shanemullens
- 7 skills
- 0 followers
- 16 hours ago last updated
- ▌ Splunk Aitk MCP · shanemullens bundleDrive the Splunk AI Toolkit (AITK) 6.0 from Claude Code or Cursor through a Splunk MCP Server — writing and executing ML-SPL such as `ai`, `aiagent`, `fit`, `apply`, `score`, `summary`, `listmodels`, and `deletemodel` against Splunk Cloud. Use this skill whenever the user mentions the AI Toolkit, MLTK, ML-SPL, the `ai` or `aiagent` command, Agent Launchpad, LLM connections in Splunk, training or applying a Splunk ML model, scoring or validating a Splunk model, or asks to summarize/classify/enrich Splunk events with an LLM in the search pipeline — even if they don't name the toolkit explicitly. Also use it when a Splunk search containing `fit`, `apply`, or `ai` fails, times out, truncates at 100k events, or trips an SPL safeguard warning.
- ▌ Splunk Diag Doctor · shanemullens bundleRoot-cause a Splunk deployment from diag files. Crawls one or many Splunk diags (extracted folders or .tar.gz) sitting in the repo, correlates splunkd.log, metrics.log, systeminfo.txt, and the conf layer into an evidence-backed root cause, then writes a remediation plan with ready-to-apply conf stanzas and CLI. Use this skill whenever a Splunk diag is present or mentioned, whenever the user uploads or points at a `diag-*` folder or tarball, and whenever they describe a Splunk problem — indexing lag, blocked queues, skipped searches, crashes, KVStore or mongod failures, SSL/cert errors, cluster bucket fixup, replication factor not met, license violations, forwarder connection failures, high CPU or memory, disk pressure, duplicate or missing events — and expect the answer to come from diag data rather than a live search. Also use it for "why is this indexer slow", "what's wrong with this search head", "review this diag", "triage this support case bundle", or any request to compare diags across a cluster.
- ▌ Peak Threat Hunting · shanemullens bundleConduct threat hunts in Splunk using the PEAK framework (Prepare, Execute, Act with Knowledge). Supports hypothesis-driven, baseline, and model-assisted hunts. Use when the user wants to threat hunt, investigate security anomalies, baseline data sources, detect adversary techniques, or map findings to MITRE ATT&CK.
- ▌ Splunk Log Generator · shanemullens bundleBuild Python scripts that generate realistic logs for any Splunk sourcetype and send them to Splunk via HEC. Supports catalog mode (multi-sourcetype registry with CLI selection) and scenario mode (time-sequenced narratives with correlated IOCs). Use when generating test data, simulating logs, building HEC integrations, populating Splunk indexes, creating demo data, or building log simulators for any vendor or product.
- ▌ Splunk Ta Development · shanemullens bundleBuild Splunk Technology Add-ons (TAs) by parsing log samples, creating props.conf and transforms.conf configurations, loading data, and validating field extractions using the Splunk MCP server. Use when creating Splunk add-ons, parsing log files for Splunk, developing sourcetypes, or configuring field extractions.
- ▌ Comprehensive Plan Mode · shanemullens bundleEnhances Cursor Plan Mode with a strict three-phase workflow — extreme clarification, targeted research, and detailed plan generation with Mermaid diagrams and validation steps. Attach at the end of Plan Mode prompts when you want maximum plan depth, accuracy, and reviewability before implementation.
- ▌ Splunk Dashboard Studio · shanemullens bundleBuild Splunk Dashboard Studio dashboards using JSON dashboard definitions. Covers visualization selection, layout design, tokens, interactivity, dynamic options syntax, and conditional formatting. Use when creating Dashboard Studio dashboards, designing JSON dashboard definitions, building interactive Splunk dashboards, or when the user wants to go beyond Simple XML into modern Splunk dashboard design.