Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

Developer Spotlight with Eduard Lekanne

vvalverde
Splunk Employee
Splunk Employee

From Network Engineer to Building Agentic AI for Splunk

headshot-Eduard-Lekanne.pngEduard Lekanne has been architecting technology solutions for over 30 years, beginning his career as a network engineer in 1994. His deep curiosity about how applications perform across networks led him from early log analysis with Perl and Python to discovering the power of Splunk Enterprise—a turning point that fundamentally transformed his approach to data analysis.

Since going independent in 2009, Eduard has earned Splunk’s highest certifications and specialized in IT Service Intelligence (ITSI). He has been publishing Splunk apps since 2019. Today he builds and sells Adjutant AI through his own company, ITMIP BV, under the brand The Dutch Data Difference, designed for organizations in government, finance, healthcare, and critical infrastructure that cannot allow their data to leave their own environment.

Building Smarter Splunk Apps with AI

Eduard’s journey with Splunk began in 2014 at Rabobank, where he built deep expertise in both Splunk Enterprise and Splunk Cloud Platform. Today, he develops apps that integrate seamlessly with IT Service Intelligence (ITSI), Enterprise Security, and the Machine Learning Toolkit.

The Dutch Data Difference.pngOne of his standout projects is Adjutant AI, previously released as AI Workbench, a native agentic AI platform that runs entirely inside the customer’s own Splunk deployment. First revealed publicly at Splunk GO in Hilversum and now available on Splunkbase, it demonstrates how agentic AI can automate real operational workflows, from ITSI root cause analysis and service investigations to threat analysis, forecasting, and anomaly detection, without any data leaving the customer's environment. Eduard’s work reflects a firm conviction that AI in regulated environments has to be governed, auditable, and owned by the customer.

Adjutant AI: Agentic AI That Stays Inside Your Environment

Adjutant AI.png

 

Adjutant AI is a native Splunk app that runs entirely inside the customer’s own deployment. No data leaves the environment, the customer chooses the model, and every action an agent takes is governed by existing Splunk roles and recorded as an auditable event. It generates validated searches, dashboards, alerts, and machine learning workflows from natural language, and it can also execute multi-step workflows autonomously, producing results that reviewers can inspect, validate, and reproduce. Building that required designing AI agents that operate entirely within Splunk's native security model, respecting RBAC, audit logging, and customer-selected LLMs.

Built for both security and IT operations teams, Adjutant AI streamlines critical work such as ITSI root cause analysis, service investigations, threat investigations, phishing triage, MITRE ATT&CK analysis, and anomaly detection. Unlike generic AI tools, it validates results against the user’s actual Splunk deployment, so responses are accurate, grounded in real data, and traceable back to the search that produced them.

The inspiration for Adjutant AI came from years of hands-on experience. Eduard recognized that many customer challenges were rooted in data complexity, driving him to build a platform that makes Splunk more approachable while ensuring customers retain full control over their data, models, and governance. It works with the models and toolkits an organization already trusts, including the Splunk AI Toolkit and Cisco’s Deep Time Series Model, rather than tying anyone to a single provider.

Building this as a founder has been both rewarding and demanding. Beyond writing code, Eduard owns the entire product lifecycle, from design and testing to marketing and customer support. His goal remains clear: helping organizations extract more value from Splunk while keeping ownership of their data, their roles, and their model.

Eduard’s Advice for New Splunk App Developers

For developers just starting their journey, Eduard’s advice is simple: Build something you believe in. Splunk Enterprise is a powerful platform with endless opportunities for innovation, and every developer brings a unique perspective that can solve real-world problems.

He recommends taking full advantage of Splunk’s built-in capabilities, such as authentication, role-based access control (RBAC), KVStore, and secure credential storage. In addition, designing with Splunk Cloud compatibility in mind from the start ensures your app reaches the widest possible audience.

Just as importantly, Eduard emphasizes building trust. "Be transparent when data is incomplete, test with real-world datasets, and run AppInspect early and often throughout development," he suggests. His final piece of advice? Don’t be afraid to think creatively. Innovation starts with curiosity and the confidence to turn ideas into reality.

Life Beyond Code: Finding Balance in Nature

When he isn’t developing apps, Eduard finds balance in the great outdoors. Living in a wooded area, he is constantly working on new projects, whether that's gardening, wood carving, painting, or maintaining his property.

He also cares for three Friesian horses, a hands-on responsibility that keeps him busy year-round. For Eduard, working with his hands provides the perfect balance to the digital world, helping him recharge, stay grounded, and return to his development work with a fresh perspective.

We’ve added a new "AI Champion" category to the series! Want to be the next one featured?

Nominate yourself or a peer here: Submit your nomination

Keep the good stuff coming. Here’s how to subscribe to this blog — and stay in the loop on the topics that matter to you.  

Contributors
Get Updates on the Splunk Community!

Catalog Is Now Generally Available on Splunk Cloud Platform

A Unified View of Your Data  Security logs, application events, business data, and historical telemetry often ...

Developer Spotlight with Eduard Lekanne

From Network Engineer to Building Agentic AI for Splunk Eduard Lekanne has been architecting technology ...

From Data Landing to Insight

Search Across More of Your Data Ecosystem The data you need may live in Splunk, high-volume machine data, ...