AI Query Assistant for Splunk
from $9.9/moNatural-language to SPL with templates and history.
- Natural-language to SPL
- Multi-provider AI
- Per-user query history
Open source and paid apps for Splunk, from natural-language SPL to drag-and-drop dashboards. Spin up any of them on your own node, free, and keep the ones that earn their place.
Natural-language to SPL with templates and history.
Open sourceAuthor and stage Splunk events without leaving the SPL workbench.
PaidSigning, activation, renewal, and audit. Everything to sell a Splunk app and keep it honest in the field, signed with a key that never leaves the server.
Take payment or start a trial and the server returns an RSA-PSS signed, node-locked token. No manual key handling, ever.
Audit every issue, renewal, and revoke. Track activations per host across the whole catalog.

Licenses verify on the customer's install against the public key. No SaaS round-trip, online or air-gapped.

Rotate from RSA-2048 to 3072 without breaking a single license already in the field. Splunk Cloud and Search Head Clusters supported.

Choose any app in the catalog — open-source or paid. No account needed to look around.
We mint a 30-day, node-locked license token signed with your app's RSA key. It lands in your dashboard instantly.
Drop the token into your Splunk install. It verifies locally against the public key, online or air-gapped.
3072-bit signatures, verified per token.
Bound to a host fingerprint on activation.
No SaaS round-trip. Works air-gapped.
Rotate keys without breaking the field.
“We had a signed trial running on our air-gapped search head in ten minutes. Nothing phoned home, and the token verified against the public key we already had on file.”

“The trial converted itself. By the time procurement asked for a demo, the team had been using it for three weeks.”

“Open-sourcing Event Builder is why we trusted the paid app. We could read exactly how the signing worked.”

AI Query Assistant tiers. Every plan ships a node-locked, RSA-PSS signed license. Start on Starter, upgrade when the trial proves out.
Evaluate on a single node.
Start free trialFor growing security teams.
Buy ProfessionalLarge SOC / compliance orgs.
Buy EnterpriseStill unsure? Start a trial. It costs nothing and tells you more than any sales call would.
Start a free trialNo. The license verifies locally against the app's public key, so it works fully air-gapped. Nothing about your environment leaves your install.
The app falls back to its unlicensed state. Buy a seat to keep the paid features running. Your data and configuration stay exactly where they are.
Each token is node-locked to a host fingerprint captured on first activation. One token activates one node, and the binding is enforced cryptographically.
Yes. Keys rotate from RSA-2048 to 3072 with zero downtime. Licenses already in the field keep verifying against the key they were signed with.
Splunk Enterprise, Splunk Cloud, and Search Head Clusters. KV-store ACLs and conf replication are handled so the apps behave the same across all three.
Yes. Apps like Event Builder are free and open source; others are paid. Both use the same signed, node-locked license model.
List a Splunk app, wire up Stripe, and start issuing node-locked licenses. The signing key never leaves the server.