Introducing Splunk Agent Skills: Portable Splunk Expertise for Your AI Agents
Artificial Intelligence Shriya ParamkusamKey takeaways
- Splunk is publishing its first open source agent skills in a governed GitHub repository, beginning with three Splunk-built skills for common practitioner workflows.
- Agent skills bring reusable Splunk expertise to compatible AI agents, helping them draft and improve searches, convert dashboards, and build custom visualizations with Splunk-specific guidance.
- Each Splunk-published skill is reviewed, evaluated, documented, and released with clear prerequisites and expected outcomes.
AI coding agents such as Claude Code and Codex can write code, edit files, and accelerate technical work. But when a general-purpose agent is asked to perform a Splunk-specific task, it may produce plausible SPL or dashboard code without the conventions, validation steps, and judgment an experienced Splunk practitioner would apply.
Agent skills help close that gap. A skill is a portable playbook that packages instructions, examples, and domain conventions for a specific job. Rather than explaining how to write a Splunk search from scratch each time, you can give a compatible agent a skill that guides it through the task: how to structure the search, which fields and assumptions to examine, and how to validate the result.
An LLM provides broad reasoning and generation. A skill directs those capabilities toward a defined job, using reusable Splunk expertise to help the agent perform it more consistently.
Today, Splunk is publishing the first open source Splunk agent skills: three Splunk-built skills designed for work Splunk practitioners do every day.
Skills Built for Real Splunk Jobs
The repository is organized around jobs to be done, not product features. Each skill maps to a recognizable practitioner task and draws on recurring customer needs and Splunk product guidance.
At launch, the repository includes three skills:
- Splunk Search helps you create, understand, and improve searches with Splunk-specific guidance. It can explain intent, draft SPL, examine fields and assumptions, and guide you toward clearer, better-validated searches.
Example prompt: "Review this SPL, explain what it does, and flag any assumptions that could skew the results." - Dashboard Studio Conversion guides the migration of supported Simple XML dashboard patterns to Dashboard Studio, with conversion steps and validation guidance along the way.
- Custom Visualization Builder helps you scaffold, package, and iterate on custom visualizations for Splunk data using starter examples and a shareable project structure.
Example prompt: "Scaffold a custom visualization for this data and connect it to my search."
More Splunk-built skills are planned across search, dashboards, data ingestion, platform operations, administration, and security. The repository will make it clear which skills are available and ready to use.
Use Them Where You Already Work
Because the skills are open source, they are not tied to a single agent or interface. You can use them with compatible agents that support the skill format.
Developers can pull the skills from the Splunk agent skills repository on GitHub and use them with Claude Code, Codex, or another compatible agent. The open format also makes it possible to inspect a skill and adapt it to fit your environment within the terms of its license.
Agent skills and MCP serve different but complementary roles. When an agent is connected to Splunk through an MCP server, MCP can provide authorized access to the Splunk data and tools exposed by that server; the skill provides the instructions and conventions for using that access effectively. MCP is not required, however. A command-line agent can also apply a skill to local files, saved searches, or dashboard definitions.
How a Skill Earns Its Place in the Repository
Publishing skills in the open makes them inspectable, but openness alone does not establish quality. Splunk-published skills follow a governed review and evaluation process before release.
At launch, the repository begins with skills built and maintained by Splunk. Each published skill must meet defined requirements for structure, safety review, task performance, ownership, documentation, and product review. Skills that interact with a Splunk environment are tested against one before publication.
Each skill also includes clear prerequisites, an expected outcome, and installation guidance, so users can understand what they need before they begin and what the skill is designed to produce.
The model is straightforward: publish reusable expertise in the open while maintaining rigorous review and evaluation before a skill is released. Splunk plans to expand the contribution model over time.
Getting Started
Browse the Splunk agent skills repository on GitHub to review the first three skills, check prerequisites, and install the ones that match the job you need to do.
At .conf26 in Denver, September 14-17, 2026, we will share live demos of the approved skills and more about the future contributor experience.
Related Articles

That Was Easy! Manage Lookup Files and Backups With the Splunk App for Lookup File Editing

The State of Security 2023: Collaboration Is Essential For Building Resilience
