Natural language queries
Ask in plain English, get valid SPL. No cheat sheets, no syntax wrangling.
AI Query Assistant turns natural language into production-ready SPL. Multi-provider AI, template management, query history, and security validation — all native to your Splunk workspace.
From natural-language prompts to battle-tested SPL — with the security, templates, and history your team expects from production tooling.
Ask in plain English, get valid SPL. No cheat sheets, no syntax wrangling.
Switch between OpenAI, Anthropic, Azure, Gemini, DeepSeek, and local Ollama with a single dropdown.
Save proven query patterns as reusable templates. Share them across your team or keep them private.
Every query is logged, searchable, and rerunnable. Rebuild past investigations without rewriting a single pipeline.
Built-in SPL safety checks flag destructive commands, unsafe rex, and injection risks before they run.
Per-seat license keys, usage metering, and custom quota enforcement for regulated environments.
The assistant lives inside Splunk. Ask a question, review the generated SPL, and run it against your indexes — with every result cached and ready to share.
Type a question in natural language. The assistant understands your indexes, sourcetypes, and field names from context.
The model returns SPL with inline explanations. Edit directly, ask for alternatives, or pass it through the security validator.
Execute in a single click. Save as a template for next time, or hand the query off to a dashboard or alert.
Which source IPs had more than 10 failed SSH logins in the last 24h? Include country info.
Investigate incidents in seconds. Hunt across indexes, correlate across sourcetypes, and walk away with hardened SPL you can pin to an alert.
→ Phishing campaigns, brute-force, lateral movement
Answer the on-call question faster. Surface p95 latencies, error budgets, and noisy tenants without memorizing a single stat command.
→ Latency, error rates, capacity, saturation
Let PMs and analysts explore Splunk data directly. Ship dashboards from questions, not tickets — with the guardrails IT needs.
→ Usage, conversion, revenue, cohort analysis
Install the AI Query Assistant in minutes. Bring your own API key. Keep your data inside your Splunk instance.