Use Splunk AI Assistant for SPL in the Search app
Splunk AI Assistant for SPL is an optional generative AI feature in Splunk Web that helps users write, interpret, and optimize SPL searches. The assistant is displayed on the right side of the search bar.
Splunk AI Assistant for SPL is optional generative AI-powered assistance that provides bi-directional translation between natural language (NL) and Splunk Search Processing Language (SPL) to help users learn how to write, understand, interpret, and optimize SPL searches. More advanced users can use Splunk AI Assistant for SPL to make their searches more efficient and get detailed explanations of what their SPL searches are doing. To learn more about Splunk AI Assistant for SPL, see About Splunk AI Assistant for SPL.
Find Splunk AI Assistant for SPL in the Search app
In order to use the AI Assistant in searches, the Splunk AI Assistant for SPL app must be set up and activated. When users who don't have administrator privileges click on the Splunk AI Assistant for SPL icon in the search bar, the following screen is displayed on the right side of the Search app indicating that the AI Assistant has not been activated yet:
When administrators click on the Splunk AI Assistant for SPL icon, a link in the right side of the Search app takes them to activation information:
Activate Splunk AI Assistant for SPL in the Search app
Splunk AI Assistant for SPL is an optional generative AI feature in Splunk Web that helps users write and interpret SPL searches. The assistant is displayed on the right side of the search bar.
Before you can use Splunk AI Assistant for SPL in your searches in Splunk Web, your Splunk administrator must activate the application by following these steps.
Turn off the sparkle icon for Splunk AI Assistant for SPL
Splunk platform deployments that aren't ready to use the Splunk AI Assistant for SPL yet can turn off the AI sparkle icon from the Search bar in the Search app.
- Have the permissions to edit configuration files. Only users with file system access, such as system administrators, can edit configuration files.
- Know how to edit configuration files. Review the steps in How to edit a configuration file in the Splunk Enterprise Admin Manual.
- Decide which directory to store configuration file changes in. There can be configuration files with the same name in your default, local, and app directories. See Where you can place (or find) your modified configuration files in the Splunk Enterprise Admin Manual.
- Open the local web-features.conf file at $SPLUNK_HOME/etc/system/local.
- In the
[feature:search_ai_assistant]stanza, setenable_search_ai_assistant = false.- If you're using Splunk Enterprise in a distributed search deployment, you must set
enable_search_ai_assistant=falsein the web-features.conf file on all search heads.
- If you're using Splunk Enterprise in a distributed search deployment, you must set
- Restart Splunk Enterprise, so the change to the configuration file takes effect.
- To make the AI sparkle icon and its corresponding tooltip reappear in the Search bar, remove
enable_search_ai_assistant = falsefrom the web-features.conf file to return the setting to its default.
- To make the AI sparkle icon and its corresponding tooltip reappear in the Search bar, remove
The Splunk AI Assistant for SPL sparkle icon and its corresponding tooltip no longer appear in the Search app.
To make the AI sparkle icon and its corresponding tooltip reappear in the Search bar, remove enable_search_ai_assistant = false from the web-features.conf file to return the setting to its default.