Use Splunk AI Assistant in the Search app

Splunk AI Assistant is an optional generative AI feature in Splunk Web that helps users write, interpret, and optimize SPL searches. The assistant is displayed on the right side of the search bar.

Splunk AI Assistant is an optional generative AI assistant that helps users write, understand, explain, and optimize SPL and SPL2 searches using natural language. It brings the latest AI agentic capabilities directly into the Search & Reporting workflow, and includes SPL2 search authoring for federated searches third-party data stores and Machine Data Lake data sources.

When the AI Assistant needs to use a tool, such as running a search, it asks for your approval before proceeding. You can approve or deny each tool call. The AI Assistant also displays its thinking process as it works, which you can expand or collapse once the response is complete. To learn more about Splunk AI Assistant, see About Splunk AI Assistant.

Note: Splunk AI Assistant gives users SPL assistance without compromising customer confidentiality and security. If you choose a third-party hosted LLM (such as Microsoft Azure OpenAI) to power the AI Assistant, your selected third party will process some of the data to provide the services, but your data will not be used to train, fine tune, or improve the third-party model. Third-party models will only be used if your administrator chooses such a model, as discussed in Feature preview: Third-party LLM Usage. Users can opt out of having their data used by Splunk for research and development by configuring the assistant's user settings at any time. See Splunk Protects for full details on data privacy at Splunk.

Find Splunk AI Assistant in the Search app

In order to use the AI Assistant in searches, the Splunk AI Assistant app must be set up and activated. When users who don't have administrator privileges click on the Splunk AI Assistant icon in the search bar, the following screen is displayed on the right side of the Search app indicating that the AI Assistant has not been activated yet:

This image shows the Splunk AI Assistant icon on the right side of the Search bar with text in the panel on the far right of the Search window instructing users to contact their administrator to activate the Splunk AI Assistant.

When administrators click on the Splunk AI Assistant icon, a link in the right side of the Search app takes them to activation information:

This image shows the Splunk AI Assistant icon on the right side of the Search bar with a button in the panel in the lower right corner of the Search window linking administrators to activation documentation, so they can activate the Splunk AI Assistant.