Evidence tier Source Confirmed · 3 captures on record
What the publisher says
As described on AWS Marketplace.
**Splunk MCP Server Implementation:** Keos installs and configures Splunk's Model Context Protocol (MCP) server on your Splunk environment, enabling AI assistants and LLMs to connect directly to your Splunk data — running searches, retrieving results, and surfacing insights through natural language.
**AI-Assisted Threat Hunting and Investigation:** Once the MCP server is configured, analysts can interact with Splunk using conversational AI tools — asking questions, running ad-hoc investigations, and exploring data without needing to write SPL manually.
Show the rest of the publisher’s description (3 more lines)
**Automated Workflow Integration:** Keos configures MCP server integrations that allow AI models to trigger searches, correlate events, and feed findings into existing Splunk workflows — reducing the manual burden on your SOC and operations teams.
**Whiteleaf AI Detection Coverage (Optional Add-On):** For teams looking to extend AI capabilities into automated detections, Keos can also install and configure Whiteleaf AI's 100+ pre-built security use cases, which surface AI-driven risk scores directly within Splunk Enterprise Security.
**Validation and Documentation:** The full deployment is validated end-to-end, with documentation and weekly status reports delivered throughout the 80-hour engagement.
Highlights
Highlighted by the publisher on AWS Marketplace.
Splunk MCP server configured to enable AI assistants and LLMs to query, search, and analyze your Splunk data using natural language
AI-assisted threat hunting and automated investigation workflows reduce manual SPL authoring and accelerate SOC response
Whiteleaf AI's 100+ pre-built security detections available as a complementary add-on for expanded AI-powered coverage
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Sources
Linked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

