OS AI Agent
Bring your own LLM to Splunk, and put it to work with your approval.
OS AI Agent is a vendor-agnostic AI assistant that runs inside Splunk. Point it at the model you already pay for - OpenAI, Anthropic, Azure OpenAI, AWS Bedrock, or a local model behind an OpenAI-compatible endpoint - and it profiles your data, writes and verifies SPL, reads your macros and data models, and builds dashboards and alerts that pause for your approval before anything is written. Chat with it, call it from SPL, or let it investigate an alert while nobody is watching. Every action runs with the calling user's own Splunk permissions. OS AI Agent is in beta: it is not on Splunkbase yet, and is available on request, together with a license for the beta.
Requirements
Splunk versions, KV Store, network access to your provider, and what alert investigations need
→Installation
Install on a search head, assign roles, add a provider, have your first conversation
→Splunk Cloud
What is different on Splunk Cloud: everything is set from the Setup page, hosted providers, egress, and token authentication
→Concepts
How the agent works: providers, tools, approvals, the background worker, and what leaves your environment
→Providers
The four provider kinds, their endpoints and credentials, local models, reliability, and pricing
→Chat
Conversations, approvals, tool cards, per-conversation settings, and export and import
→Tools
The agent's tools - read-only discovery and search, approval-gated authoring, deployment knowledge, and the reference it consults
→The osai command
Full SPL reference for | osai: a completion, an SPL explanation, or an unattended investigation
→Alerts and schedules
Unattended runs: the Ask OS AI Agent alert action and scheduled | osai task= reports
→Configuration
The Settings and Guidance tabs and the os_ai_agent.conf they write: chat defaults, retention, the activity trail, logging, and guidance notes
→Costs and limits
How the app records tokens and cost, how to price a provider, and the rolling 24-hour budgets
→Security
Roles and capabilities, the permission model, prompt-injection defenses, secrets, and the activity trail
→Dashboards
Token Usage, Activity Trail, Health, and the Conversation inspector
→Licensing
Free tier vs paid, the single seat, the grace period, and entering a key
→Troubleshooting
Find logs, read the health check, and diagnose the common failures
→Support
How to get help and what to include in a request
→Release history
Version history for the OS AI Agent app
→