AI Workbench: The Generative Workspace for Splunk

AI Workbench is not just another chatbot bolted onto a search bar; it is a native, generative workspace designed to live exactly where your users already work—inside Search, Enterprise Security (ES), ITSI, and TrackMe. It functions as a “host shell,” meaning it has no use-cases of its own until it derives them from the Splunk app you open it from and the roles you hold.

What does it do for the user? It allows anyone, from junior analysts to senior specialists, to talk to Splunk in plain English. Whether you need to build a complex SPL search, design a Dashboard Studio or Simple XML dashboard, or create an end-to-end Machine Learning pipeline with the AI Toolkit (MLTK), AI Workbench does the heavy lifting for you. Every output—be it a saved search, an alert, or an ML model—is a validated Splunk knowledge object that is run for real before being saved to your current app’s namespace.

What makes AI Workbench unique? The “depth is the difference” [summary in conversation]. Unlike generic assistants, AI Workbench is Splunk-aware through its four powerful pillars:

  • Templates: Guided recipes for common tasks like outlier detection or correlation.
  • Tools: Over 60 built-in, fine-grained tools that allow the AI to “reach out” and interact with Splunk Core, ES, and ITSI.
  • Skills: Reusable “do-it-correctly” prose rules that ensure every generated object meets your corporate standards (e.g., naming conventions or performance priorities).
  • Knowledge: A retrieval-backed layer that pulls best practices from sources like Splunk Security Essentials (SSE) or internal wikis on-demand.

Enterprise-Ready Security AI Workbench is built with multi-tenancy at its core. It automatically resolves your Organisation (Org) and Business Unit (BU) context based on your role, ensuring you only see the templates and tools you are authorized to use. Best of all, your data stays within your Splunk environment, and you can Bring Your Own LLM—from Anthropic and OpenAI to local, fully offline models like Ollama.

No active development anymore

Common Metadata Data Model (CMDM)
The CMDM product can also be seen as the Corporate Metadata Data Model.

The CMDM is developed because there are multiple use cases that need content and context.
The first use case that is developed with the CMDB is to bring ServiceNow CMDB/CMS/CSDM content AND context to Splunk.
But there are more use cases and for that see the solutions section.

In general, the purpose of this CMDM solution is to collect, reconcile, and visualize data in a common model context. With this organizations can bring several CMDBs/CMS/cloud configs/services/IT4IT together in one flexible model to steer the digitalization of the organization.

This product supersedes the CMDB-to-ITSI product which is EOL.

End-of-life products

CMDB-to-ITSI This product is end-of-life since end 2020. But version can be found on Splunk base here https://splunkbase.splunk.com/app/3779/. This product is superseded by the Splunk CMDB product as mentioned above.