Appearance
Splunk
Splunk context enriches an existing Pulse. It does not create Pulses.
How this helps triage: matching excerpts can show up in the summary, the first checks, and What informed this on the Pulse.
This is not Splunk On-Call paging ingest. If Splunk On-Call incidents should become Pulses, connect Sources → Splunk On-Call.
Connect
- Sign in as a workspace admin.
- Open Connections → Context → Observability context → Splunk.
- Save the Splunk public HTTPS host and token (or user credentials required by your deployment), then Test connection.
- Test connection to mark the connector configured.
See Splunk's official guide: Create authentication tokens.
Missing credentials, timeouts, or vendor 403s skip this block. Triage still completes. Send-test-alert Pulses skip live collectors.
Plan
Business or higher.Connector slots are shared across Context categories (markdown runbooks use a separate document cap). Tighten AI → Prompt → Context use if excerpts are noisy or too large.
API
Writes use the signed-in session and CSRF. Secrets are never returned on GET.