Use Splunk AI Assistant in the Search app
Splunk AI Assistant is an optional generative AI feature in Splunk Web that helps users write, interpret, and optimize SPL searches. The assistant is displayed on the right side of the search bar.
Splunk AI Assistant is an optional generative AI assistant that helps users write, understand, explain, and optimize SPL and SPL2 searches using natural language. It brings the latest AI agentic capabilities directly into the Search & Reporting workflow, and includes SPL2 search authoring for federated searches third-party data stores and Machine Data Lake data sources.
When the AI Assistant needs to use a tool, such as running a search, it asks for your approval before proceeding. You can approve or deny each tool call. The AI Assistant also displays its thinking process as it works, which you can expand or collapse once the response is complete. To learn more about Splunk AI Assistant, see About Splunk AI Assistant and Use Splunk AI Assistant for federated searches.
Find Splunk AI Assistant in the Search app
In order to use the AI Assistant in searches, the Splunk AI Assistant app must be set up and activated. When users who don't have administrator privileges click on the Splunk AI Assistant icon in the search bar, the following screen is displayed on the right side of the Search app indicating that the AI Assistant has not been activated yet:
When administrators click on the Splunk AI Assistant icon, a link in the right side of the Search app takes them to activation information:
Activate Splunk AI Assistant in the Search app
Splunk AI Assistant is an optional generative AI feature in Splunk Web that helps users write and interpret SPL searches. The assistant is displayed on the right side of the search bar.
Before you can use Splunk AI Assistant in your searches in Splunk Web, your Splunk administrator must activate the application by following these steps.
Turn off the sparkle icon for Splunk AI Assistant
Splunk platform deployments that aren't ready to use the Splunk AI Assistant yet can turn off the AI sparkle icon, so it doesn't appear in the Search bar in the Search app.
By default, to turn on or off the AI sparkle icon for the Splunk AI Assistant, you must be a member of the admin or sc_admin role.
- In Splunk Web, select Settings and then Server settings and then Search preferences.
- Turn off the toggle for the Splunk Search AI Assistant.
- If you're using Splunk Enterprise in a distributed search deployment, you must turn off the toggle on all search heads.
- To make the AI sparkle icon and its corresponding tooltip reappear in the Search bar, return the toggle for the Splunk Search AI Assistant to its default.
The Splunk AI Assistant sparkle icon and its corresponding tooltip no longer appear in the Search app.