Open source, enterprise-ready AI skills for Splunk use cases, built for secure discovery, consistent execution, and production-grade customer workflows.
概览
These skills are experimental. They are not covered by existing Splunk support contracts. Review Support before using them. Skills are agent-facing instructions and tools that help AI agents work with Splunk. They may use Splunk documentation and product capabilities, but they are not product features, product code, or replacements for built-in product experiences. Each skill is self-contained under skills/. This repository uses the skills/ /SKILL.md layout expected by compatible AI coding agents.
README
Splunk Agent Skills
[!WARNING] These skills are experimental. They are not covered by existing Splunk support contracts. Review Support before using them.
Skills are agent-facing instructions and tools that help AI agents work with Splunk. They may use Splunk documentation and product capabilities, but they are not product features, product code, or replacements for built-in product experiences.
Skills
| Skill | Purpose |
|---|---|
alerting-and-notable-workflows |
Give cited, advisory-only readiness guidance for Splunk alerts, scheduled-report actions, Enterprise Security finding/notable and risk workflows, delivery, ownership, escalation, and validation. |
app-and-add-on-lifecycle-advisor |
Give cited, advisory-only guidance for Splunk app and add-on packaging, compatibility, installation, upgrade, validation, migration, and removal. |
custom-visualization-builder |
Scaffold, build, package, and install a custom visualization into Splunk using the dashboard-studio-extension framework. |
dashboard-report-alert-performance-advisor |
Assess dashboard, report, and alert latency, scheduling, timeout, concurrency, refresh, and data-source fan-out evidence without changing Splunk objects or deployments. |
data-model-and-search-acceleration |
Assess Splunk data-model and report-acceleration readiness, summary health, completeness, applicability, validation, and ownership without making changes. |
data-source-onboarding-advisor |
Orchestrate evidence-bound Splunk data-source intake, supported method selection, metadata and event contracts, acceptance, ownership, and exact implementation handoffs without configuring or changing a deployment. |
deployment-server-and-forwarder-fleet-management |
Explain, plan, and diagnose Splunk Enterprise Deployment Server and Agent Management fleet behavior from public documentation and sanitized evidence without changing a deployment. |
field-extraction-and-cim-mapping |
Author, explain, diagnose, and validate Splunk search-time field extractions and Common Information Model mappings from representative evidence without deploying configuration or changing a Splunk environment. |
forwarder-and-data-ingest-doctor |
Diagnose Splunk forwarder and data-ingest paths from sanitized, read-only evidence, isolate the earliest pipeline gap, and prepare a safe next check or provider-owned handoff without changing production. |
hec-setup-and-troubleshooting |
Set up and validate Splunk HTTP Event Collector from current public documentation, diagnose delivery failures from sanitized evidence, and prepare bounded escalation handoffs without changing production systems. |
incident-diagnosis-specialist |
Diagnose post-triage multi-component Splunk incidents from privacy-reviewed packets with aligned evidence, testable hypotheses, bounded confirmation, validation, ownership, and exact specialist handoffs. |
index-and-storage-management-advisor |
Design and assess Splunk indexes, retention, capacity, storage tiers, bucket lifecycle, and SmartStore without applying changes. |
indexer-cluster-health-and-troubleshooting |
Assess Splunk indexer-cluster membership, factors, bucket and bundle state, rolling readiness, multisite behavior, and SmartStore interactions without changing a deployment. |
ingestion-pipeline-design |
Design implementation-ready Splunk ingestion pipelines from known source requirements without configuring, deploying, or mutating them. |
knowledge-object-governance |
Give cited public Splunk knowledge-object governance guidance and assess user-authorized inventory, ownership, permissions, naming, lifecycle, lookup, and search-head comparison evidence without changing a deployment. |
license-and-capacity-planning-advisor |
Separate Splunk Enterprise entitlement lifecycle issues from measured license-capacity demand and produce a minimum-evidence, assumption-bounded, advisory-only plan grounded in current official Splunk documentation. |
report-authoring-specialist |
Define evidence-bounded scheduled and ad hoc Splunk report contracts, readiness findings, acceptance checks, and owner routes without creating, running, changing, scheduling, or sending reports. |
search-and-dashboard-troubleshooter |
Diagnose broken searches, reports, alerts, dashboards, and their dependencies from supplied evidence; isolate the first unsupported functional stage and define read-only validation and exact adjacent ownership without remediation. |
search-head-cluster-health-and-troubleshooting |
Assess Splunk Search Head Cluster captaincy, member health, replication, search availability, KV Store, deployer phases, drift, and rolling readiness without changing a deployment. |
search-performance-optimizer |
Diagnose and improve one existing functional Splunk search from supplied SPL and runtime evidence while preserving semantics and separating query, workload, and platform concerns. |
splunk-cloud-admin-copilot |
Read Splunk Cloud Platform ACS state, assess maintenance or restart readiness without changing it, and execute one explicitly approved IPv4 CIDR add or remove for one feature-specific IP allowlist through the documented public ACS provider. |
splunk-dashboard-converter |
Convert classic Splunk Simple XML dashboards (version 1) into Dashboard Studio (version 2), preserve every SPL query verbatim, and return the Studio JSON definition to the caller. |
splunk-enterprise-administration-advisor |
Read-only Splunk Enterprise administration advisor for routine local user, role, capability, configuration precedence, service ownership, maintenance readiness, and safe validation decisions grounded in current official Splunk documentation and sanitized supplied evidence. |
splunk-health-monitoring-and-diagnostic-collection |
Explain Splunk health-monitoring surfaces, collect the smallest useful evidence, guide privacy-aware diagnostic collection, and turn supplied observations into a bounded diagnostic packet without changing a system. |
splunk-identity-saml-readiness-advisor |
Research current public Splunk sources and use optional existing-auth read-only stack evidence to diagnose identity, SAML, LDAP, role, capability, mapping, login, and access-readiness problems without changing configuration or handling credentials. |
splunk-product-question-navigator |
Research current public Splunk sources to answer general product questions with citations, applicability, and explicit uncertainty or routing. |
splunk-search |
Run bounded, read-only Splunk SPL searches through splunkctl and return compact, evidence-backed results without exposing credentials or flooding context. |
splunk-setup-page-builder |
Build a certification-compliant first-run setup page for a Splunk app or add-on using the configurations REST endpoint and storage/passwords, avoiding the deprecated setup.xml mechanism. |
upgrade-and-security-readiness-router |
Classify Splunk version-change, advisory, vulnerability, compliance, and post-change incident requests and return exact non-mutating handoffs. |
upgrade-and-vulnerability-readiness-advisor |
Assess cited, evidence-labeled Splunk Enterprise and Splunk Cloud version, maintenance, and security-patch readiness without executing the change. |
upgrade-planning-and-execution-readiness |
Build cited, evidence-labeled Splunk Enterprise upgrade plans and Splunk Cloud support-assisted version-change readiness plans without performing or approving an upgrade. |
vulnerability-remediation-and-compliance-readiness |
Assess Splunk vulnerability findings, remediation or exception evidence, compliance readiness, and documented vulnerability-management surfaces without changing a deployment or compliance state. |
Each skill is self-contained under skills/.
Install and use
This repository uses the skills//SKILL.md layout expected by
compatible AI coding agents.
Available skill IDs:
alerting-and-notable-workflowsapp-and-add-on-lifecycle-advisorcustom-visualization-builderdashboard-report-alert-performance-advisordata-model-and-search-accelerationdata-source-onboarding-advisordeployment-server-and-forwarder-fleet-managementfield-extraction-and-cim-mappingforwarder-and-data-ingest-doctorhec-setup-and-troubleshootingincident-diagnosis-specialistindex-and-storage-management-advisorindexer-cluster-health-and-troubleshootingingestion-pipeline-designknowledge-object-governancelicense-and-capacity-planning-advisorreport-authoring-specialistsearch-and-dashboard-troubleshootersearch-head-cluster-health-and-troubleshootingsearch-performance-optimizersplunk-cloud-admin-copilotsplunk-dashboard-convertersplunk-enterprise-administration-advisorsplunk-health-monitoring-and-diagnostic-collectionsplunk-identity-saml-readiness-advisorsplunk-product-question-navigatorsplunk-searchsplunk-setup-page-builderupgrade-and-security-readiness-routerupgrade-and-vulnerability-readiness-advisorupgrade-planning-and-execution-readinessvulnerability-remediation-and-compliance-readiness
List the skills before installing:
npx skills add splunk/splunk-agent-skills --list
Run one of these commands from a project root to copy all 32 skills for the selected agent:
npx skills add splunk/splunk-agent-skills --skill '*' --agent claude-code --copy --yes
npx skills add splunk/splunk-agent-skills --skill '*' --agent codex --copy --yes
npx skills add splunk/splunk-agent-skills --skill '*' --agent cursor --copy --yes
npx skills add splunk/splunk-agent-skills --skill '*' --agent github-copilot --copy --yes
npx skills add splunk/splunk-agent-skills --skill '*' --agent gemini-cli --copy --yes
npx skills add splunk/splunk-agent-skills --skill '*' --agent opencode --copy --yes
Project scope is the default. Add --global to install into the selected
agent’s user-level skills directory instead. To copy only one skill, name it
with --skill:
npx skills add splunk/splunk-agent-skills --skill splunk-search --agent codex --copy --yes
For a manual installation, clone or download this repository and copy the
desired directory from skills/ into the skills directory configured for the
agent. Read the selected SKILL.md before use; it defines the prerequisites,
workflow, and safety boundaries for that skill.
The skills CLI installs skill directories; it does not install external
executables. The splunk-cloud-admin-copilot skill requires the separately
installed acs CLI, preconfigured for the exact deployment and environment.
The skill never runs login or setup commands.
splunkctl is a separate, optional dependency for this repository and the preferred path for supported Splunk API operations. Install it from https://github.com/splunk/splunkctl when desired. The splunk-search skill’s live SPL execution path requires splunkctl; SPL authoring and explanation remain available without it.
Then use the installed skill through your agent according to its normal skill invocation workflow.
Policies
推荐工具
换一个关键词,或者移除筛选条件。
安装
npx skillfish add splunk/splunk-agent-skills