What's new in the AI Toolkit

Here's what's new in each version of the AI Toolkit.

Version 6.0.2

AI Toolkit version 6.0.2 requires version 4.3.4 of the PSC add-on. This version of PSC is packaged with Python version 3.13.

Note: Make sure you use compatible versions of the AI Toolkit app and PSC add-on. See Splunk AI Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

Splunk AI Toolkit version 6.0.2 is a maintenance release that addresses some issues and implements minor enhancements.

Version 6.0.1

AI Toolkit version 6.0.1 requires version 4.3.4 of the PSC add-on. This version of PSC is packaged with Python version 3.13.

Note: Make sure you use compatible versions of the AI Toolkit app and PSC add-on. See Splunk AI Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

Splunk AI Toolkit version 6.0.1 is a maintenance release that addresses some issues and implements minor enhancements.

Version 6.0.0

AI Toolkit version 6.0.0 requires version 4.3.2 or 4.3.3 of the PSC add-on. This version of PSC is packaged with Python version 3.13.

Note: Make sure you use compatible versions of the AI Toolkit app and PSC add-on. See Splunk AI Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

  • Version 6.0.0 introduces Agent Launchpad to the AI Toolkit. Agent Launchpad can help you build, run, review, and manage operational agents directly in Splunk. For more information see AI Toolkit Agent Launchpad.

  • Changes to have been made to the preview of the Cisco Deep Time Series Model (CDTSM). For more information see Feature preview: Cisco Deep Time Series Model.

  • Changes have been made to what anonymized data the AI Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For more information see Share data in the AI Toolkit.

Version 5.7.4

AI Toolkit version 5.7.4 requires version 4.3.2 of the PSC add-on. This version of PSC is packaged with Python version 3.13.

Note: Make sure you use compatible versions of the AI Toolkit app and PSC add-on. See Splunk AI Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

  • Version 5.7.4 introduces a Vertex AI endpoint integration feature. This feature lets AI Toolkit users invoke Google Cloud Platform (GCP) Vertex AI-hosted online prediction endpoints directly from Splunk searches, dashboards, and alerts See Upload and inference a pre-trained Vertex AI model in the AI Toolkit.

  • Enhancements have been made to the Cisco Deep Time Series Model (CDTSM) preview:

    • You can now include a by parameter when using the CDTSM for forecasting and for anomaly detection on that forecast.

    • You can now include a fill_null parameter when using the CDTSM for forecasting and for anomaly detection on that forecast.

    • The minimal requirement for 60 datapoints has been removed.

    • For more information see Feature preview: Cisco Deep Time Series Model

  • The main navigation bar and menu options for the AI Toolkit has been updated.

  • Changes have been made to what anonymized data the AI Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For more information see Share data in the AI Toolkit.

Version 5.7.3

AI Toolkit version 5.7.3 requires version 4.3.1 of the PSC add-on. This version of PSC is packaged with Python version 3.13.

Note: Make sure you use compatible versions of the AI Toolkit app and PSC add-on. See Splunk AI Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

Splunk AI Toolkit version 5.7.3 provides enhancements to the Cisco Deep Time Series Model (CDTSM) preview:

  • You can now add anomaly detection to your time series forecast. See Feature preview: Cisco Deep Time Series Model.

  • A new Visualization is available of Anomaly Detection Chart.

  • The CDTSM preview is no longer limited to Splunk Cloud users and is now available for on-premises users.

  • There are 2 new Showcase examples for the Cisco Deep Time Series Model (CDTSM) preview. See AI Toolkit Showcase.

Version 5.6.4

AI Toolkit version 5.6.4 requires version 3.2.3, 3.2.4, 3.2.5, 4.2.3, or 4.2.4 of the PSC add-on, and version 3.9 or higher of Python.

Note: Make sure you use compatible versions of the AI Toolkit app and PSC add-on, see Splunk AI Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

Version 5.6.3

AI Toolkit version 5.6.3 requires version 3.2.3, 3.2.4, 3.2.5, 4.2.3, or 4.2.4 of the PSC add-on, and version 3.9 or higher of Python.

Note: Make sure you use compatible versions of the AI Toolkit app and PSC add-on, see Splunk AI Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

AI Toolkit version 5.6.3 is a maintenance and patch release:

  • This version introduces an updated name for this app. The Splunk Machine Learning Toolkit (MLTK) is being renamed to the AI Toolkit.

Version 5.6.1

MLTK version 5.6.1 requires version 3.2.3, 3.2.4, 3.2.5, 4.2.3, or 4.2.4 of the PSC add-on, and version 3.9 or higher of Python.

Note: Make sure you use compatible versions of the MLTK app and PSC add-on, see Splunk Machine Learning Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

MLTK version 5.6.1 is a maintenance and patch release:

  • This version addresses an issue when a symbol is in the model name on KV store configuration. See Fixed issues.
  • This version removes the mltk_aicommander.csv dataset because it gets flagged as a false positive from virus scanners.

Version 5.6.0

MLTK version 5.6.0 requires version 3.2.3 or 4.2.3 of the PSC add-on, and version 3.9 or higher of Python.

Note: Make sure you use compatible versions of the MLTK app and PSC add-on, see Splunk Machine Learning Toolkit version dependencies.
CAUTION: When upgrading PSC ensure that you remove previous versions of PSC and perform a clean install.

Features and improvements

  • Large Language Model (LLM) connectors introduced for OpenAI, Anthropic, Azure hosted OpenAI, Groq, Gemini, AWS Bedrock, and Ollama. To learn more see the Connection Management page.
  • A new search command of ai, that allows users to send data from Splunk to an externally hosted LLM and present the results back in Splunk. To learn more see About the ai command.
    • New Showcase examples are available that demonstrate the ai command in action. See LLM Integrations.
    • Note: MLTK version 5.6.0 includes 2 new sample datasets that are helpful for exploring the new ai command. Some virus scanners might flag the provided samples of malicious payloads in mltk_ai_commander_dataset.csv as malware. This is a false positive you can safely ignore.
  • Enhancements to the ONNX apply feature. Users can now output multiple variables instead of single variables.
  • An Alerts tab is now present in MLTK so that users can view and manage alerts created in MLTK.
  • Changes have been made to what anonymized data the Machine Learning Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For details, see Share data in the Machine Learning Toolkit.
  • Patches for security vulnerabilities, including an upgrade of the OpenSSL library in PSC versions 3.2.3 and 4.2.3.

Version 5.5.0

MLTK version 5.5.0 requires version 3.2.2 or 4.2.2 of the PSC add-on, and version 3.9 or higher of Python.

Note: Make sure you use compatible versions of the MLTK app and PSC add-on, see Splunk Machine Learning Toolkit version dependencies.

Features and improvements

  • Enhancements to the DensityFunction algorithm. The new supervise_split_by parameter can be set to true or false.
    • When set to true, the fields entered in the by clause are used by a decision tree algorithm to automatically generate groups in the dataset.
  • Changes have been made to what anonymized data the Splunk Machine Learning Toolkit as deployed on Splunk Enterprise sends Splunk Inc. For details, see Share data in the Machine Learning Toolkit.
  • Patches for security vulnerabilities, including an upgrade of the OpenSSL library in PSC versions 3.2.2 and 4.2.2.

Version 5.3.3

Features and improvements

  • In version 5.3.3, the StateSpaceForecast algorithm scoring metric values are based on the holdback period data.
  • The Classic tab of the MLTK app is removed in version 5.3.3. The features of the Classic tab are available in the Experiments tab.
  • Deprecated support of Internet Explorer.
  • Version 4.0.0 of the PSC add-on release. This version provides updates and adds several libraries in the package. In particular, Pytorch, cpuonly, transformers, onnxruntime, pydantic, and watchdog.

Note: Version 4.0.0 of the PSC add-on is only available for MLTK version 5.3.3. Users upgrading to version 4.0.0 of the PSC add-on must follow some additional installation steps. See Install version 4.0.0 of the Python for Scientific Computing add-on.

CAUTION: The build size of PSC version 4.0.0 might exceed the default value of max_upload_size which can prevent you from installing the package using the "Install app from file" option under Manage Apps. To install PSC 4.0.0 you must create a web.conf file , update max_upload_size to a higher value, and restart Splunk from your terminal.

Version 5.3.1

Features and improvements

  • The new parameter of exclude_dist is available for the Density Function algorithm. Use this parameter when dist=auto to exclude a minimum of 1 and a maximum of 3 of the available distribution types (norm, expon, gaussian_kde, beta). For more information, see Density Function.
  • Version 3.0.2 of the PSC add-on is now available. This version of PSC is compatible with both version 5.3.0 and 5.3.1 of the MLTK app. This PSC version does not include any new features, and addresses bug fixes only.
  • The streaming_apply feature was deprecated in version 5.0.0 of MLTK, and has now been removed from the app. This feature has been removed to prevent bundle replication performance issues on index clusters.

CAUTION: Users upgrading to MLTK version 5.3.0 or higher must retrain models created in lower versions of MLTK.

Version 5.3.0

Features and improvements

This version of MLTK requires version 3.0.0 of the Python for Scientific Computing (PSC) add-on. This release of PSC brings updates to several libraries in the package including Numpy, Scipy, scikit-learn, Statsmodels, and Networkx. 

CAUTION: Users upgrading to MLTK version 5.3.0 must retrain models created in lower versions of MLTK.

Version 5.3.0

Features and improvements

This version of MLTK requires version 3.0.0 of the Python for Scientific Computing (PSC) add-on. This release of PSC brings updates to several libraries in the package including Numpy, Scipy, scikit-learn, Statsmodels, and Networkx. 

CAUTION: Users upgrading to MLTK version 5.3.0 must retrain models created in lower versions of MLTK.