Skip to content

Connectors

Connectors extend the agent with external tools by connecting it to MCP (Model Context Protocol) servers. A connector's tools appear alongside the agent's built-in Splunk tools, letting it enrich, correlate, or act on what it finds in your data - for example, looking up a ticket, checking a threat intelligence feed, or querying an asset inventory while investigating.

Connectors are personal. Each user adds their own from the User Settings page, and they apply only to that user's conversations.

Note

Connectors don't widen the agent's scope. The agent remains a Splunk agent and uses connector tools in service of the Splunk task at hand - it won't take on unrelated work just because a connector makes it possible.

Adding a Connector

  1. Navigate to User Settings in the Splunk app.

  2. Under the User Connectors section, click + Add.

  3. Fill in the following fields:

    • Name - A display name for the connector.

    • MCP server URL - The server's endpoint URL, starting with https://.
      Only Streamable HTTP MCP servers are supported.

    • HTTP headers (optional) - Extra headers for servers that require authentication, written one Name: value per line, for example:

      Authorization: Bearer <token>
      X-Api-Version: 2025-11-25
      

      Headers that control the connection itself or the MCP protocol are reserved and cannot be set here.

    • Risk level - Which of the server's tools are exposed to the agent. See Risk Levels below.

  4. Click Save, then reload the Lynx AI Agent page.

Use the checkbox on the left of a connector to disable it temporarily without deleting it, and the Delete button to remove it entirely.

Info

A connector's tools become available when the app page is opened. After adding, changing, or removing a connector, reload the page for the change to take effect.

Risk Levels

Every connector carries a risk level that decides which of the server's tools are exposed to the agent. It is based on the readOnlyHint and destructiveHint annotations that the MCP server reports for each of its tools.

Risk level MCP tools exposed to the agent
🟢 Read-only tools only (default) Only tools annotated readOnlyHint.
🟡 No destructive tools The above, plus tools explicitly annotated destructiveHint: false.
🔴 All tools (DANGER) Everything the MCP server exposes, including unannotated tools.

Warning

Annotations are self-reported by the MCP server and are not a security boundary. A server is free to describe a destructive tool as read-only.

Tools that carry no annotations at all are treated as destructive and are exposed only at the highest risk level. Only connect servers you trust, and keep the risk level as low as the task allows.

How the Agent Uses Connector Tools

  • Tool names and descriptions come from the MCP server, not from Lynx AI.

  • The agent prefers its built-in Splunk tools for anything reachable through Splunk, and uses connector tools for what isn't. Built-in tools take precedence over a connector tool of the same name.

  • Connector output is treated as untrusted data. The agent reports what a tool returns but does not follow instructions contained in it.

  • A connector that fails to load is skipped. The conversation continues without its tools.

Connectivity

Connector requests are made by the Lynx AI backend, so the backend must be able to reach the MCP server - not the browser, and not the search head.

flowchart LR
    User(["User"])

    subgraph you["Your Infrastructure"]
        App["Lynx AI Agent Splunk App"]
        Splunk[("Splunk")]
    end

    Backend["Lynx AI Backend"]
    MCP["MCP Server (Connector)"]

    User -- Prompt --> App
    App <--> Splunk
    App <--> Backend
    Backend <--> MCP

What a connector may point to depends on where your backend runs:

☁ Cloud backend 🔒 Self-hosted backend
URL scheme https only http or https
Internal-network MCP servers ❌ ✅

With the Lynx AI cloud backend, the MCP server must be reachable over the public internet. A self-hosted backend (Private Cloud or air-gapped) can also reach servers inside your own network.

Note

Point the connector at the MCP server's final endpoint URL - redirects are not followed.

Storage and Privacy

Connectors are stored in Splunk's KV store, alongside your user rules and custom user skills. Each user sees only their own connectors. Administrators with the admin role can view all users' KV store data.

Warning

Connector headers - including any API keys or tokens - are stored in the KV store as entered, and are not encrypted.

Use scoped, least-privilege credentials for connectors, and rotate them as you would any other shared secret.

As with chat history and user rules, the KV store must be enabled on the Search Head for connectors to work. See Permissions for more on KV store access.

Troubleshooting

If a connector's tools don't show up in a conversation:

  • Confirm the connector is enabled and was saved, then reload the Lynx AI Agent page.

  • Check that the tools you expect are permitted at the connector's risk level. Tools without annotations require the highest level.

  • Verify the MCP server is reachable from your backend. On the cloud backend, it must be publicly reachable over https.

  • Open the browser's developer console. A connector that failed to load logs a warning naming the connector and the error it returned.