Investigate a Splunk production issue. Loads events, runs deterministic detectors, then drives an iterative investigation loop via MCP tools — Claude is the reasoning engine. No Ollama, no API key, no server process. Watch live progress via the TUI (uv run python -m splunk.tui).