Splunk Search

Execute and validate SPL (Search Processing Language) queries.

gabrielmoreira Updated 17 repo stars

File contents

Splunk Search Skill

Execute and validate SPL (Search Processing Language) queries.

Tools

Tool Description
validate_spl Validate SPL syntax without executing
search_oneshot Execute SPL query and return results
search_export Execute SPL query and export to file

Output Format

Results are formatted as Markdown tables for easy reading. Sensitive fields are automatically sanitized.

Example Queries

Validate this SPL: index=network sourcetype=syslog | stats count by host

Search for all firewall denies in the last hour

Export BGP peer events from the network index

SPL Tips

  • Use earliest=-1h for time ranges
  • Use | table field1, field2 to select columns
  • Use | stats count by field for aggregations

Prerequisites

  • SPLUNK_HOST Splunk server hostname
  • SPLUNK_PORT Management port (default: 8089)
  • SPLUNK_USERNAME Service account username
  • SPLUNK_PASSWORD Service account password

Server

This skill uses the splunk-mcp server via npx.

gabrielmoreira/agent-skills-mirror/tree/main/mirrors/repos/automateyournetwork@netclaw/workspace/skills/splunk-search commit e3165e93a3

Frequently asked questions

npx skillmds@latest add gabrielmoreira/splunk-search