Introducing Splunk Agent Skills: Portable Splunk Expertise for Your AI Agents

Artificial Intelligence Shriya Paramkusam

Key takeaways

  1. Splunk is publishing its first open source agent skills in a governed GitHub repository, beginning with three Splunk-built skills for common practitioner workflows.
  2. Agent skills bring reusable Splunk expertise to compatible AI agents, helping them draft and improve searches, convert dashboards, and build custom visualizations with Splunk-specific guidance.
  3. Each Splunk-published skill is reviewed, evaluated, documented, and released with clear prerequisites and expected outcomes.

AI coding agents such as Claude Code and Codex can write code, edit files, and accelerate technical work. But when a general-purpose agent is asked to perform a Splunk-specific task, it may produce plausible SPL or dashboard code without the conventions, validation steps, and judgment an experienced Splunk practitioner would apply.

Agent skills help close that gap. A skill is a portable playbook that packages instructions, examples, and domain conventions for a specific job. Rather than explaining how to write a Splunk search from scratch each time, you can give a compatible agent a skill that guides it through the task: how to structure the search, which fields and assumptions to examine, and how to validate the result.

An LLM provides broad reasoning and generation. A skill directs those capabilities toward a defined job, using reusable Splunk expertise to help the agent perform it more consistently.

Today, Splunk is publishing the first open source Splunk agent skills: three Splunk-built skills designed for work Splunk practitioners do every day.

Skills Built for Real Splunk Jobs

The repository is organized around jobs to be done, not product features. Each skill maps to a recognizable practitioner task and draws on recurring customer needs and Splunk product guidance.

At launch, the repository includes three skills:

More Splunk-built skills are planned across search, dashboards, data ingestion, platform operations, administration, and security. The repository will make it clear which skills are available and ready to use.

Use Them Where You Already Work

Because the skills are open source, they are not tied to a single agent or interface. You can use them with compatible agents that support the skill format.

Developers can pull the skills from the Splunk agent skills repository on GitHub and use them with Claude Code, Codex, or another compatible agent. The open format also makes it possible to inspect a skill and adapt it to fit your environment within the terms of its license.

Agent skills and MCP serve different but complementary roles. When an agent is connected to Splunk through an MCP server, MCP can provide authorized access to the Splunk data and tools exposed by that server; the skill provides the instructions and conventions for using that access effectively. MCP is not required, however. A command-line agent can also apply a skill to local files, saved searches, or dashboard definitions.

How a Skill Earns Its Place in the Repository

Publishing skills in the open makes them inspectable, but openness alone does not establish quality. Splunk-published skills follow a governed review and evaluation process before release.

At launch, the repository begins with skills built and maintained by Splunk. Each published skill must meet defined requirements for structure, safety review, task performance, ownership, documentation, and product review. Skills that interact with a Splunk environment are tested against one before publication.

Each skill also includes clear prerequisites, an expected outcome, and installation guidance, so users can understand what they need before they begin and what the skill is designed to produce.

The model is straightforward: publish reusable expertise in the open while maintaining rigorous review and evaluation before a skill is released. Splunk plans to expand the contribution model over time.

Getting Started

Browse the Splunk agent skills repository on GitHub to review the first three skills, check prerequisites, and install the ones that match the job you need to do.

At .conf26 in Denver, September 14-17, 2026, we will share live demos of the approved skills and more about the future contributor experience.

Related Articles

That Was Easy! Manage Lookup Files and Backups With the Splunk App for Lookup File Editing
Security
2 Minute Read

That Was Easy! Manage Lookup Files and Backups With the Splunk App for Lookup File Editing

The 4.0.1 release of the App for Lookup File Editing helps users mitigate issues with new features such as a backup size limit and dashboards for tracking backup size.
The State of Security 2023: Collaboration Is Essential For Building Resilience
Security
4 Minute Read

The State of Security 2023: Collaboration Is Essential For Building Resilience

Explore the trends and findings in our new report, The State of Security 2023, detailing research on the challenges and opportunities ahead for security leaders and teams.
Splunk Named a Leader in the 2026 IDC MarketScape for Worldwide SIEM
Security
5 Minute Read

Splunk Named a Leader in the 2026 IDC MarketScape for Worldwide SIEM

We’re thrilled to share that Splunk has been named a Leader in the IDC MarketScape: Worldwide SIEM 2026 Vendor Assessment.