Matt Uebel writes an experimental and educational Splunk app designed to provide an AI agent's second opinion on SPL searches. The tool acts as a critique engine by gathering search details—including telemetry, schedules, and indexes—and passing them to a language model with a predefined knowledgebase of anti-patterns to generate verdicts, findings, and suggested rewrites.
- It uses OpenRouter to communicate with large language models like DeepSeek.
- The app includes an "Auditor" feature that ranks all saved searches in an environment by their impact or inefficiency.
- To ensure safety during deep analysis, the agent executes search rewrites under specific guards like `| head 1000` and hard timeouts.
- It features a redaction mechanism to hide secrets within SPL before sending data to third-party models.
This Splunk blog post announces the general availability of **Search Processing Language version 2 (SPL2)**, the next generation of Splunk’s data search and preparation language. SPL2 aims to improve upon the existing SPL language by addressing user feedback and modernizing data interaction.
**Key benefits and features of SPL2 include:**
* **Unified Language:** SPL2 provides a single syntax for both searching data within Splunk and preparing data in-stream (via Edge and Ingest Processor).
* **SQL-like Syntax:** It supports both SPL-like and SQL-like syntax, making it more accessible to users familiar with database languages.
* **Enhanced User Experience:** A multi-statement “module” editor offers features like autocomplete, in-product documentation, and a point-and-click interface.
* **Improved Data Management:** "Data views" allow administrators to define and permission access to data, improving data sharing and reducing index bloat. Custom data types enable data quality validation and conditional dropping of poor data.
* **Code Reusability:** Developers can create and share custom functions for use across the Splunk ecosystem.
* **Streamlined Workflows:** The “learn once, use everywhere” model allows for consistent data processing across search and ingest solutions.
* **App Development Enhancement:** SPL2 module files allow developers to ship apps with curated data, custom functions, and packaged views.
This gist contains BNF (Backus-Naur Form) syntax definitions for various data types used in Splunk, such as boolean, field, field-and-value, and more.
A discussion thread about finding a grammar for the Splunk query language, providing links to BNF grammars for search and datatypes generated from a Splunk instance.
This article provides a convenient list of Splunk query commands, organized by the type of queries you would like to conduct on your data, such as basic pattern search, filtering, mathematical computations, and statistical functionalities.
Breser is a powerful and flexible query language designed for efficient log processing and structured data filtering. It provides an intuitive syntax that combines the familiarity of programming languages with the specific needs of log analysis and data querying.
This chapter covers the fundamental syntax elements and field access mechanisms for accessing and manipulating data fields within structured data.
Breser stands for Business Rules & Expression Syntax for Easy Retrieval. It is a powerful and flexible query language designed for efficient log processing and structured data filtering.