Skip to main content
Adjutant AI (AI Workbench) app icon

Adjutant AI (AI Workbench)

A workbench for Splunk, not just a chatbot. Analyse, correlate and build across SPL, dashboards, alerts, AI Toolkit / MLTK, ES, ITSI and TrackMe through tools that understand each one — plus any MCP server you add. Pick your LLM: Anthropic, OpenAI, Azure, Groq, Gemini, Bedrock, Ollama, OpenRouter. Multi-tenant, multi-tier (Free, Pro, Enterprise, MSP).Built by Eduard Lekanne
splunk product badge

Default Version 2.5.9

September 10, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4

CIM Version: 8.x, 6.x, 5.x, 4.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported
Ranking

#36 in Artificial Intelligence

Adjutant AI turns the Splunk your platform team built into something the business can use. Install it on your search head and it drives the Adjutant AI Domain Workspace (app 9691, arriving on Splunkbase shortly): your saved searches, dashboards, lookups and data models assembled into a workspace people work in. Ask in plain language, comment on what you find, claim and hand over rows, and every role gets its own perspective on one model: business on one side, plumbing on the other. Every number comes from a real search run as that user, never from the model. This is how Splunk reaches the business side of IT. Underneath it is a full generative workbench: ask in English, get back working SPL, dashboards, alerts, lookups and MLTK pipelines, built against your running environment and run for real before saving. New in 2.5: your first LLM connection takes a minute instead of a week. Pick a provider, paste whatever URL you have, and the setup wizard works out the endpoint, the API version, the route, your proxy and what must bypass it, TLS interception, and whether your token ceiling can carry a question. Ten checks prove the whole path, ending in a real answer and a real Splunk tool call, because a connection that authenticates and then ignores tools looks healthy until the first question. Every failure names what happened, who can fix it and how long it takes, with a block to paste into a ticket when it belongs to another team. What the AI already in Splunk does not give you: Your keys never leave the building. Bring your own model, Anthropic, OpenAI, Azure, Bedrock, Gemini, Groq, OpenRouter or Ollama fully offline, running server side on your search head. It knows your Splunk, not Splunk in general. Fine grained tools across Core, ES, ITSI, TrackMe, ServiceNow and the AI Toolkit under your existing roles, with your macros expanded and syntax read live from your box. An engineer who distrusts AI can check the working. ITSI Root Cause Analysis walks your dependency graph and scores the evidence with no LLM in the analysis, so a red KPI on a dead feed is named as a data problem, and the same evidence always gives the same answer. Fraud rings a risk threshold structurally cannot find: many accounts each too small to alert, sharing a device or payout account. A coverage audit grades your estate against nine fraud use cases, AML included. Your SOC can watch the agent. LLM calls, tool calls, config changes and policy refusals go out as OCSF events to an index Enterprise Security already reads. Explain a SPL search and the fraud demo dataset are free on every tier. The workspace and most of the depth are licence gated, so a download alone shows the shape, not the substance. Come and see it properly: a free hour on video on your use cases, then a proof of value licence scoped to what you want to prove. PoV customers see the workspace before Splunkbase does, and get a real say in what it does next. eduard.lekanne@thedutchdatadifference.nl