Public Agents gallery and attach your Splunk Observability integration configuration.