Agent skill

Spl To Apl

by openclaw in openclaw/clawhub

Translates Splunk SPL queries to Axiom APL. An agent skill from openclaw/clawhub.

MITAuto-check passedWriting & Content

Install Spl To Apl

skills CLI
$ npx skills add openclaw/clawhub --skill spl-to-apl -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install openclaw/clawhub spl-to-apl --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/openclaw/clawhub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/spl-to-apl .claude/skills/spl-to-apl && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spl-to-apl
GitHub stars
9.5k
Token cost
~1.6k tokens
SKILL.md length
398 words
Files
11
Skills in repo
55
Repo updated
First seen
Licence
MIT

At a glance

Translates Splunk SPL queries to Axiom APL. An agent skill from openclaw/clawhub.

  • Works in 4 steps: Time is explicit in APL: SPL time… → Structure: SPL index=... | command → APL… → Join is preview: limited to 50k rows,… → …
  • Migrating from Splunk
  • SKILL.md covers Critical Differences, Core Command Mappings, Stats → Summarize and Eval → Extend, plus 5 more sections
  • Runs TypeScript scripts from its folder

What it does

Spl To Apl is an agent skill from openclaw/clawhub. Translates Splunk SPL queries to Axiom APL. Provides command mappings, function equivalents, and syntax transformations. Use when migrating from Splunk, converting SPL queries, or learning APL equivalents of SPL patterns.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files (for example `.meta/2026-01-28-schema-read-findings.md`, `.meta/DESIGN-NOTES.md` and `.meta/cases.ts`).

It sits in Writing & Content. It works with Splunk. The repository describes itself as: Skill + Plugin Registry for OpenClaw. The licence is MIT.

When your agent uses it

  • Migrating from Splunk
  • Converting SPL queries
  • Learning APL equivalents of SPL patterns

Example prompts

  • “Use the spl-to-apl skill to translate Splunk SPL queries to Axiom APL. An agent skill from openclaw/clawhub”
  • “/spl-to-apl”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Time is explicit in APL: SPL time pickers don't translate — add where _time between (ago(1h) .. now())
  2. Structure: SPL index=... | command → APL ['dataset'] | operator
  3. Join is preview: limited to 50k rows, inner/innerunique/leftouter only
  4. cidrmatch args reversed: SPL cidrmatch(cidr, ip) → APL ipv4_is_in_range(ip, cidr)

What it can do on your machine

Read from SKILL.md and the folder at commit d044664. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • axiom.co

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spl To Apl loads about 1.6k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 398 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from openclaw/clawhub at commit d044664, republished under its MIT licence (© openclaw). 398 words, ~1,596 tokens.

Download SKILL.mdSave it as .claude/skills/spl-to-apl/SKILL.md (or your agent's skills folder). This skill also uses 10 other files; get the full folder from GitHub.
name
spl-to-apl
description
Translates Splunk SPL queries to Axiom APL. Provides command mappings, function equivalents, and syntax transformations. Use when migrating from Splunk, converting SPL queries, or learning APL equivalents of SPL patterns.

SPL to APL Translator

Type safety: Fields like status are often stored as strings. Always cast before numeric comparison: toint(status) >= 500, not status >= 500.


Critical Differences

  1. Time is explicit in APL: SPL time pickers don't translate — add where _time between (ago(1h) .. now())
  2. Structure: SPL index=... | command → APL ['dataset'] | operator
  3. Join is preview: limited to 50k rows, inner/innerunique/leftouter only
  4. cidrmatch args reversed: SPL cidrmatch(cidr, ip) → APL ipv4_is_in_range(ip, cidr)

Core Command Mappings

SPLAPLNotes
search index=...['dataset']Dataset replaces index
search field=valuewhere field == "value"Explicit where
wherewhereSame
statssummarizeDifferent aggregation syntax
evalextendCreate/modify fields
table / fieldsprojectSelect columns
fields -project-awayRemove columns
rename x as yproject-rename y = xRename
sort / sort -order by ... asc/descSort
head Ntake NLimit rows
top N fieldsummarize count() by field | top N by count_Two-step
dedup fieldsummarize arg_max(_time, *) by fieldKeep latest
rexparse or extract()Regex extraction
joinjoinPreview feature
appendunionCombine datasets
mvexpandmv-expandExpand arrays
timechart span=Xsummarize ... by bin(_time, X)Manual binning
rare N fieldsummarize count() by field | order by count_ asc | take NBottom N
spathparse_json() or json['path']JSON access
transactionNo direct equivalentUse summarize + make_list

Complete mappings: reference/command-mapping.md


Stats → Summarize

# SPL
| stats count by status

# APL  
| summarize count() by status
Key function mappings
SPLAPL
countcount()
count(field)countif(isnotnull(field))
dc(field)dcount(field)
avg/sum/min/maxSame
median(field)percentile(field, 50)
perc95(field)percentile(field, 95)
first/lastarg_min/arg_max(_time, field)
list(field)make_list(field)
values(field)make_set(field)
Show full SKILL.md (162 more words)Show less
Conditional count pattern
# SPL
| stats count(eval(status>=500)) as errors by host

# APL
| summarize errors = countif(status >= 500) by host

Complete function list: reference/function-mapping.md


Eval → Extend

# SPL
| eval new_field = old_field * 2

# APL
| extend new_field = old_field * 2
Key function mappings
SPLAPLNotes
if(c, t, f)iff(c, t, f)Double 'f'
case(c1,v1,...)case(c1,v1,...,default)Requires default
len(str)strlen(str)
lower/uppertolower/toupper
substrsubstring0-indexed in APL
replacereplace_string
tonumbertoint/tolong/torealExplicit types
match(s,r)s matches regex "r"Operator
split(s, d)split(s, d)Same
mvjoin(mv, d)strcat_array(arr, d)Join array
mvcount(mv)array_length(arr)Array length
Case statement pattern
# SPL
| eval level = case(
    status >= 500, "error",
    status >= 400, "warning",
    1==1, "ok"
  )

# APL  
| extend level = case(
    status >= 500, "error",
    status >= 400, "warning",
    "ok"
  )

Note: SPL's 1==1 catch-all becomes implicit default in APL.


Rex → Parse/Extract

# SPL
| rex field=message "user=(?<username>\w+)"

# APL - parse with regex
| parse kind=regex message with @"user=(?P<username>\w+)"

# APL - extract function  
| extend username = extract("user=(\\w+)", 1, message)
Simple pattern (non-regex)
# SPL
| rex field=uri "^/api/(?<version>v\d+)/(?<endpoint>\w+)"

# APL
| parse uri with "/api/" version "/" endpoint

Time Handling

SPL time pickers don't translate. Always add explicit time range:

# SPL (time picker: Last 24 hours)
index=logs

# APL
['logs'] | where _time between (ago(24h) .. now())
Timechart translation
# SPL
| timechart span=5m count by status

# APL
| summarize count() by bin(_time, 5m), status

Common Patterns

Error rate calculation
# SPL
| stats count(eval(status>=500)) as errors, count as total by host
| eval error_rate = errors/total*100

# APL
| summarize errors = countif(status >= 500), total = count() by host
| extend error_rate = toreal(errors) / total * 100
Subquery (subsearch)
# SPL
index=logs [search index=errors | fields user_id | format]

# APL
let error_users = ['errors'] | where _time between (ago(1h) .. now()) | distinct user_id;
['logs']
| where _time between (ago(1h) .. now())
| where user_id in (error_users)
Join datasets
# SPL
| join user_id [search index=users | fields user_id, name]

# APL
| join kind=inner (['users'] | project user_id, name) on user_id
Transaction-like grouping
# SPL
| transaction session_id maxspan=30m

# APL (no direct equivalent — reconstruct with summarize)
| summarize 
    start_time = min(_time),
    end_time = max(_time),
    events = make_list(pack("time", _time, "action", action)),
    duration = max(_time) - min(_time)
  by session_id
| where duration <= 30m

String Matching Performance

SPLAPLSpeed
field="value"field == "value"Fastest
field="*value*"field contains "value"Moderate
field="value*"field startswith "value"Fast
match(field, regex)field matches regex "..."Slowest

Prefer has over contains (word-boundary matching is faster). Use _cs variants for case-sensitive (faster).


Reference

  • reference/command-mapping.md — complete command list
  • reference/function-mapping.md — complete function list
  • reference/examples.md — full query translation examples
  • APL docs: https://axiom.co/docs/apl/introduction

© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 10 other files in .agents/skills/spl-to-apl of openclaw/clawhub.

  • SKILL.md
  • .meta/2026-01-28-schema-read-findings.md
  • .meta/DESIGN-NOTES.md
  • .meta/cases.ts
  • .meta/spl-to-apl.eval.ts
  • README.md
  • reference/command-mapping.md
  • reference/dataset-schemas.md
  • reference/examples.md
  • reference/function-mapping.md
  • tests/test-queries.md

Open the folder on GitHubat commit d044664

Compare with similar skills

Spl To Apl next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spl To Apl compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spl To Apl this skillopenclaw/clawhub9.5k—~1.6kAutomated safety check: PassMIT
Socialcoreyhaines31/marketingskills54k4 repos~4.5kAutomated safety check: PassMIT
HumanizerAzure-Samples/interview-coach-agent-framework17237 repos~5.8kAutomated safety check: PassMIT
Avoid AI Writingconorbronsdon/avoid-ai-writing4.9k3 repos~8.1kAutomated safety check: PassMIT
JavaScript Concept Fact Checkerleonardomso/33-js-concepts67k1 repos~5kAutomated safety check: PassMIT
User-Facing Text Cleanupguillaumemeyer/watermarks-remover24k—~3.5kAutomated safety check: PassMIT

Similar skills

  • Social

    coreyhaines31/marketingskills

    When the user wants help creating, scheduling, or optimizing social media content for LinkedIn, Twitter/X, Instagram, TikTok, or Facebook, or wants to do social listening and engagement triage.

    54k GitHub starsUsed in 4 repos~4.5k tokens
    Writing & ContentAuto-check passed
  • Humanizer

    Azure-Samples/interview-coach-agent-framework

    Official

    Remove signs of AI-generated writing from text. An agent skill from Azure-Samples/interview-coach-agent-framework.

    172 GitHub starsUsed in 37 repos~5.8k tokens
    Writing & ContentAuto-check passed
  • Avoid AI Writing

    conorbronsdon/avoid-ai-writing

    Audit and rewrite content to remove AI writing patterns ("AI-isms").

    4.9k GitHub starsUsed in 3 repos~8.1k tokens
    Writing & ContentAuto-check passed
  • JavaScript Concept Fact Checker

    leonardomso/33-js-concepts

    Verifies the technical accuracy of JavaScript concept pages by checking code examples, MDN and ECMAScript claims and external links through a five-phase method.

    67k GitHub starsUsed in 1 repo~5k tokens
    Writing & ContentAuto-check passed
  • User-Facing Text Cleanup

    guillaumemeyer/watermarks-remover

    Audits prose for invisible Unicode characters and rewrites it while keeping facts, citations, code and required disclosures unchanged and the writer's voice intact.

    24k GitHub stars~3.5k tokensUpdated today
    Writing & ContentAuto-check passed
  • Install Anti Slop

    trycompai/crm

    Install and configure the anti-slop Oxlint plugin in a local TypeScript or JavaScript repository.

    11k GitHub starsUsed in 1 repo~881 tokens
    Writing & ContentAuto-check passed

More from openclaw/clawhub

All 55 skills in this repo
  • Creates and manages Axiom monitors and notifiers end to end through the v2 API, with scripts for each CRUD operation and a recommended create-validate-tune workflow.

    9.5k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Axiom Dashboard Builder

    openclaw/clawhub

    Designs and deploys Axiom dashboards through the API, choosing chart types and writing APL or metrics queries, with templates and migration notes for Splunk and Grafana.

    9.5k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Axiom Cost Control

    openclaw/clawhub

    Finds unused data in Axiom by analyzing query patterns, then deploys a cost dashboard and ingest monitors to keep spend under the contract limit.

    9.5k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Axiom Metrics Query

    openclaw/clawhub

    Explores and queries OpenTelemetry metrics in Axiom MetricsDB, listing datasets, metrics and tags first and picking the right aggregation for each metric's type.

    9.5k GitHub stars~2.6k tokensUpdated today
    Auto-check passed
  • Axiom SRE Investigator

    openclaw/clawhub

    Investigates incidents and production problems with hypothesis-driven debugging, queries Axiom observability data when available, and keeps secrets out of commands and output.

    9.5k GitHub stars~7.1k tokensUpdated today
    Auto-check passed
  • Axiom Eval Writer

    openclaw/clawhub

    Scaffolds evaluation suites for the Axiom AI SDK: eval files, scorers, flag schemas and axiom.config.ts, generated from plain descriptions of an AI capability.

    9.5k GitHub stars~4.1k tokensUpdated today
    Auto-check: warnings

Works with

Questions about Spl To Apl

What does Spl To Apl do?

Translates Splunk SPL queries to Axiom APL. An agent skill from openclaw/clawhub. Spl To Apl is an agent skill from openclaw/clawhub. Translates Splunk SPL queries to Axiom APL.

When should I use Spl To Apl?

Spl To Apl fits situations like: migrating from Splunk; converting SPL queries; learning APL equivalents of SPL patterns.

How do I install Spl To Apl in Claude Code?

Run `npx skills add openclaw/clawhub --skill spl-to-apl -a claude-code`. Or copy the skill folder (.agents/skills/spl-to-apl in openclaw/clawhub) into .claude/skills/spl-to-apl in your project. Claude Code loads it when a task matches its description.

How do I install Spl To Apl in Codex?

Run `npx skills add openclaw/clawhub --skill spl-to-apl -a codex`. Or copy the skill folder (.agents/skills/spl-to-apl in openclaw/clawhub) into .agents/skills/spl-to-apl in your project. Codex loads it when a task matches its description.

Can I use Spl To Apl in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/clawhub --skill spl-to-apl -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spl-to-apl, .gemini/skills/spl-to-apl, .github/skills/spl-to-apl and .opencode/skills/spl-to-apl in your project.

What does Spl To Apl need to run?

Going by SKILL.md and its folder, Spl To Apl needs TypeScript for the scripts in its folder. Our summary lists: Node.js.

Does Spl To Apl access the network?

SKILL.md names 1 domain. As links in the text: axiom.co. This is read from the text; nothing was executed.

Is Spl To Apl safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Spl To Apl use?

Spl To Apl is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spl To Apl use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spl To Apl?

Skills that share tags, products or a category with Spl To Apl: Social (coreyhaines31/marketingskills, 54k stars), Humanizer (Azure-Samples/interview-coach-agent-framework, 172 stars), Avoid AI Writing (conorbronsdon/avoid-ai-writing, 4.9k stars) and JavaScript Concept Fact Checker (leonardomso/33-js-concepts, 67k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spl To Apl?

openclaw (a GitHub organization) maintains it in openclaw/clawhub, which has 9,500 GitHub stars. The repository holds 55 skills in this directory. The repository was last updated on October 8, 2026.

Source: openclaw/clawhub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.