Splunk Tech Talks
Deep-dives for technical practitioners.

Get Operational Insights Quickly with Natural Language on the Splunk Platform

DayaSCanales
Splunk Employee
Splunk Employee

Screenshot 2025-08-04 091702.png

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With built-in AI capabilities, the Splunk Platform makes it easier than ever to extract operational insights and boost productivity—no matter your level of expertise with Splunk.

Join experts Jeff Wiedemann and Mohit Verma for an engaging session where you’ll see live demos showcasing how AI can simplify your workflows and enhance decision-making. Discover how Splunk integrates AI in a safe, compliant, and responsible way, ensuring your company’s data remains secure while you leverage cutting-edge technology.

Whether you’re just getting started or looking to optimize your Splunk environment, this session will provide the tools and knowledge you need to take your productivity to the next level.

Watch the Tech Talk here:


Topics Covered:

  • Obstacles in going from Machine Data > Insights
  • Artificial Real Intelligence
  • AI Assistant for SPL
  • What's new?
  • Technical deep dive
  • Quality & Accuracy
  • Hold breath for a surprise
  • Q&A

 

DayaSCanales
Splunk Employee
Splunk Employee

Here are a few top of mind questions from the live Tech Talk

 

Q. Is this only available for Splunk Cloud, or is it available for a Splunk Enterprise deployment, and if so, is there a minimum version level , for example: 9.4.x ?

A. As long as you are on a version in which you can install a Splunk base application, it will work.

DayaSCanales_0-1754511782471.png

Q. Is the AI assistant available for Splunk On Prem as well?

A. Yes, with the v1.3.0 release Splunk Enterprise customers can use AI Assistant.

DayaSCanales_3-1754511782472.png

Q. How to navigate to NLP section Splunk SaaS?

A. The question how to access the AI Assistant in Splunk Cloud, you can install the AI Assistant for SPL application on your deployment and access it through the application. At .conf the assistant will be available inside the Search & Reporting app for even easier access.

DayaSCanales_2-1754511782472.png

Q. A security concern would be that other's are know the naming convention of my environment and that information is protected because essentially that is enumeration. How is that protected and how is that specifically unavailable to others?

A. All the personalization metadata (including the naming convention of the environment) is only used for inferencing. In other words, the only place where this data is used to improve the response quality for users of your deployment. None of this data is fed back into the model in any way.

DayaSCanales_5-1754511782473.png

Q. These AI assistant capabilities be available through APIs?

A. Yes,  not only as APIs, but they will also be available in the MCP server, very shortly. So yeah, stay tuned for that update.

DayaSCanales_6-1754511782474.png

Q. Can MCP be used for the on Prem installation

A. It is available for Splunk Cloud customers today, support for Enterprise customers is coming very shortly.

DayaSCanales_7-1754511782474.png

Q. Are the user prompts available in the internal logs?

A. If you are talking about the chat history in the AI Assistant, they are currently not present in internal logs but I expect it to be there in the next release.

DayaSCanales_8-1754511782475.png

Q. What safeguards are in place to prevent exposing our proprietary data?

A. Splunk's AI Assistant for SPL employs several safeguards to protect proprietary data: it processes all inferences within Splunk Cloud services, meaning your actual data never leaves Splunk's "four walls" or goes to third-party AI providers. For personalization, it only collects metadata (like index names, field names, and search queries) about the shape of your data, not the sensitive content itself, and this metadata sharing is an opt-in feature with configurable controls. Additionally, the system honors existing Role-Based Access Control (RBAC) and includes guardrail checks to prevent prompt injection and ensure secure interactions.

DayaSCanales_14-1754511782478.png

Q. Here is a good lantern article for the use-cases for AI Assistant for SPL:

A. Implementing key use cases for the Splunk AI Assistant for SPL.

DayaSCanales_1-1754511782471.png

Q. Are there currently no plans to charge for MCP like SAIA?

A. No plans to charge at the moment or in the near future.

DayaSCanales_1-1754511782471.png

Q. Do the Splunk Admins, have the ability to add to the prompt engineering rules?

A. Not at the moment but there are a couple approaches to it, those examples are in the recording.

DayaSCanales_1-1754511782471.png

Q. Is it available for Splunk Cloud on GCP?

A. Not at the moment, it is coming to Azure regions around conf timeframe and GCP will be next.

DayaSCanales_4-1754511782473.png

Contributors
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...