ソリューション  ·  2026-09-10

Splunk MCP Server 2.0 — identity-bound、least-privilege agent access to Splunk data

ソリューションHigh 影響度Global
Splunk published deployment guidance(2026年9月8日)for MCP Server 2.0、adding browser-based OAuth that binds agent access to an authenticated user、role-to-tool enforcement at discovery and invocation、safe SPL allowlists、rate/timeout/output-row limits、read-only alert tools、and provenance-labeled activity logged to _audit.
It's a concrete、shipping implementation pattern(from a major SIEM vendor)for the industry's biggest agentic-AI security gap: MCP tool calls executing with unbounded、un-auditable privilege — directly relevant as MCP-related CVEs(LiteLLM、DeepSeek Harness)proliferate this same week.
Security teams deploying MCP servers against SIEM/telemetry data should adopt this as a reference architecture for OAuth-bound、role-scoped、audited agent tool access.
Splunk Blog
ライブフィードで見る AIセキュリティとガバナンスの関連情報をさらに見る — 毎朝更新。
フィードを開く →