Skip to main content
User guide

Settings

Index allow-list, the three masking modes, audit forwarding, version. There is no Elasticsearch-connection block: the Splunk connection is implicit inside the app.

Settings is admin-only; its tab family includes AI settings, License and MCP. Changes collect in the save bar at the bottom; "Save and apply" writes local/copilot.conf with no restart.

Settings

Data access

ItemKeyNotes
Index allow-list[limits] agentic_index_whitelistComma-separated. Bounds what the model may touch on its own, the home page's "all logs" scope and MCP list_indexes; SPL the user writes is not affected, and Splunk role permissions remain the floor. Empty = unrestricted
Masking mode[masking] modecloud: IPs to /24, email domain only, secrets and tokens redacted; private: IPs to /16; airgapped: nothing. Read-only here when RST_MASKING_MODE pins it

Masking runs before data leaves Splunk, including samples the model fetches through tools and the per-cluster history triage looks up.

Audit forwarding

[audit_sinks]: syslog address (tcp://host:601 or tls://host:6514), webhook URL and headers (headers echo back as <set · N chars>), TLS verification. The local _internal audit is unaffected.

Version

Current version and build, Splunkbase link. No online update: upgrade by installing a new .spl.

File-only settings

Rate limits ([limits] rate_per_min / burst), agentic budget ([agentic]), threat intel ([threat_intel]) and the operations-layer thresholds are in Configuration.

On this page