Skip to main content
Skills / Splunk Tenable Cloud Security Skill

Splunk Tenable Cloud Security Skill

Contributed

Query and triage Tenable Cloud Security posture findings in Splunk via the official Splunk MCP Server.

Authorrrossetti-splunk
Invocation/splunk-tenable-cloud-security
LicenseApache-2.0
AddedAug 17, 2026

Compatible Platforms

Claude CodeClaude DesktopCursorCodexGitHub Copilot

Integrations

SplunkTenable

Tags

splunktenablecloud-securityposturesplmcp

Query and triage Tenable Cloud Security posture findings already ingested in Splunk using production-safe, count-first SPL via the official Splunk MCP Server.

What it does

  • Provides three workflows for finding inventory, cluster/workload triage, and Tenable policy/account exposure
  • Enforces count-first SPL guardrails with explicit time bounds and read-only defaults
  • Parses resources{}{} fields and rolls up findings by cluster, workload, account, and policy
  • Routes through Splunk MCP discovery tools with a documented CLI fallback when MCP is unavailable

How it works

The skill packages routing logic in SKILL.md with progressive disclosure into references/ and workflows/. The agent discovers your Splunk environment via MCP, validates Tenable posture field mappings, runs bounded SPL queries, and returns structured triage output. It integrates with upstream Splunk Agent Skills for SPL optimization and CLI fallback without forking their content.