Skip to main content
User guide

UI tour

The three navigation groups and the shift they follow, the top-bar controls, the command palette, how roles affect buttons, and the three entry points outside the navigation.

The app runs full-screen inside Splunk Web with Splunk's own bar hidden. The left rail has three groups; top to bottom is the order of a shift.

Shell

Three groups

GroupPagesPurpose
Security operationsSecurity posture (tabs: Alerts / Reports), Smart query, Investigations, Triage, Detection rulesWhat is burning now → chase one thread → look back at what was asked → clear alerts in batches → turn conclusions into rules
Reference dataField dictionary, Runbooks, Asset inventory, Baseline checks, Data onboardingWhat you consult while handling, not what you handle today
AdministrationPlatform health (tabs: Audit log / Outbound channels / Search performance), Settings (tabs: AI settings / License / MCP)The first is opened weekly, the second rarely after install

Two links at the bottom: Help center (these docs) and Documentation.

Top bar

  • Language: Chinese / English, reloads on switch. The AI's output language is governed separately by response_language, which follows the UI by default.
  • Theme: light / dark / system.
  • Account: shows the Splunk user and the role tier (admin / analyst / viewer); the menu holds only Preferences.
  • ⌘K / Ctrl+K: command palette; type a page name to jump, including tab destinations; on the home page it also resets the current conversation.

Command palette

How roles shape the UI

Every page is visible. Write actions follow the three role tiers: a button stays visible below the required tier and, when clicked, explains "needs analyst / admin". Paid capabilities without a licence behave the same, pointing to the licence page.

Three entry points outside the navigation

EntryWherePage
| copilot / | splexplainSplunk search barSearch commands
"Investigate with Copilot"Enterprise Security → Incident Review → notable row menuAlerts
MCP serverExternal agents (Claude Desktop / Cursor / your own)MCP

First visit

The empty home page shows an onboarding checklist (LLM / licence / index allow-list / demo data / first question); the first three items are admin-only. It collapses once complete. Its state is per user in the KV store.

On this page