Agent skill

Splunk Spl2 Pipeline Kit

by Kilo-Org in Kilo-Org/kilo-marketplace

Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats…

Apache-2.0Auto-check passedDevelopment

Install Splunk Spl2 Pipeline Kit

skills CLI
$ npx skills add Kilo-Org/kilo-marketplace --skill splunk-spl2-pipeline-kit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Kilo-Org/kilo-marketplace splunk-spl2-pipeline-kit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/splunk-spl2-pipeline-kit .claude/skills/splunk-spl2-pipeline-kit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
splunk-spl2-pipeline-kit
GitHub stars
190
Token cost
~910 tokens
SKILL.md length
283 words
Files
10 (incl. scripts, references)
Skills in repo
86
Repo updated
First seen
Licence
Apache-2.0

At a glance

Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats…

  • The user needs SPL2 pipeline authoring
  • SKILL.md covers Agent Behavior, Quick Start, Outputs and Guardrails
  • Runs Shell and Python scripts from its folder; calls bash
  • Conversion review

What it does

Splunk Spl2 Pipeline Kit is an agent skill from Kilo-Org/kilo-marketplace. Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats, custom templates, SPL-to-SPL2 compatibility, and PCRE2 migration checks. Use when the user needs SPL2 pipeline authoring, conversion review, compatibility linting, or shared templates for Ingest Processor or Edge Processor workflows, including Cisco Data Fabric or telemetry pipeline management requests that need…

Its SKILL.md is about 910 tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `agents/openai.yaml`, `reference.md` and `references/research-ledger.md`).

It sits in Development, covering Linting and formatting and CRM management. It works with Splunk. The repository describes itself as: Kilo Marketplace - A curated collection of Skills, MCP Servers, and Modes for enhancing AI agent capabilities across the Kilo ecosystem—including Kilo Code (VS Code extension)… The licence is Apache-2.0.

When your agent uses it

  • The user needs SPL2 pipeline authoring
  • Conversion review
  • Compatibility linting
  • Shared templates for Ingest Processor

Example prompts

  • “/splunk-spl2-pipeline-kit”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit ff51758. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (Shell and Python), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Splunk Spl2 Pipeline Kit loads about 910 tokens when it runs, and up to ~1.1k if it reads all its reference files. Until then it costs about 141 tokens; SKILL.md has 283 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~141
When it runs · the whole SKILL.md, loaded when a task matches
~910
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from Kilo-Org/kilo-marketplace at commit ff51758, republished under its Apache-2.0 licence (© Kilo-Org). 283 words, ~910 tokens.

Download SKILL.mdSave it as .claude/skills/splunk-spl2-pipeline-kit/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
splunk-spl2-pipeline-kit
description
Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats, custom templates, SPL-to-SPL2 compatibility, and PCRE2 migration checks. Use when the user needs SPL2 pipeline authoring, conversion review, compatibility linting, or shared templates for Ingest Processor or Edge Processor workflows, including Cisco Data Fabric or telemetry pipeline management requests that need reusable SPL2 pipeline logic.
metadata.category
observability

Splunk SPL2 Pipeline Kit

This skill is the shared SPL2 authoring and validation surface for splunk-ingest-processor-setup and splunk-edge-processor-setup. It is offline-only: it renders starter SPL2, lints pipeline files, and reports profile compatibility issues without calling Splunk APIs.

For newer Cisco Data Fabric wording, this is the reusable SPL2 authoring route. Native Observability Metrics Pipeline Management remains a separate UI workflow covered by splunk-observability-deep-native-workflows.

Agent Behavior

  • Use ingestProcessor for Splunk-hosted Ingest Processor pipelines.
  • Use edgeProcessor for Edge Processor pipelines.
  • Keep real samples, private keys, HEC tokens, Observability tokens, and lookup contents out of chat and rendered files. Render placeholders and file-path handoffs only.
  • Treat SPL-to-SPL2 conversion as review assistance. Splunk's in-product conversion tool remains the authoritative conversion workflow.
  • Read reference.md before changing supported commands, templates, or lint rules.

Quick Start

Render every template and lint the rendered output:

bash
bash skills/splunk-spl2-pipeline-kit/scripts/setup.sh --phase all --profile both

Lint a user-provided pipeline:

bash
bash skills/splunk-spl2-pipeline-kit/scripts/setup.sh \
  --phase lint \
  --profile ingestProcessor \
  --pipeline-file pipelines/my_pipeline.spl2

Run the offline smoke test:

bash
bash skills/splunk-spl2-pipeline-kit/scripts/smoke_offline.sh

Outputs

The default output directory is splunk-spl2-pipeline-kit-rendered/:

  • templates/<profile>/*.spl2 - route, branch, redact, sample, lookup, extract, timestamp, JSON/XML, OCSF, decrypt, metrics, stats, S3, and compatibility starters where supported.
  • custom-template-app/default/data/spl2/*.spl2 - SPL2 custom template module examples using @template and runtime profile metadata.
  • lint-report.json and lint-report.md.
  • coverage-report.json.

Guardrails

  • logs_to_metrics requires an import logs_to_metrics from /splunk.ingest.commands style import and is Ingest Processor-only.
  • decrypt is Ingest Processor-only and must be treated as a private-key lookup handoff. Do not render private-key material.
  • stats linting rejects avg() because Ingest Processor documents sum()/count() as the supported average pattern. Edge Processor stats is supported and includes newer state-window behavior on current EP versions.
  • object_to_array() is deprecated in SPL2 release notes; use json_entries().
  • Regex guidance is PCRE2-oriented. Prefer named captures like (?P<fieldName>...).
  • Edge Processor-only and Ingest Processor-only differences are reported in the lint output rather than hidden in comments.

© Kilo-Org, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in skills/splunk-spl2-pipeline-kit of Kilo-Org/kilo-marketplace.

  • SKILL.md
  • LICENSE
  • agents/openai.yaml
  • reference.md
  • references/research-ledger.md
  • scripts/setup.sh
  • scripts/smoke_offline.sh
  • scripts/spl2_pipeline_kit.py
  • scripts/validate.sh
  • template.example

Open the folder on GitHubat commit ff51758

Compare with similar skills

Splunk Spl2 Pipeline Kit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Splunk Spl2 Pipeline Kit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Splunk Spl2 Pipeline Kit this skillKilo-Org/kilo-marketplace190—~910Automated safety check: PassApache-2.0
Dx Code Analyzer Runforcedotcom/sf-skills1.1k—~6.3kAutomated safety check: PassApache-2.0
Mobile Platform Offline Validateforcedotcom/sf-skills1.1k—~2kAutomated safety check: PassApache-2.0
Minimizing Ty Ecosystem Changesastral-sh/ruff50k—~4.6kAutomated safety check: PassMIT
Install Anti-Slop Oxlint Rulesdmmulroy/anti-slop5.3k—~2.2kAutomated safety check: PassMIT
Babysit PR To Pass CIsgl-project/sglang37k2 repos~3kAutomated safety check: PassApache-2.0

Similar skills

  • Dx Code Analyzer Run

    forcedotcom/sf-skills

    Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.

    1.1k GitHub stars~6.3k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Review a Lightning Web Component for mobile offline compatibility — the Komaci offline static analyzer that pre-primes the data graph for Salesforce Mobile App Plus and Field Service Mobile App.

    1.1k GitHub stars~2k tokensUpdated 2 days ago
    Sales & SupportAuto-check passed
  • Official

    A skill your agent uses when a user says "minimize this ty ecosystem change", "reproduce this ecosystem result", "investigate a primer difference", "investigate a mypyprimer difference"…

    50k GitHub stars~4.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub stars~2.2k tokensUpdated 29 days ago
    DevelopmentAuto-check passed
  • Babysit PR To Pass CI

    sgl-project/sglang

    Start and persistently pursue a goal to babysit an SGLang pull request until selected GitHub Actions workflows pass on the latest PR head.

    37k GitHub starsUsed in 2 repos~3k tokens
    DevelopmentAuto-check passed
  • Guide for writing idiomatic Rust code based on Apollo GraphQL's best practices handbook.

    5.6k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed

More from Kilo-Org/kilo-marketplace

All 86 skills in this repo
  • AzureML Project Scaffolding

    Kilo-Org/kilo-marketplace

    Sets up and maintains AzureML-ready Python projects as uv workspaces with devcontainers, a Makefile and job YAML, so local runs match cloud jobs and experiments stay reproducible.

    190 GitHub stars~3.1k tokensUpdated 10 days ago
    Auto-check: notes
  • Jupyter Notebook Builder

    Kilo-Org/kilo-marketplace

    Creates, inspects, edits and runs Jupyter notebooks, scaffolding experiment or tutorial notebooks from templates and preferring a Jupyter MCP server over raw JSON edits.

    190 GitHub stars~1.3k tokensUpdated 10 days ago
    Auto-check passed
  • Tableau Dashboard Creator

    Kilo-Org/kilo-marketplace

    Takes a plain-language dashboard request through brand setup, data exploration, planning, an interactive HTML mock and a Tableau implementation spec.

    190 GitHub stars~3.8k tokensUpdated 10 days ago
    Auto-check: notes
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 10 days ago
    Auto-check passed
  • Nifi Flow Layout

    Kilo-Org/kilo-marketplace

    A skill your agent uses when arranging Apache NiFi processors, process groups, ports, comments, numbering, crossing connections, dense fan-in/fan-out, or reusable readable canvas layouts.

    190 GitHub stars~1.5k tokensUpdated 10 days ago
    Auto-check passed
  • Splunk Ingest Processor Setup

    Kilo-Org/kilo-marketplace

    Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and…

    190 GitHub stars~1.2k tokensUpdated 10 days ago
    Auto-check passed

Works with

Categories

Questions about Splunk Spl2 Pipeline Kit

What does Splunk Spl2 Pipeline Kit do?

Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats…. Splunk Spl2 Pipeline Kit is an agent skill from Kilo-Org/kilo-marketplace. Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats, custom templates, SPL-to-SPL2 compatibility, and PCRE2 migration checks.

When should I use Splunk Spl2 Pipeline Kit?

Splunk Spl2 Pipeline Kit fits situations like: the user needs SPL2 pipeline authoring; conversion review; compatibility linting; shared templates for Ingest Processor.

How do I install Splunk Spl2 Pipeline Kit in Claude Code?

Run `npx skills add Kilo-Org/kilo-marketplace --skill splunk-spl2-pipeline-kit -a claude-code`. Or copy the skill folder (skills/splunk-spl2-pipeline-kit in Kilo-Org/kilo-marketplace) into .claude/skills/splunk-spl2-pipeline-kit in your project. Claude Code loads it when a task matches its description.

How do I install Splunk Spl2 Pipeline Kit in Codex?

Run `npx skills add Kilo-Org/kilo-marketplace --skill splunk-spl2-pipeline-kit -a codex`. Or copy the skill folder (skills/splunk-spl2-pipeline-kit in Kilo-Org/kilo-marketplace) into .agents/skills/splunk-spl2-pipeline-kit in your project. Codex loads it when a task matches its description.

Can I use Splunk Spl2 Pipeline Kit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Kilo-Org/kilo-marketplace --skill splunk-spl2-pipeline-kit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/splunk-spl2-pipeline-kit, .gemini/skills/splunk-spl2-pipeline-kit, .github/skills/splunk-spl2-pipeline-kit and .opencode/skills/splunk-spl2-pipeline-kit in your project.

What does Splunk Spl2 Pipeline Kit need to run?

Going by SKILL.md and its folder, Splunk Spl2 Pipeline Kit needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: Python 3; A Bash shell.

Does Splunk Spl2 Pipeline Kit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Splunk Spl2 Pipeline Kit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Splunk Spl2 Pipeline Kit use?

Splunk Spl2 Pipeline Kit is published under the Apache-2.0 licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Splunk Spl2 Pipeline Kit use?

About 910 tokens (SKILL.md is roughly 3.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 209 tokens, read only when the agent opens those files.

What are the alternatives to Splunk Spl2 Pipeline Kit?

Skills that share tags, products or a category with Splunk Spl2 Pipeline Kit: Dx Code Analyzer Run (forcedotcom/sf-skills, 1.1k stars), Mobile Platform Offline Validate (forcedotcom/sf-skills, 1.1k stars), Minimizing Ty Ecosystem Changes (astral-sh/ruff, 50k stars) and Install Anti-Slop Oxlint Rules (dmmulroy/anti-slop, 5.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Splunk Spl2 Pipeline Kit?

Kilo-Org (a GitHub organization) maintains it in Kilo-Org/kilo-marketplace, which has 190 GitHub stars. The repository holds 86 skills in this directory. The repository was last updated on September 28, 2026.

Source: Kilo-Org/kilo-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.