AI Workbench

Splunk Community

AI Workbench

AI Workbench
AI Workbench is a generative workspace for Splunk. Not a chatbot bolted onto search but a real workbench, where you investigate, analyse and build using tools that understand Splunk natively. Ask in plain English. Get back validated SPL searches, Simple XML dashboards, alerts, lookups, reports and Splunk AI Toolkit (MLTK) machine-learning pipelines. Every artefact is run for real before it is saved, and every artefact is a normal Splunk knowledge object you can find again in Splunk's own UI. The depth is the difference. Where a generic MCP-only assistant can talk to Splunk through one broad door, AI Workbench ships with fine-grained, Splunk-aware tools across Core, Enterprise Security, ITSI, TrackMe and the AI Toolkit — roughly fifty of them, each scoped to one job a Splunk admin actually does. The LLM picks the right tool for the question, runs it under your existing Splunk ACLs, and shows its work. Want to extend it further? Add your own HTTP tools or register any MCP server in the Tools tab — they appear alongside the built-ins. Two audiences benefit immediately. Splunk users who know what they want but find SPL foreign get production-quality searches and dashboards generated, validated panel-by-panel, and saved as named objects. Splunk users who bounce off MLTK because choosing an algorithm, tuning thresholds and proving a model works is a Saturday's worth of homework get an outlier detector, forecaster, classifier or clusterer built end-to-end, with a companion dashboard that proves the model is doing something sensible. Bring your own LLM. Eight providers supported: Anthropic, OpenAI, Azure OpenAI, Groq, Google Gemini, AWS Bedrock, Ollama (local, fully offline) and OpenRouter. Browser-direct for speed, or Splunk-server-side proxy mode so API keys never leave the search head. Streaming where the provider supports it. Bring your own corporate IAM — WebEAM.Next, Ping, Okta, AzureAD, internal SAML — via a customer-supplied Python hook that mints fresh auth headers per request. Multi-tenant by design. Organisations and Business Units scope templates, LLM configurations and tool availability. Disable alert creation for a BU that uses a separate alerting platform. Restrict an MLTK-heavy template to users who actually have the AI Toolkit installed. Run one Splunk environment for many teams or many customers without them seeing each other. See the cost. Tokens and Costs breaks spend down by App, User, Model, Provider, Organisation, Business Unit or LLM configuration — over time, side-by-side, with real per-model pricing. Free, Professional, Enterprise and MSP licence tiers, activated self-serve from the License tab, air-gap-friendly.
1 topic and 0 replies mentioned AI Workbench in
Latest Topics
Latest Replies
No posts to display.
Top Topics
My Topics
No posts to display.