July 23, 2026
Federal AI LookupOps
Air-gap-first governance for Splunk lookup changes: inventory, deterministic validation, semantic diff, approvals with separation of duties, verified publication and rollback, audit evidence export, offline transfer bundles, and optional behind-the-firewall AI review with zero authority. No cloud dependencies. No telemetry.Built by Lloyd ClarkSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1
Log in to rate this app
Federal AI LookupOps turns Splunk lookup edits into governed changes. It is built air-gap-first: no cloud dependencies, no external services, and no telemetry. Analysts propose candidate changes by uploading a CSV, pasting records, or cloning the current lookup. A deterministic policy engine validates schemas, unique and composite keys, field types (IPv4, IPv6, CIDR, hostname, URL, email, date, boolean, number), enumerations, patterns, blank values, duplicates, and expirations. A key-aware semantic diff shows exactly what will change - additions, removals, field-level modifications, normalization-only changes, and schema changes - each with a stable evidence ID. Approvers act under enforced separation of duties; self-approval is blocked server-side. Publication captures the production content hash at submission, re-verifies it immediately before the write, publishes only through documented Splunk interfaces, verifies the resulting hash after the write, and preserves the previous version for one-action verified rollback. Every step lands in a hash-chained audit trail with an exportable JSON evidence report. Deterministic offline bundles with SHA-256 manifests move changes safely between enclaves. Optionally, connect a customer-approved, behind-the-firewall LLM (OpenAI-compatible, Ollama, or custom JSON). AI review runs server-side only with TLS verification always enforced, and provides risk assessment, justification-vs-diff contradiction detection, reviewer questions, policy proposals, normalization patches, dependency impact, and release narratives. Every material AI finding must cite deterministic evidence IDs, and the model has zero authority - it can never approve, publish, or roll back. Works with your existing SAML login through Splunk's own authentication. Includes role-based capabilities (view, submit, approve, publish, rollback, AI use, AI admin), KV Store-backed state that replicates across search-head clusters, and full documentation. Support: LC@federal.ai | www.federal.ai
Log in to report this app listing.