Skip to main content
Adjutant AI (AI Workbench) app icon

Adjutant AI (AI Workbench)

A workbench for Splunk, not just a chatbot. Analyse, correlate and build across SPL, dashboards, alerts, AI Toolkit / MLTK, ES, ITSI and TrackMe through tools that understand each one — plus any MCP server you add. Pick your LLM: Anthropic, OpenAI, Azure, Groq, Gemini, Bedrock, Ollama, OpenRouter. Multi-tenant, multi-tier (Free, Pro, Enterprise, MSP).

splunk product badge
screenshot
screenshot
screenshot

Default Version 2.2.1
August 5, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4
CIM Version: 8.x, 6.x, 5.x, 4.x
Rating

0

(0)

Log in to rate this app
Support
Developer Supported
Ranking

#36

in Artificial Intelligence
Adjutant AI (formerly AI Workbench) is a generative workspace for Splunk — not a chatbot bolted onto search, but a real workbench where you investigate, analyse and build with tools that understand Splunk. It is a host shell: it has no use-cases of its own, deriving everything from the Splunk app a user opens it from and their roles. Install once on the Search Head, then embed it in the apps your users already live in — Search, ITSI, Enterprise Security, your SOC and MSP customer apps. Users never leave the app they came from, and artefacts land in that app's namespace. Ask in plain English. Get back validated SPL, Simple XML and Dashboard Studio dashboards, alerts, lookups, reports and Splunk AI Toolkit (MLTK) machine-learning pipelines — grounded in your running Splunk (your knowledge objects, live command syntax, CIM models), run for real before they are saved, owned by the calling user. The depth is the difference. Where a generic MCP-only assistant talks to Splunk through one broad door, Adjutant AI ships fine-grained, Splunk-aware tools across Core, Enterprise Security, ITSI, TrackMe, ServiceNow and the AI Toolkit, each scoped to one job and run under your existing Splunk ACLs. Extend it with HTTP tools or any MCP server. New in 2.1 — a fraud capability that starts by telling you what you cannot yet detect. The Fraud Data Coverage Audit grades your estate against nine use cases (including AML) and returns ready, partial or blocked with the specific blocker, identifying event families by what events contain rather than by sourcetype name. Entity resolution runs before scoring, because risk accumulates per entity. Generated rules are weighted contributions with readable reasons, emitted into Enterprise Security's risk framework where it exists and into RBA's own field vocabulary where it does not. Nothing generated is ever enabled or scheduled. New in 2.0 — ITSI Root Cause Analysis with no LLM in the answer. It walks your real dependency graph, verifies the data behind every KPI, scores the evidence transparently, then lets an LLM narrate. The same evidence always gives the same answer. A red KPI on a dead feed is a data problem, and it names the forwarder, HEC, DB Connect, Cribl or Edge Processor leg at fault. Plus durable memory, scheduled playbooks, governed integrations, and per-tenant resource-consumption reporting. Your SOC can watch the agent: LLM calls, tool and ServiceNow calls, config changes, unattended verdicts and policy refusals emitted as OCSF events to an index Enterprise Security already watches. On-prem, no cloud egress, off by default. Bring your own LLM: Anthropic, OpenAI, Azure OpenAI, Groq, Gemini, Bedrock, Ollama (fully offline) or OpenRouter — server-side, so keys never leave the search head. Multi-tenant by design. Free, Professional, Enterprise and MSP tiers, self-serve and air-gap-friendly.

Categories

Artificial Intelligence, DevOps

Created By

Eduard Lekanne

Type

app

Downloads

116

Resources

Log in to report this app listing