Guys need help,
We have successfully installed the Splunk AI Assistant application on our Search Head. However, we are still encountering the following alerts during initialization:
What is confusing is that the application appears to work normally when installed on the Heavy Forwarder environment, while the same setup on the Search Head continues to show these messages.
Could you please help clarify:
For reference, we have attached a screenshot of the issue observed on the Search Head & Heavy Forwarder.
Search Head :
Heavy Forwarder :
Hello,
It seems it requires a connection to Splunk Cloud:
You do not need to be a Splunk Cloud customer in the sense of hosting your Splunk environment in Splunk Cloud, but you do need Splunk’s cloud-connected AI service and activation.
You should check this with your Splunk Account Sales/Engineer.
Best Regards,
Edoardo
Hi @Alkern Could you pls suggest your
1) Splunk on-prim search head version
2) Splunk AI Assistant version
3) Are you using Splunk Trial license?
Thank you for your assistance on the previous post.
Our current environment details are as follows:
- Splunk Enterprise Version: 10.0.2
- Splunk AI Assistant (SAIA) Version: 2.0.0
- Deployment Type: Splunk Enterprise Security On-Prem
We are not using a Splunk trial license.
Hi @Alkern
As per the documentation, Splunk AI assistant is supported on Splunk Enterprise Security(OnPrim).
Maybe pls check the audit logs:
index=_audit sourcetype=splunk_ai_assistant_chat_log
OR
index=_audit sourcetype=splunk_ai*As it says "Failed during initial setup. Please contact Splunk Support", I think it is better to contact the Splunk Support.