SaaS app
Splunk agent skills for Claude Code, Codex and other agents.
- skills
- 47
- official
- 1
- Type
- SaaS app
- Website
- splunk.com
- Official GitHub
- splunk
- Reviews
- See Splunk on Enlisted
Splunk skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
Official (1 skill)
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | A skill your agent uses when the user is deploying or operating the DOCA Argus Service — the packaged BlueField-side runtime-security container that watches the BlueField and attached host for… | NVIDIA/ | 3.5k | — | ~4.8k | Automated safety check: Pass | Apache-2.0 | today |
Community
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 2 | Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana. | openclaw/ | 9.5k | — | ~4.9k | Automated safety check: Pass | MIT | today |
| 3 | A skill your agent uses when creating or updating splunkconfig.yml, designing Splunk Enterprise lab topology, multisite IDXC, SHC layout, architecture plan before config, or AWS Terraform block for… | splunk/ | 137 | — | ~3.5k | Automated safety check: Pass | Proprietary | yesterday |
| 4 | Creates SC4S syslog-ng parsers. An agent skill from splunk/splunk-connect-for-syslog. | splunk/ | 180 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | today |
| 5 | A skill your agent uses when adding app scope/routing test coverage (deployer, CM, DS, direct). | splunk/ | 137 | — | ~2.2k | Automated safety check: Pass | Proprietary | yesterday |
| 6 | Translates Splunk SPL queries to Axiom APL. An agent skill from openclaw/clawhub. | openclaw/ | 9.5k | — | ~1.6k | Automated safety check: Pass | MIT | today |
| 7 | Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and… | Kilo-Org/ | 189 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 8 | Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats… | Kilo-Org/ | 189 | — | ~910 | Automated safety check: Pass | Apache-2.0 | 8 days ago |
| 9 | Generic detection rule creation and management using Sigma, the universal SIEM rule format. | AgentSecOps/ | 219 | 1 repo | ~4k | Automated safety check: Pass | Unknown | 5 mo ago |
| 10 | Build a systematic threat-hunt workflow that turns threat intelligence and ATT&CK gap analysis into testable hypotheses, then executes and validates them via EDR/SIEM queries (CrowdStrike, Defender… | mukul975/ | 34k | — | ~893 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 11 | Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular… | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Detect adversary lateral movement across networks using Splunk SPL queries against Windows authentication logs, SMB traffic, and remote service (WMI/PsExec/RDP) abuse. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Detect abuse of service accounts by hunting for anomalous interactive logons, privilege escalation, and lateral movement using EDR/SIEM telemetry (CrowdStrike Falcon, Microsoft Defender, Splunk… | mukul975/ | 34k | — | ~904 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Hunt for suspicious PowerShell execution (T1059.001) such as encoded commands, download cradles, AMSI bypass, and constrained language mode evasion using EDR telemetry (CrowdStrike, Microsoft… | mukul975/ | 34k | — | ~923 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Detects DNS tunneling and covert-channel data exfiltration by analyzing Zeek dns.log for high-entropy subdomain queries, excessive query volume, abnormally long query lengths, and unusual DNS record… | mukul975/ | 34k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Perform structured log source onboarding into SIEM platforms (Splunk, Elastic, Sentinel, QRadar, or similar) by prioritizing sources with a tiered value framework, configuring collectors, building… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Classifies and prioritizes security incidents using structured IR playbooks and SIEM/case-management queries (Splunk, TheHive) to determine severity, assign response teams, and initiate the… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 19 | Analyzes Windows Security, System, and Sysmon event logs in Splunk to detect authentication attacks, privilege escalation, persistence mechanisms, and lateral movement using SPL queries mapped to… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 20 | Automates the enrichment of raw indicators of compromise with multi-source threat intelligence context using SOAR platforms, Python pipelines, or TIP playbooks to reduce analyst triage time and… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 21 | Builds vendor-agnostic detection rules using the Sigma rule format for threat detection across SIEM platforms including Splunk, Elastic, and Microsoft Sentinel. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 22 | Builds real-time incident response dashboards in Splunk, Elastic, or Grafana to provide SOC analysts and leadership with situational awareness during active incidents, tracking affected systems… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 23 | Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and… | mukul975/ | 34k | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 24 | Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization… | mukul975/ | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 25 | Detect Golden Ticket attacks in Active Directory using Splunk and KQL queries against domain controller event logs, looking for Kerberos TGT anomalies such as mismatched encryption types, impossible… | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 26 | Detects credential stuffing attacks by analyzing authentication logs for login velocity anomalies, ASN diversity, password spray patterns, and geographic distribution of failed logins. | mukul975/ | 34k | — | ~732 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 27 | Implements strategies to reduce SOC alert fatigue by tuning detection rules, consolidating duplicate alerts, implementing risk-based alerting, and measuring alert quality metrics to maintain analyst… | mukul975/ | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 28 | Write multi-event correlation rules in Splunk SPL and Sigma format that detect APT lateral movement by chaining Windows authentication events (4624, 4648), process execution (4688, Sysmon Event 1)… | mukul975/ | 34k | — | ~784 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 29 | Implements SIEM detection use cases by designing correlation rules, threshold alerts, and behavioral analytics mapped to MITRE ATT&CK techniques across Splunk, Elastic, and Sentinel. | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 30 | Implements Security Orchestration, Automation, and Response (SOAR) workflows using Splunk SOAR (formerly Phantom) to automate alert triage, IOC enrichment, containment actions, and incident response… | mukul975/ | 34k | — | ~3.6k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 31 | Automates phishing incident response by calling the Splunk SOAR (Phantom) REST API to create containers, attach artifacts (emails, URLs, attachments), and trigger response playbooks. | mukul975/ | 34k | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 32 | Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk… | mukul975/ | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 33 | Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL… | mukul975/ | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 34 | 34.Siem Logging Configure security information and event management (SIEM) systems for threat detection, log aggregation, and compliance. | ancoleman/ | 526 | — | ~3.4k | Automated safety check: Pass | MIT | 10 mo ago |
| 35 | Build effective detection rules using Splunk Search Processing Language (SPL) correlation searches to identify security threats in SOC environments. | mukul975/ | 34k | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 36 | Leverages Splunk Enterprise Security and SPL (Search Processing Language) to investigate security incidents through log correlation, timeline reconstruction, and anomaly detection. | mukul975/ | 34k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 37 | Detect Kerberos Golden Ticket forgery (e.g. An agent skill from mukul975/Anthropic-Cybersecurity-Skills. | mukul975/ | 34k | — | ~677 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 38 | Detect Kerberos Pass-the-Ticket (PtT) attacks by analyzing Windows Event IDs 4768, 4769, and 4771 for anomalous ticket usage patterns, with detection queries for Splunk and Elastic SIEM. | mukul975/ | 34k | — | ~717 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 39 | Configures Fluent Bit as an endpoint log forwarder and Fluentd as the central aggregator for centralized log collection, routing, filtering, and enrichment, covering input plugins for… | mukul975/ | 34k | — | ~697 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 40 | Tune SIEM detection rules in Splunk and Elastic to reduce false positives by analyzing alert volumes, creating context-aware exclusion lists, adjusting thresholds against environmental baselines… | mukul975/ | 34k | — | ~657 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 41 | Engineer and audit SIEM detection rules — log source coverage, Sigma / KQL / SPL / Elastic query authoring, MITRE ATT&CK mapping, false-positive tuning, and detection-as-code workflows. | briiirussell/ | 412 | — | ~2.6k | Automated safety check: Notes | MIT | 4 mo ago |
| 42 | Run hypothesis-driven threat hunts across endpoint, network, cloud, and identity telemetry using stack counting, outlier analysis, and ATT&CK-based hypotheses, with SIEM query patterns for Splunk… | trilwu/ | 156 | — | ~3.5k | Automated safety check: Pass | MIT | 1 mo ago |
| 43 | Conducts digital forensics investigations following a personal data breach, covering evidence preservation, chain of custody documentation, log analysis, scope determination, and root cause analysis. | mukul975/ | 295 | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | 6 mo ago |
| 44 | Triage AEM Workflow issues on AEM 6.5 LTS and AMS by classifying symptoms, gathering the right logs and metrics, and mapping to runbooks or Splunk searches. | adobe/ | 195 | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | today |
| 45 | Triage AEM Workflow issues on AEM as a Cloud Service by classifying symptoms, gathering the right logs and metrics, and mapping to runbooks or Splunk searches. | adobe/ | 195 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | today |
| 46 | Execute and validate SPL (Search Processing Language) queries. | automateyournetwork/ | 674 | — | ~439 | Automated safety check: Pass | Apache-2.0 | yesterday |
| 47 | 47.Soc Analyst Security operations center expertise covering SIEM query writing, alert triage workflows, incident investigation procedures, IOC analysis, threat hunting techniques, playbook design, log analysis… | FerroxLabs/ | 608 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | yesterday |
Questions, answered from the data.
What is the best Splunk skill?
Doca Argus (official) from NVIDIA/skills ranks first of the 47 Splunk skills listed here, with the highest score: its repository has 3.5k GitHub stars, its SKILL.md loads about 4.8k tokens and it passes the automated safety check with no findings. Next come Axiom Dashboard Builder and Spa Create Config.
Is there an official Splunk skill?
1 of the 47 Splunk skills are official, published by the vendor's own GitHub organization: Doca Argus.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.