Feature preview: SPL2 and Federated Data Context (Beta)
Splunk Cloud customers of Splunk AI Assistant version 2.2.0 can choose to try a beta feature called SPL2 and Federated Data Context.
This feature preview brings natural-language searches to Federated data. Using Splunk AI Assistant, users can compose searches in plain english and the assistant returns SPL2 across Splunk indexes, federated datasets, and Machine Data Lake data sources. Users can then execute this SPL2 search and view results in the assistant, or manually execute it in the Search app.
-
For more information on SPL2 see SPL2 Overview.
-
For more information on federated search see Welcome to Splunk Federated Search.
Preview disclaimer
Beta features described in this document are provided by Splunk to you "as is" without any warranties, maintenance and support, or service-level commitments. Splunk makes this Beta feature available at its sole discretion and may discontinue it at any time. Use of Beta features is subject to the Splunk Pre-Release Agreement for Hosted Services.
Requirements
You must meet the following requirements to use this beta feature:
-
You must be a Splunk Cloud customer.
-
You must be running Splunk AI Assistant version 2.2.0 or higher.
-
You must be running Splunk Cloud version 10.5.2605.5 or higher with both Agent Mode and SPL2 and Federated Data Context (Beta) settings set as on.
Supported regions
SPL2 and Federated Data Context (Beta) is supported in the following AWS regions:
-
AWS - US West Oregon
-
AWS - US East Virginia
-
AWS - Canada Central
-
AWS - EU Frankfurt
-
AWS - EU London
-
AWS - EU Paris
-
AWS - EU Dublin
SPL2 and Federated Data Context (Beta) settings
From Splunk AI Assistant, select Settings. A new tab for SPL2 and Federated Data Context (Beta) is available.
See the following table for information on each of the available settings:
| Setting | Description |
|---|---|
| Federated Analytics with SPL2 (Beta) | The main setting for this beta feature. If toggled off, all other beta feature settings also toggle off. |
| Collect data from federated datasets | Allows Splunk AI Assistant to search and present results from federated datasets. |
| Collect data from Machine Data Lake - Time Series Index | Allows Splunk AI Assistant to search and present results from the Machine Data Lake, specifically time series index data. |
| Collect data from Machine Data Lake - Promoted | Allows Splunk AI Assistant to search and present results from from the Machine Data Lake, specifically promoted data. |
Using SPL2 and Federated Data Context (Beta)
When you opt in for the feature preview, you can use Splunk AI Assistant as you usually would. The key difference is that now the app can search from federated datasets and the Machine Data Lake, depending on your selected settings.
The following image shows an example where the chat prompt used is find all federated datasets and the app was able to return results:
Known limitations
The following are known limitations for the preview version of SPL2 and Federated Data Context (Beta):
-
Responses from the assistant are slower when the beta feature is turned on.
-
Beta support is limited to single search only. No SPL2 modules. To learn more see SPL2 modules and statements.
-
Beta is limited to Splunk Cloud customers only, in specific AWS regions.
-
Machine Data Lake raw querying is out of scope. Beta supports Machine Data Lake raw discovery and provides a deep link to the catalog promotion wizard.