Splunk Observability Cloud
Connect agents to Splunk Observability Cloud for metrics, SignalFlow, APM, traces, and alert triage
Splunk Observability Cloud
Splunk Observability Cloud (o11y) connects Deslicer AI agents to your metrics, APM services, distributed traces, and alerts through Splunk's hosted MCP Gateway.
Navigation
- Parent: Integrations
- Related: Splunk MCP | Purpose-Built Agents — Observability
What It Does
The Splunk Observability integration gives agents read access to your Observability Cloud environment. Agents can discover metric names, run SignalFlow programs, inspect APM service dependencies, analyze latency and errors, fetch exemplar traces, and search alerts or incidents — all grounded in live data from your realm.
The integration uses Splunk's hosted MCP Gateway. Deslicer derives the correct regional gateway URL from your Observability realm, so you only need to provide your realm and access token.
Setup
- Go to Settings → Integrations → Splunk Observability Cloud.
- Select your realm (for example,
eu1,us0,us1). Deslicer maps the realm to the correct regional MCP Gateway endpoint. - Enter your Splunk Observability access token — an org access token with API authentication scope. Deslicer sends it as the
X-SF-TOKENheader. - Optionally provide an MCP Gateway URL override if your realm is not in the supported list or you use a self-hosted gateway.
- Test the connection and save.
Sensitive fields are masked in the integration editor. Leave the token field unchanged to keep the stored value.
Supported Realms
| Realm | Region |
|---|---|
eu0 | Dublin |
eu1 | Frankfurt |
eu2 | London |
us0 | US East |
us1, us3 | US West |
jp0 | Tokyo |
au0 | Sydney |
sg0 | Singapore |
If your realm is not listed, provide an explicit MCP Gateway URL in the override field.
Tool Capabilities
Agents with this integration can:
| Category | What Agents Can Do |
|---|---|
| Metrics & SignalFlow | Search metric names, read metadata, generate and execute SignalFlow programs |
| APM | List environments and services, map dependencies, analyze latency and errors, fetch exemplar traces |
| Alerting | Search alerts and incidents for triage |
Read-Only by Design
Splunk Observability MCP tools are read and analysis only. Agents cannot create detectors, SLOs, synthetic tests, dashboards, or Metrics Pipeline Management rules through MCP. Purpose-built Observability agents deliver create/update recommendations as Observability UI handoffs — exact steps and deeplinks you follow in the Splunk Observability console.
Pair this integration with Splunk MCP when agents need to pivot from Observability signals into Splunk Enterprise or ITSI logs for root-cause evidence.
Purpose-Built Agents
Three public agents ship pre-configured with Splunk Observability Cloud and matching skills:
| Agent | Focus |
|---|---|
| Observability SRE Copilot | On-call triage — alerts, APM, traces, RUM, synthetics |
| Observability Platform Builder | Dashboards, SLOs, and synthetic test design |
| Observability Cost & Cardinality Steward | Metric volume, cardinality, and MPM rule recommendations |
Clone any of these from the Public Agents gallery and attach your Splunk Observability integration configuration.