What's new in the AI Toolkit
Here's what's new in each version of the AI Toolkit.
Version 6.0.2
AI Toolkit version 6.0.2 requires version 4.3.4 of the PSC add-on. This version of PSC is packaged with Python version 3.13.
Features and improvements
Splunk AI Toolkit version 6.0.2 is a maintenance release that addresses some issues and implements minor enhancements.
Version 6.0.1
AI Toolkit version 6.0.1 requires version 4.3.4 of the PSC add-on. This version of PSC is packaged with Python version 3.13.
Features and improvements
Splunk AI Toolkit version 6.0.1 is a maintenance release that addresses some issues and implements minor enhancements.
Version 6.0.0
AI Toolkit version 6.0.0 requires version 4.3.2 or 4.3.3 of the PSC add-on. This version of PSC is packaged with Python version 3.13.
Features and improvements
-
Version 6.0.0 introduces Agent Launchpad to the AI Toolkit. Agent Launchpad can help you build, run, review, and manage operational agents directly in Splunk. For more information see AI Toolkit Agent Launchpad.
-
Changes to have been made to the preview of the Cisco Deep Time Series Model (CDTSM). For more information see Feature preview: Cisco Deep Time Series Model.
-
Changes have been made to what anonymized data the AI Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For more information see Share data in the AI Toolkit.
Version 5.7.4
AI Toolkit version 5.7.4 requires version 4.3.2 of the PSC add-on. This version of PSC is packaged with Python version 3.13.
Features and improvements
-
Version 5.7.4 introduces a Vertex AI endpoint integration feature. This feature lets AI Toolkit users invoke Google Cloud Platform (GCP) Vertex AI-hosted online prediction endpoints directly from Splunk searches, dashboards, and alerts See Upload and inference a pre-trained Vertex AI model in the AI Toolkit.
-
Enhancements have been made to the Cisco Deep Time Series Model (CDTSM) preview:
-
You can now include a
byparameter when using the CDTSM for forecasting and for anomaly detection on that forecast. -
You can now include a
fill_nullparameter when using the CDTSM for forecasting and for anomaly detection on that forecast. -
The minimal requirement for 60 datapoints has been removed.
-
For more information see Feature preview: Cisco Deep Time Series Model
-
-
The main navigation bar and menu options for the AI Toolkit has been updated.
-
Changes have been made to what anonymized data the AI Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For more information see Share data in the AI Toolkit.
Version 5.7.3
AI Toolkit version 5.7.3 requires version 4.3.1 of the PSC add-on. This version of PSC is packaged with Python version 3.13.
Features and improvements
Splunk AI Toolkit version 5.7.3 provides enhancements to the Cisco Deep Time Series Model (CDTSM) preview:
-
You can now add anomaly detection to your time series forecast. See Feature preview: Cisco Deep Time Series Model.
-
A new Visualization is available of Anomaly Detection Chart.
-
The CDTSM preview is no longer limited to Splunk Cloud users and is now available for on-premises users.
-
There are 2 new Showcase examples for the Cisco Deep Time Series Model (CDTSM) preview. See AI Toolkit Showcase.
Version 5.6.4
AI Toolkit version 5.6.4 requires version 3.2.3, 3.2.4, 3.2.5, 4.2.3, or 4.2.4 of the PSC add-on, and version 3.9 or higher of Python.
Features and improvements
- Version 5.6.4 introduces a SageMaker Inference Endpoint Integration feature. This feature lets AI Toolkit users invoke their own AWS SageMaker–hosted models directly from Splunk platform searches, dashboards, and alerts. See Upload and inference pre-trained AWS SageMaker models in the AI Toolkit.
- Changes have been made to what anonymized data the AI Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For details, see Share data in the AI Toolkit.
Version 5.6.3
AI Toolkit version 5.6.3 requires version 3.2.3, 3.2.4, 3.2.5, 4.2.3, or 4.2.4 of the PSC add-on, and version 3.9 or higher of Python.
Features and improvements
AI Toolkit version 5.6.3 is a maintenance and patch release:
- This version introduces an updated name for this app. The Splunk Machine Learning Toolkit (MLTK) is being renamed to the AI Toolkit.
Version 5.6.1
MLTK version 5.6.1 requires version 3.2.3, 3.2.4, 3.2.5, 4.2.3, or 4.2.4 of the PSC add-on, and version 3.9 or higher of Python.
Features and improvements
MLTK version 5.6.1 is a maintenance and patch release:
- This version addresses an issue when a symbol is in the model name on KV store configuration. See Fixed issues.
- This version removes the
mltk_aicommander.csvdataset because it gets flagged as a false positive from virus scanners.
Version 5.6.0
MLTK version 5.6.0 requires version 3.2.3 or 4.2.3 of the PSC add-on, and version 3.9 or higher of Python.
Features and improvements
- Large Language Model (LLM) connectors introduced for OpenAI, Anthropic, Azure hosted OpenAI, Groq, Gemini, AWS Bedrock, and Ollama. To learn more see the Connection Management page.
- A new search command of
ai, that allows users to send data from Splunk to an externally hosted LLM and present the results back in Splunk. To learn more see About the ai command.- New Showcase examples are available that demonstrate the
aicommand in action. See LLM Integrations. -
Note: MLTK version 5.6.0 includes 2 new sample datasets that are helpful for exploring the new
aicommand. Some virus scanners might flag the provided samples of malicious payloads inmltk_ai_commander_dataset.csvas malware. This is a false positive you can safely ignore.
- New Showcase examples are available that demonstrate the
- Enhancements to the ONNX apply feature. Users can now output multiple variables instead of single variables.
- An Alerts tab is now present in MLTK so that users can view and manage alerts created in MLTK.
- Changes have been made to what anonymized data the Machine Learning Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For details, see Share data in the Machine Learning Toolkit.
- Patches for security vulnerabilities, including an upgrade of the OpenSSL library in PSC versions 3.2.3 and 4.2.3.
Version 5.5.0
MLTK version 5.5.0 requires version 3.2.2 or 4.2.2 of the PSC add-on, and version 3.9 or higher of Python.
Features and improvements
- Enhancements to the DensityFunction algorithm. The new
supervise_split_byparameter can be set to true or false.- When set to true, the fields entered in the
byclause are used by a decision tree algorithm to automatically generate groups in the dataset.
- When set to true, the fields entered in the
- Changes have been made to what anonymized data the Splunk Machine Learning Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For details, see Share data in the Machine Learning Toolkit.
- Patches for security vulnerabilities, including an upgrade of the OpenSSL library in PSC versions 3.2.2 and 4.2.2.
Version 5.3.3
Features and improvements
- In version 5.3.3, the StateSpaceForecast algorithm scoring metric values are based on the
holdbackperiod data. - The Classic tab of the MLTK app is removed in version 5.3.3. The features of the Classic tab are available in the Experiments tab.
- Deprecated support of Internet Explorer.
- Version 4.0.0 of the PSC add-on release. This version provides updates and adds several libraries in the package. In particular, Pytorch, cpuonly, transformers, onnxruntime, pydantic, and watchdog.
max_upload_size which can prevent you from installing the package using the "Install app from file" option under Manage Apps. To install PSC 4.0.0 you must create a web.conf file , update max_upload_size to a higher value, and restart Splunk from your terminal.
Version 5.3.1
Features and improvements
- The new parameter of
exclude_distis available for the Density Function algorithm. Use this parameter when dist=auto to exclude a minimum of 1 and a maximum of 3 of the available distribution types (norm, expon, gaussian_kde, beta). For more information, see Density Function. - Version 3.0.2 of the PSC add-on is now available. This version of PSC is compatible with both version 5.3.0 and 5.3.1 of the MLTK app. This PSC version does not include any new features, and addresses bug fixes only.
- The
streaming_applyfeature was deprecated in version 5.0.0 of MLTK, and has now been removed from the app. This feature has been removed to prevent bundle replication performance issues on index clusters.
Version 5.3.0
Features and improvements
This version of MLTK requires version 3.0.0 of the Python for Scientific Computing (PSC) add-on. This release of PSC brings updates to several libraries in the package including Numpy, Scipy, scikit-learn, Statsmodels, and Networkx.
Version 5.3.0
Features and improvements
This version of MLTK requires version 3.0.0 of the Python for Scientific Computing (PSC) add-on. This release of PSC brings updates to several libraries in the package including Numpy, Scipy, scikit-learn, Statsmodels, and Networkx.