Splunk
Search logs stored in Splunk Enterprise or Splunk Cloud
The Splunk tool gives a workbench read-only access to logs already stored in Splunk Enterprise or Splunk Cloud. It searches that data through the Splunk REST API and does not ingest logs or install a forwarder.
Capabilities
- Placeholder: name each operation the agent can call, from
lib/console/ai/tools/workbench/(andgo/cloud-query/internal/tools/when the tool is query-backed). - Placeholder: mention permissions only when the implementation or the setup guide states them.
Setup
Create the tool under Workbenches → Integrations and follow the inline setup guide for credentials and Console fields. That guide is maintained at js/console/public/setup-guides/tools/splunk.md.