Skip to main content
Back to products
SubscriptionAIQueryProductivity

AI Query Assistant for Splunk

Natural-language to SPL with built-in security validation, multi-provider AI, and per-user history.

A 30-day trial licence, issued as soon as you sign in.

Overview

Operators describe an intent in plain English; AI Query Assistant translates it into an optimized SPL query. Multi-provider AI (OpenAI, Anthropic, custom presets), KV-backed query history per user, savable templates, and a security guardrail that catches dangerous time-range and SSRF patterns before they hit Splunk. Ships with full Chinese + English localization (198 i18n keys across 7 views) and works across Splunk Enterprise 10.0+, Splunk Cloud, and Search Head Cluster deployments.

Capabilities

01

Natural-language to SPL

Operators ask in plain English; the assistant emits an optimized SPL query with caveats and field hints. The translation accepts intent ("failed logins from China today"), not just literal field names.

02

Multi-provider AI

Compatible with OpenAI, Anthropic / Claude, and custom presets. Provider configurations live in a KV-backed `mcp_provider_presets` collection — admins can add, rename, or remove vendors without re-installing the app.

03

Per-user query history

Server-side filtered by user (`{user: self.userName}` enforced in the REST handler). Survives Splunk Web restarts because history records live in the KV store, not in-process Python dicts.

04

Saved templates

Save and reuse common query patterns. Trial = 5 templates, Professional = 30, Enterprise unlimited. Tier-aware caps surface in the UI before you hit them.

05

Security guardrail

SPL validation rejects dangerous time-range patterns (the `-30mon` bug from 2.x is fixed: every relative unit s/m/h/d/w/mon/y is now anchored). SSRF guard rejects integration-platform URLs that resolve to private/loopback/link-local IP ranges.

06

Locked-down KV ACLs

KV collections (`mcp_ai_providers`, `mcp_license_status`, etc.) cannot be mutated outside the validating REST handlers. The legacy `debug_keys` endpoint that exposed the licence signing key was removed in 3.0.1.

07

RSA-PSS signed licenses

Licences carry a 2048-bit RSA-PSS signature verified locally on the customer's install. Optional AES decryption is retained for legacy issuers; new deployments verify with `public_key_pem` only — no SaaS round-trip.

08

Splunk Cloud + SHC

`metadata/default.meta` grants `sc_admin` alongside `admin` so KV collections work on Splunk Cloud. `default/server.conf` adds `[shclustering] conf_replication_include.mcp = true` so Setup-page edits propagate across SHC members.

Editions

Pick an edition below. Licences are issued from the console and can be upgraded at any time without reinstalling.

Professional

Recommended

$9.9/mo

$89/yr

Growing security teams

Enterprise

$39/mo

$349/yr

Large SOC/Compliance organizations

Need Professional or Enterprise? Contact sales

Requirements

Splunk
8.0+
Platform
Linux, Windows, macOS
Memory
4GB RAM minimum, 8GB recommended
Storage
500MB available space
CPU
2+ cores recommended