Community Blog
Get the latest updates on the Splunk Community, including member experiences, product education, events, and more!

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

vvalverde
Splunk Employee
Splunk Employee

Another quarter, another wave of innovation. From complex integrations to pushing the limits of what’s possible with Splunk, your technical brilliance drives our ecosystem. Thank you for being the heartbeat of our community—let’s dive into this quarter’s highlights. 

Splunk Developer Day: A Milestone Event 

On May 13, 2026, we hosted our virtual Splunk Developer Day, focusing on the practical tools you need to build, scale, and monetize on the Splunk platform today. If you couldn’t join us live, here are the key takeaways: 

  • Platform Extensibility: Learn how to build scalable, repeatable business outcomes using structured extension points rather than one-off integrations. 
  • Modern TA Tooling: Standardize your workflow with the UCC framework and our new gold-standard self-assessment checklist for reliable data collection. 
  • AI-Enhanced Quality: Speed up development with AI-powered root-cause analysis in AppInspect and use the new Splunkbase app analyzer to optimize your listing metadata. 
  • Monetization: Ready to go to market? Check out our new guide on the developer portal for navigating the path to paid apps on Splunkbase. 

If you missed the live event, you can catch up on all the demos and implementation details via our official event recap blog and the full YouTube event playlist 

Mastering the Agentic Loop: Agents in Apps (Python SDK) 

One of the standout sessions focused on the intersection of automation and intelligence. Michael Szebenyi, Engineering Product Manager at Splunk, teamed up with Guilhem Marchand, Founder & Director of TrackMe Limited, to dive deep into the Splunk SDK for Python Agentic Loop. With the agentic loop built into the Python SDK, apps can now deploy agents directly within the Splunk Platform—whether it’s an assistant panel to guide users or running headless tasks behind the scenes. You can watch their full presentation here. 

Where to start: Add a contained AI chat panel or a read-only background agent to a non-production app to help explain investigations or enrich search results. 

Get started: Splunk Enterprise SDK for Python. 

The Future of AI: App MCP Tools 

Apps are the primary way Splunk insights are packaged for customers, and the Splunk Model Context Protocol (MCP) allows these apps to share insights easily with LLMs for analysis and action. In this session, JD Radadiya, Product Manager for Splunk AI, demonstrated how apps can create App MCP tools from custom REST endpoints and saved searches. These tools are exposed to the Splunk MCP server via a new tools.conf file, which includes a stanza per tool to define the name and description shared with agents and LLMs. Catch the recording of JD’s insightful session at this link. 

Where to start: Choose a useful, safe, and easy-to-describe saved search or REST-backed workflow to package as a callable tool. 

Get started: Add MCP tools to your Splunk app. 

Developer Spotlight: Mika Borner 

We featured Mika Borner, founder of Datapunctum AG, whose journey began by winning Splunk’s first "Apptitude App Challenge." His project evolved into Alert Manager Enterprise, a robust tool that combats alert fatigue with advanced workflow and synchronization capabilities. Mika advises developers to focus on real-world pain points and master Python and React to build impactful solutions. Read his full story in our Spotlight blog and check out his app on Splunkbase

Interested in being our next Developer Spotlight? Let us know by filling out this form! 

Deep Dives: Tech Talk Highlights 

This quarter also featured some fantastic technical deep dives. If you are looking to sharpen your skills, be sure to watch these on-demand Tech Talks: 

Join Us at .conf26! 

The momentum doesn't stop here. We are already gearing up for .conf26 and we want you there with us! It’s the perfect opportunity to connect with fellow developers, learn from experts, and see the latest in Splunk innovation. 

  • Explore the Developer Track: Check out the session catalog to plan your schedule. 
  • Visit the Builder Bar:  Don't forget to stop by the Builder Bar at the Pavilion to get hands-on support and chat with our engineering teams. 

We can’t wait to see what you build next. Keep the conversation going in the forums, share your projects, and continue to challenge the status quo. Happy coding! 

Contributors
Get Updates on the Splunk Community!

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...