Purpose-Built Agents
Pre-configured agents for Splunk tasks — Search Ninja, Splunk Sensei, BOTS Hunter, Data Explorer, Docs Copilot, GDI, GDI v7, Data Input Monitoring, Environment Documenter, Deslicer Automation Copilot, App Deployment, Splunk UC Catalog, and Splunk Observability specialists
Purpose-Built Agents
Deslicer ships with purpose-built agents, each tuned for a specific Splunk domain. They come pre-configured with system prompts, tools, and integrations.
Navigation
- Parent: Agents
- Previous: Understanding Agents
- Next: Creating Agents
- Related: Agent Templates | Integrations
Search Ninja
SPL query expert. Generates, optimizes, and explains SPL. Runs queries against your live Splunk via MCP, generates and tests regex for field extractions, references CIM data models, and follows best practices.
Requires: Splunk MCP, Regex for Splunk MCP
Use when: You need to write, refine, or debug SPL queries. Ideal for analysts and developers working with Splunk search.
Splunk Sensei
Splunk learning assistant. Runs interactive quizzes, SPL challenges, and certification prep (SPLK-1001 through SPLK-4001). Tracks your progress with points and badges. Builds personalized study plans.
Requires: Exa Web Search, Splunk MCP (optional for live practice)
Use when: You're studying for Splunk certifications, onboarding new team members, or want interactive SPL practice.
BOTS Hunter
SOC analyst for Splunk Boss of the SOC (BOTS) style investigations. Discovers indexes and sourcetypes on first interaction. Runs investigation workflows with IOC enrichment, evidence chains, and MITRE ATT&CK mapping.
Requires: Splunk MCP, VirusTotal MCP, Censys MCP, Exa Web Search
Use when: You're doing security analysis, threat hunting, or investigating anomalous behavior. Built for security analysts and SOC teams.
Splunk Data Explorer
Data exploration agent. Discovers indexes, sourcetypes, and fields. Infers data types and use cases. Suggests KPIs, CIM mappings, saved searches, and dashboards based on your data.
Requires: Splunk MCP
Use when: You're exploring unfamiliar data, assessing what's available in an index, or mapping data to CIM models.
Splunk Docs Copilot
Documentation-only assistant. Searches and cites official Splunk documentation including admin guides, SPL references, troubleshooting guides, CIM references, and Dashboard Studio topics. Does not modify your environment.
Requires: Splunk MCP (docs tools only)
Use when: You need to find specific Splunk documentation, look up SPL commands, or reference admin/troubleshooting guides without searching docs.splunk.com manually.
GDI Onboarding Agent
Splunk data onboarding specialist. Analyzes sample logs, matches CIM data models, generates a complete deployment-ready config package, validates it with a data quality score, and optionally pushes to GitHub. See Data Onboarding for the full workflow.
Requires: Splunk MCP, Regex for Splunk, GitHub (optional), Deslicer Observer (optional)
Generates:
inputs.conf— monitor stanzas for forwardersprops.conf— index-time and search-time parsing with Magic 8 compliancetransforms.conf— field extractions and lookupstags.conf— CIM taggingserverclass.conf— deployment server classes with host whitelists
Multi-app layout: Creates 4 Splunk apps per sourcetype — TA-{sourcetype}_inputs, TA-{sourcetype}_indexer, TA-{sourcetype}_search, TA-{sourcetype}_deployment.
Validation and scoring: After generating configs, the agent runs Splunk readiness checks (index existence, sourcetype conflicts, host verification) and a data quality score (0–100 with letter grade) covering Magic 8 compliance, line breaking, timestamp parsing, and CIM alignment. Configs scoring below 90 are iterated before finalizing.
Config download: Finalized configs are packaged as a downloadable .tar.gz archive. You receive a download link in the chat that remains valid for one hour.
GitHub integration: Enable the GitHub integration to push configs directly to a repository. The agent creates a branch and opens a pull request with the full multi-app layout for code review.
Use when: You're onboarding new data sources, building deployment-ready Splunk app packages, or need CIM-compliant configs.
GDI Agent v7
Evolved onboarding agent with post-onboarding orchestration. It includes everything in the GDI Onboarding Agent workflow plus specialist handoffs after configs are validated:
| Handoff | Specialist | What Happens |
|---|---|---|
| Deploy | Deslicer Automation Copilot | Governed DAP change-plan deployment with your approval |
| Value | Splunk Value Architect | Use-case, compliance, MITRE ATT&CK, and data-sizing reports |
| Monitor | Splunk Data Input Monitoring | Scheduled ingestion health checks for onboarded sourcetypes |
GDI v7 also supports Splunk Cloud ACS setup inline and surfaces compliance/MITRE coverage before deploy. The agent creates per-dataset scheduled monitors directly when you choose monitoring during onboarding.
Requires: Splunk MCP, Regex for Splunk, Splunk UC Catalog, GitHub (optional), Splunk Cloud ACS (for Cloud deploy), Deslicer Observer (for DAP deploy)
Use when: You want end-to-end onboarding through deploy, value reporting, and ongoing input monitoring in a single guided flow. See Data Onboarding.
Splunk Data Input Monitoring
Unified data-input health agent. Tracks configured Splunk inputs against live ingestion — freshness, volume, and staleness — and evaluates data quality and CIM conformance.
Requires: Splunk MCP, Deslicer Observer (optional, for fleet input inventory)
Capabilities:
- Correlate
inputs.confinventory with live tstats staleness and volume - Build input-health Dashboard Studio views and saved searches
- Create per-dataset scheduled monitors (hourly or daily)
- Open human-in-the-loop remediation drafts via the CIM Normalizer or Deslicer Automation Copilot — never auto-executes fixes
Use when: You need ongoing ingestion monitoring after onboarding, want to find stale inputs across the fleet, or schedule recurring data-quality checks.
Splunk Environment Documenter
Living documentation agent for your Splunk estate. Collects fleet topology, data inputs, indexes, knowledge objects, and drift from Splunk MCP and DAP, then publishes chapterized markdown with Mermaid diagrams to a GitHub repository via pull request.
Requires: Splunk MCP, Deslicer Observer (optional), GitHub
Use when: You need up-to-date environment documentation, topology diagrams, or a weekly scheduled docs refresh PR for auditors and onboarding.
Deslicer Automation Copilot
Splunk fleet co-pilot for the Deslicer Automation Platform. Combines read-only fleet intelligence (configs, certificates, drift, security audit, compliance baselines) with governed change-plan lifecycle — draft, approve, execute, monitor, and retry — all behind human-in-the-loop confirmation cards.
Requires: Deslicer Observer API
Entry points:
- Public Agents gallery → Deslicer Automation Copilot
- Observe → Fleet Overview → Ask Copilot
- Observe → Nodes → host detail → Audit this node
- Automate → Plans → plan detail → Walk me through this plan
Observe capabilities — read-only fleet audit across enrolled Insights nodes: fleet summary, certificates, security audit, inputs coverage, drift signals, anomalies, and compliance baseline context. Produces prioritized findings with severity tags before any change is proposed.
Automate capabilities — resolve target host groups, author plan drafts, preview diffs, and drive approve/execute/retry flows. Works with Git-backed compiles, manifest reconciliation, and inline compliance or agent-authored remediation drafts.
Bundled skills — Observe Fleet Audit, Investigate Config Drift, Resolve Plan Target Group, Plan Lifecycle (HITL), plus GDI deploy and compliance remediation handoff skills. See Agent Skills.
Use when: You want a single agent to audit fleet posture, investigate drift, scope a change plan to the right hosts, and walk an existing plan through approval and execution. GDI Agent v7 hands off here for governed DAP deploy.
Splunk App Deployment Agent
Enterprise assistant for Splunk app onboarding and configuration management via the Deslicer Observer API. Inspects hosts, manages change plans with human-in-the-loop approvals, and generates reconciliation reports.
Requires: Deslicer Observer API
Use when: You're managing Splunk app deployments across multiple hosts and need change management with approval workflows.
Splunk UC Catalog
Monitoring use case discovery and data sizing agent. Browses a curated catalog of Splunk monitoring use cases and estimates ingest volume, storage, and license requirements for deployment planning.
Requires: Splunk Monitoring Use Cases
Capabilities:
- Search use cases by category, sourcetype, CIM data model, or keyword
- Map use cases to compliance regulations (GDPR, PCI-DSS, HIPAA, NIST, and others)
- Identify MITRE ATT&CK coverage and gaps
- Recommend monitoring use cases based on your data sources and requirements
- Provide SPL examples and implementation guidance for each use case
- Estimate Splunk ingest volume (GB/day), EPS, storage, and license tier for a deployment plan
- Size deployments by endpoint count, equipment type, or Splunk UC catalog IDs
- Compare low, typical, and high volume profiles across 206 data sources
Use when: You're planning what to monitor, evaluating compliance coverage, identifying MITRE ATT&CK gaps, discovering Splunk use cases for a new data source, or sizing a Splunk deployment. This agent does not execute SPL — pair it with Search Ninja or another Splunk MCP agent to implement recommended use cases.
Observability SRE Copilot
On-call assistant for Splunk Observability Cloud. Triages live incidents using alerts, APM services, traces, errors, latency, RUM, and synthetics — then pivots into Splunk Enterprise or ITSI logs for root-cause evidence when available.
Requires: Splunk Observability Cloud, Splunk MCP (optional, for log pivot)
Capabilities:
- Search and summarize active alerts and incidents
- Investigate APM service dependencies, latency, and error rates
- Fetch exemplar traces and identify failing spans or dependencies
- Deliver Observability UI deeplinks and handoff steps for muting, routing, or detector changes (read-only via MCP — never auto-applies changes)
Use when: You are on call, responding to an incident, or need a fast, evidence-backed triage narrative across Observability and Splunk logs.
Observability Platform Builder
Render-first design assistant for Splunk Observability Cloud. Helps platform engineers draft dashboards, SLOs (with burn-rate alerts), and synthetic tests grounded in validated metrics from your realm.
Requires: Splunk Observability Cloud, Splunk MCP (optional), GitHub (optional)
Capabilities:
- Discover real metric names and dimensions before authoring SignalFlow
- Produce validated dashboard JSON specs and chart definitions
- Design SLOs with error-budget math and burn-rate alert recommendations
- Plan browser, API, HTTP, SSL, and port synthetic tests with location and alerting guidance
- Deliver Observability UI handoffs with deeplinks for every artifact
Use when: You are building or extending Observability dashboards, SLOs, or synthetic monitoring — not for live incident triage (use Observability SRE Copilot).
Observability Cost & Cardinality Steward
FinOps assistant for Splunk Observability Cloud metric volume and cardinality. Analyzes high-volume metrics, models Metrics Pipeline Management (MPM) rule impact, and proposes archive, drop, aggregate, or route changes with explicit blast-radius analysis on dashboards and detectors.
Requires: Splunk Observability Cloud, Splunk MCP (optional)
Capabilities:
- Identify high-cardinality and high-volume metrics
- Model MPM rule ordering, scope filters, and precedence
- Analyze downstream impact on dashboards, detectors, and navigators before recommending drops or archives
- Deliver MPM UI handoffs with deeplinks — never applies rules automatically
Use when: You are controlling Observability ingest cost, reducing cardinality risk, or planning MPM changes safely.
Choosing the Right Agent
| Task | Agent |
|---|---|
| Write or debug SPL | Search Ninja |
| Learn Splunk / cert prep | Splunk Sensei |
| Security investigation | BOTS Hunter |
| Explore unfamiliar data | Data Explorer |
| Look up Splunk docs | Docs Copilot |
| Onboard new data sources | GDI Onboarding Agent or GDI Agent v7 |
| Monitor ingestion health | Splunk Data Input Monitoring |
| Document Splunk topology | Splunk Environment Documenter |
| Audit fleet posture and ship DAP changes | Deslicer Automation Copilot |
| Manage app deployments | App Deployment Agent |
| Discover monitoring use cases | Splunk UC Catalog |
| Size a Splunk deployment | Splunk UC Catalog |
| Triage Observability incidents | Observability SRE Copilot |
| Build Observability dashboards, SLOs, or synthetics | Observability Platform Builder |
| Control Observability metric cost and cardinality | Observability Cost & Cardinality Steward |
You can also create custom agents or start from templates.