Spa Add Test Scenario
splunk/splunk-platform-automator
A skill your agent uses when adding app scope/routing test coverage (deployer, CM, DS, direct).
Creates SC4S syslog-ng parsers. An agent skill from splunk/splunk-connect-for-syslog.
$ npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install splunk/splunk-connect-for-syslog parser-creator --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/splunk/splunk-connect-for-syslog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/parser-creator .claude/skills/parser-creator && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "parser-creator" agent skill from https://github.com/splunk/splunk-connect-for-syslog/tree/main/.agents/skills/parser-creator into .claude/skills/parser-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "parser-creator", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/splunk/splunk-connect-for-syslog/tree/main/.agents/skills/parser-creatorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install splunk/splunk-connect-for-syslog parser-creator --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/splunk/splunk-connect-for-syslog.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/parser-creator .agents/skills/parser-creator && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "parser-creator" agent skill from https://github.com/splunk/splunk-connect-for-syslog/tree/main/.agents/skills/parser-creator into .agents/skills/parser-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "parser-creator", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install splunk/splunk-connect-for-syslog parser-creator --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/splunk/splunk-connect-for-syslog.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/parser-creator .cursor/skills/parser-creator && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "parser-creator" agent skill from https://github.com/splunk/splunk-connect-for-syslog/tree/main/.agents/skills/parser-creator into .cursor/skills/parser-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "parser-creator", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/splunk/splunk-connect-for-syslog.git --path .agents/skills/parser-creator--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install splunk/splunk-connect-for-syslog parser-creator --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/splunk/splunk-connect-for-syslog.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/parser-creator .gemini/skills/parser-creator && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "parser-creator" agent skill from https://github.com/splunk/splunk-connect-for-syslog/tree/main/.agents/skills/parser-creator into .gemini/skills/parser-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "parser-creator", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install splunk/splunk-connect-for-syslog parser-creatorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/splunk/splunk-connect-for-syslog.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/parser-creator .github/skills/parser-creator && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "parser-creator" agent skill from https://github.com/splunk/splunk-connect-for-syslog/tree/main/.agents/skills/parser-creator into .github/skills/parser-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "parser-creator", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install splunk/splunk-connect-for-syslog parser-creator --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/splunk/splunk-connect-for-syslog.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/parser-creator .opencode/skills/parser-creator && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "parser-creator" agent skill from https://github.com/splunk/splunk-connect-for-syslog/tree/main/.agents/skills/parser-creator into .opencode/skills/parser-creator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "parser-creator", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
parser-creatorCreates SC4S syslog-ng parsers. An agent skill from splunk/splunk-connect-for-syslog.
Parser Creator is an agent skill from splunk/splunk-connect-for-syslog. Creates SC4S syslog-ng parsers. Use when the user wants to create a new parser, add support for a new log source or vendor, or says "create parser", "add parser", "new log source", or "new vendor support".
Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/testing-parsers.md`).
It sits in Testing & QA. It works with Splunk. The repository describes itself as: Splunk Connect for Syslog. The licence is Apache-2.0.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit a7d1ca1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
poetryFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
opensource.orgFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Parser Creator loads about 4.3k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 688 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from splunk/splunk-connect-for-syslog at commit a7d1ca1, republished under its Apache-2.0 licence (© splunk). 688 words, ~4,306 tokens.
.claude/skills/parser-creator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.You can use only command to run the unit tests poetry run pytest test-name -v -s --tb=short -n=0 -k 'not lite and not name_cache'
Create a new SC4S parser and test coverage for a vendor/product pair in both:
package/etc/conf.d/conflib)package/lite/etc/addons)Collect this information from the user before you start:
vendor: vendor name (lowercase, for example acme)product: product name (lowercase, for example firewall)sourcetype: target Splunk sourcetype using vendor:product (for example acme:firewall)index: target Splunk index (for example netfw)sample logs: one or more raw syslog messagesIf any item is missing, ask for it before proceeding.
Examine the sample logs and identify the Syslog format.
<PRI>TIMESTAMP HOSTNAME PROGRAM: MESSAGE<PRI>VERSION TIMESTAMP HOSTNAME APP-NAME PROCID MSGID SDATA MESSAGE<PRI>TIMESTAMP HOSTNAME CEF:0|<Device Vendor>|<Device Product>|<Device Version>|<Signature ID>|<Name>|<Severity>|<Extension fields>If logs do not match one of these formats, tell the user the format is currently unsupported and stop.
Start by creating a filter for the log message. Filter has a following structure:
application <filter-name>[<topic>] {
filter {
<filter_block>
};
parser { <parser-name>(); };
};Filter are grouped into topics. Use one of the following topics:
cef - for CEF-formatted messages. Example:application app-cef-a10_vthunder[cef] {
filter{
match("A10" value(".metadata.cef.device_vendor"))
and match("vThunder" value(".metadata.cef.device_product"));
};
parser { app-cef-a10_vthunder(); };
};sc4s-syslog-pgm - matches by program value (PROGRAM in RFC3164, APP-NAME in RFC5424). Example:application app-syslog-alcatel_switch[sc4s-syslog-pgm] {
filter {
program('swlogd' type(string) flags(prefix));
};
parser { app-syslog-alcatel_switch(); };
};sc4s-syslog-sdata - matches by structured data (often a Private Enterprise Number, PEN). If PEN is present, prefer this topic. Example:application app-syslog-f5_bigip_structured[sc4s-syslog-sdata] {
filter {
match('^\[F5@12276' value("SDATA"))
;
};
parser { app-syslog-f5_bigip_structured(); };
};sc4s-syslog - general filter for RFC3164/RFC5424, usually based on message content. Example:application app-syslog-arista_eos[sc4s-syslog] {
filter {
program('^[A-Z]\S+$')
and message('%' type(string) flags(prefix));
};
parser { app-syslog-arista_eos(); };
};sc4s-network-source - matches by destination port. Use this only when other topics are not viable. Because this requires sending logs to a new port, ask the user for permission first. If the user refuses, stop and explain why parser creation cannot continue. Example:application app-netsource-brocade_syslog[sc4s-network-source] {
filter {
not filter(f_is_source_identified)
and (
(
match("brocade", value('.netsource.sc4s_vendor'), type(string))
and match("syslog", value('.netsource.sc4s_product'), type(string))
)
or (tags("ns_vendor:brocade") and tags("ns_product:syslog"))
or tags(".source.s_BROCADE")
or "${.netsource.sc4s_vendor_product}" eq "brocade_syslog"
)
};
parser { app-netsource-brocade_syslog(); };
};Next create block parser:
block parser <parser-name>() {
<parsers and filters blocks>
<rewrite block>
};If structured data or repeated key/value data exists, include a parser stage (kv-parser, csv-parser, or regexp-parser) before rewrite. Only skip parsing when the message is truly unstructured; if so, explicitly state this in the final response.
There are two rewrite functions. Choose the correct one:
r_set_splunk_dest_default — sets all base Splunk metadata. Every parser MUST call this exactly once as its first rewrite. Always include index, sourcetype, vendor, and product. Optionally include source and template.r_set_splunk_dest_update_v2 — conditionally overrides specific fields that were already set by r_set_splunk_dest_default. Use this ONLY in if/elif branches to change a subset of fields (e.g. sourcetype, index) based on message content. Never use it as the first or only rewrite.r_set_splunk_dest_default example (required in every parser):
rewrite {
r_set_splunk_dest_default(
index('netops')
sourcetype('alcatel:switch')
vendor("alcatel")
product("switch")
template('t_hdr_msg')
);
};r_set_splunk_dest_update_v2 example (optional, only after default is set):
rewrite {
r_set_splunk_dest_update_v2(
sourcetype('citrix:netscaler:appfw') condition(message(':(\s+\S+)?\s+APPFW(\s+\S+){3}\s+:'))
);
};To choose correct template refer to the definitions in file: t_templates.conf.
Parser method selection:
Use kv-parser when logs contain key/value pairs (key=value, quoted values, RFC5424 SDATA blocks).
template("${SDATA}")..values.sdata..Example:
block parser app-syslog-vendor_product() {
channel {
parser {
kv-parser(prefix(".values.") template("$(template t_hdr_msg)"));
};
# Optional: validate parsing succeeded
filter {
"${.values.some_required_field}" ne ""
};
rewrite {
r_set_splunk_dest_default(
index('netfw')
sourcetype('vendor:product')
vendor("vendor")
product("product")
template('t_kv_values')
);
};
};
};Use csv-parser when logs are consistently delimited and have stable column order.
Example:
parser {
csv-parser(
columns("col1","col2","col3","col4")
prefix(".values.")
delimiters(',')
quote-pairs('""')
flags(escape-double-char)
);
};Use regexp-parser when logs are structured but not key/value or delimited.
Combine methods when logs have multiple variants.
Example:
parser {
regexp-parser(
template("${MESSAGE}")
patterns("^(?<field1>\\d+) (?<field2>[^ ]+) (?<field3>.*)")
prefix(".parsed.")
);
};You can combine all methods and use conditional branches to parse different message variants:
block parser app-syslog-vendor_product() {
channel {
rewrite {
r_set_splunk_dest_default(
index("netops")
sourcetype('vendor:log')
vendor("vendor")
product('product')
template('t_msg_only')
);
};
if (message(',TRAFFIC,' type(string) flags(substring))) {
parser { csv-parser(columns(...) prefix(".values.") delimiters(',')); };
rewrite {
r_set_splunk_dest_update_v2(
index('netfw')
class('traffic')
sourcetype('vendor:traffic')
);
};
} elif (message(',SYSTEM,' type(string) flags(substring))) {
parser { csv-parser(columns(...) prefix(".values.") delimiters(',')); };
rewrite {
r_set_splunk_dest_update_v2(
index('netops')
class('system')
sourcetype('vendor:system')
);
};
} else { };
};
};Ask the user whether they want to create a unit test. Use this prompt:
Do you also want to create a unit test for this parser?Create a unit test for the new parser. Testing instructions: testing-parsers.
This step applies only if Step 4 was not skipped.
Ask the user whether they want to run the unit tests. Use this prompt:
We use Docker Compose to run containerized SC4S and Splunk instances for running unit tests. If you do not have Docker Compose or do not want to run the unit tests, skip this step.Run the new test using poetry run pytest test-name -v -s --tb=short -n=0 -k 'not lite and not name_cache' and verify the parser works correctly.
User input:
vendor: thinkst
product: canary
sourcetype: thinkst:canary
index: netfw
logs:
<130>1 2025-04-30T12:09:54.681299+00:00 mycompany-com ThinkstCanary 3545385 newincident
[BasicIncidentDetails@51136 Description="Web Bug Canarytoken triggered"
Timestamp="2025-04-30 12:07:53 (UTC)" Reminder="q" Token="d7a7phdpurh2vs8gs1jbniyhb"
SourceIP="192.168.1.97" IncidentHash="40a96cf3ba4596a81f18990143916b3c" eventid="17000"]
[AdditionalIncidentDetails@51136
Abbr="SAST" Accept="text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7"
Accept-Encoding="gzip, deflate" Accept-Language="en-GB,en-US;q=0.9,en;q=0.8,ro;q=0.7"
BackgroundContext="You have had 214 incidents from 192.168.1.97 previously."
Browser="Chrome" Cache-Control="max-age=0" City="Cape Town" Connection="keep-alive"
ContinentCode="AF" Country="South Africa" CountryCode="ZA" CountryCode3="ZAF" CurrencyCode="ZAR"
Date="2025-04-30" DstPort="80" Enabled="1" Host="123456789abe[.\]o3n[.\]io" HostDomain=""
Hostname="" Id="Africa/Johannesburg" Installed="1" Ip="192.168.1.97" IsBogon="False"
IsProxy="False" IsTor="False" IsV4Mapped="False" IsV6="False" IsVpn="False" Language="en-GB"
LanguageCode="zu" Latitude="-33.925552" Longitude="18.422857"
Mimetypes="Portable Document Format;pdf;application/pdf|||Portable Document Format;pdf;text/pdf|||"
Name="South Africa Standard Time" Offset="+02:00" Os="Macintosh" Platform="MacIntel"
Region="Western Cape" RegionCode="WC" SrcPort="54290" Time="14:07:53.846452"
Upgrade-Insecure-Requests="1"
User-Agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
Valid="True" Vendor="Google Inc." Version="135.0.0.0"]
A Web Bug Canarytoken was triggered by '192.168.1.97'.
<130>1 2025-04-30T12:54:52.796337+00:00 mycompany-com ThinkstCanary 3557764 newincident
[BasicIncidentDetails@51136 Description="DNS Canarytoken triggered"
Timestamp="2025-04-30 12:52:49 (UTC)" Reminder="q" Token="vv4x12n26ivmcgyd33pkb3drr"
SourceIP="1.1.1.1" IncidentHash="adaa8486af78cc450417b027e2821a22" eventid="16000"]
[AdditionalIncidentDetails@51136 BackgroundContext="This alert is the first from 1.1.1.1."
DstPort="53" Hostname="VV4x12N26IvMcgyd33pKB3DRr[.\]123456789abe[.\]o3N[.\]Io" SrcPort="48908"]
A DNS Canarytoken was triggered by a DNS query from the source IP 1.1.1.1.
Please note that the source IP refers to a DNS resolver, rather than the host that triggered the token.Created parser:
block parser app-syslog-thinkst_canary() {
channel {
parser {
kv-parser(
prefix(".values.sdata.")
template("${SDATA}")
);
};
rewrite {
r_set_splunk_dest_default(
index('netfw')
sourcetype('thinkst:canary')
vendor("thinkst")
product("canary")
template('t_5424_hdr_sdata_compact')
);
};
};
};
application app-syslog-thinkst_canary[sc4s-syslog-sdata] {
filter {
filter(f_is_rfc5424)
and program("ThinkstCanary")
and match('@51136' value("SDATA"));
};
parser { app-syslog-thinkst_canary(); };
};Created unit test:
# Copyright 2026 Splunk, Inc.
#
# Use of this source code is governed by a BSD-2-clause-style
# license that can be found in the LICENSE-BSD2 file or at
# https://opensource.org/licenses/BSD-2-Clause
import datetime
import pytest
from jinja2 import Environment, select_autoescape
from .sendmessage import sendsingle
from .splunkutils import splunk_single
from .timeutils import time_operations
env = Environment(autoescape=select_autoescape(default_for_string=False))
@pytest.mark.addons("thinkst")
@pytest.mark.parametrize(
"procid,basic_details,additional_details,incident_message",
[
(
"3545385",
'[BasicIncidentDetails@51136 Description="Web Bug Canarytoken triggered" Timestamp="2025-04-30 12:07:53 (UTC)" Reminder="q" Token="d7a7phdpurh2vs8gs1jbniyhb" SourceIP="192.168.1.97" IncidentHash="40a96cf3ba4596a81f18990143916b3c" eventid="17000"]',
'[AdditionalIncidentDetails@51136 Abbr="SAST" Accept="text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" Accept-Encoding="gzip, deflate" Accept-Language="en-GB,en-US;q=0.9,en;q=0.8,ro;q=0.7" BackgroundContext="You have had 214 incidents from 192.168.1.97 previously." Browser="Chrome" Cache-Control="max-age=0" City="Cape Town" Connection="keep-alive" ContinentCode="AF" Country="South Africa" CountryCode="ZA" CountryCode3="ZAF" CurrencyCode="ZAR" Date="2025-04-30" DstPort="80" Enabled="1" Host="123456789abe[.\\]o3n[.\\]io" HostDomain="" Hostname="" Id="Africa/Johannesburg" Installed="1" Ip="192.168.1.97" IsBogon="False" IsProxy="False" IsTor="False" IsV4Mapped="False" IsV6="False" IsVpn="False" Language="en-GB" LanguageCode="zu" Latitude="-33.925552" Longitude="18.422857" Mimetypes="Portable Document Format;pdf;application/pdf|||Portable Document Format;pdf;text/pdf|||" Name="South Africa Standard Time" Offset="+02:00" Os="Macintosh" Platform="MacIntel" Region="Western Cape" RegionCode="WC" SrcPort="54290" Time="14:07:53.846452" Upgrade-Insecure-Requests="1" User-Agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" Valid="True" Vendor="Google Inc." Version="135.0.0.0"]',
"A Web Bug Canarytoken was triggered by '192.168.1.97'.",
),
(
"3557764",
'[BasicIncidentDetails@51136 Description="DNS Canarytoken triggered" Timestamp="2025-04-30 12:52:49 (UTC)" Reminder="q" Token="vv4x12n26ivmcgyd33pkb3drr" SourceIP="1.1.1.1" IncidentHash="adaa8486af78cc450417b027e2821a22" eventid="16000"]',
'[AdditionalIncidentDetails@51136 BackgroundContext="This alert is the first from 1.1.1.1." DstPort="53" Hostname="VV4x12N26IvMcgyd33pKB3DRr[.\\]123456789abe[.\\]o3N[.\\]Io" SrcPort="48908"]',
"A DNS Canarytoken was triggered by a DNS query from the source IP 1.1.1.1. Please note that the source IP refers to a DNS resolver, rather than the host that triggered the token.",
),
],
)
def test_thinkst_canary(
record_property,
get_host_key,
setup_splunk,
setup_sc4s,
procid,
basic_details,
additional_details,
incident_message,
):
host = get_host_key
dt = datetime.datetime.now(datetime.timezone.utc)
iso, _, _, _, _, _, epoch = time_operations(dt)
# Tune time functions
epoch = epoch[:-3]
mt = env.from_string(
"{{ mark }} {{ iso }} {{ host }} ThinkstCanary {{ procid }} newincident {{ basic_details }} {{ additional_details }} {{ incident_message }}\n"
)
message = mt.render(
mark="<130>1",
iso=iso,
host=host,
procid=procid,
basic_details=basic_details,
additional_details=additional_details,
incident_message=incident_message,
)
sendsingle(message, setup_sc4s[0], setup_sc4s[1][514])
st = env.from_string(
'search _time={{ epoch }} index=netfw host="{{ host }}" sourcetype="thinkst:canary"'
)
search = st.render(epoch=epoch, host=host)
result_count, _ = splunk_single(setup_splunk, search)
record_property("host", host)
record_property("resultCount", result_count)
record_property("message", message)
assert result_count == 1Before finishing, confirm all items:
kv-parser, csv-parser, and/or regexp-parser) when sample logs are parseable.addon_metadata.yaml) when required.package/lite/etc/config.yaml updated for new lite vendor addon.block parser definition and only one application definition.© splunk, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in .agents/skills/parser-creator of splunk/splunk-connect-for-syslog.
Open the folder on GitHubat commit a7d1ca1
Parser Creator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Parser Creator this skillsplunk/splunk-connect-for-syslog | 180 | — | ~4.3k | Automated safety check: Pass | Apache-2.0 | |
| Spa Add Test Scenariosplunk/splunk-platform-automator | 137 | — | ~2.2k | Automated safety check: Pass | Proprietary | |
| Web Application Testinganthropics/skills | 180k | 51 repos | ~966 | Automated safety check: Pass | Apache-2.0 | |
| Diagnosing Bugsfossasia/eventyay-interpretation | 1.6k | 31 repos | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| TDDfossasia/eventyay-interpretation | 1.6k | 28 repos | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| TDD WorkflowhellangleZ/burn-in-cceverywhere-ralph | 112 | 11 repos | ~2.4k | Automated safety check: Pass | None |
splunk/splunk-platform-automator
A skill your agent uses when adding app scope/routing test coverage (deployer, CM, DS, direct).
anthropics/skills
Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.
fossasia/eventyay-interpretation
Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.
fossasia/eventyay-interpretation
Test-driven development. An agent skill from fossasia/eventyay-interpretation.
hellangleZ/burn-in-cceverywhere-ralph
A skill your agent uses when writing new features, fixing bugs, or refactoring code.
sanity-io/sanity
Test-driven development with red-green-refactor loop. An agent skill from sanity-io/sanity.
Works with
Categories
Creates SC4S syslog-ng parsers. An agent skill from splunk/splunk-connect-for-syslog. Parser Creator is an agent skill from splunk/splunk-connect-for-syslog. Creates SC4S syslog-ng parsers.
Parser Creator fits situations like: the user wants to create a new parser; add support for a new log source; says create parser; new vendor support.
Run `npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a claude-code`. Or copy the skill folder (.agents/skills/parser-creator in splunk/splunk-connect-for-syslog) into .claude/skills/parser-creator in your project. Claude Code loads it when a task matches its description.
Run `npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a codex`. Or copy the skill folder (.agents/skills/parser-creator in splunk/splunk-connect-for-syslog) into .agents/skills/parser-creator in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/parser-creator, .gemini/skills/parser-creator, .github/skills/parser-creator and .opencode/skills/parser-creator in your project.
Going by SKILL.md and its folder, Parser Creator needs the command-line tools its instructions call (poetry). Our summary lists: Docker.
SKILL.md names 1 domain. In commands or code: opensource.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Parser Creator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Parser Creator: Spa Add Test Scenario (splunk/splunk-platform-automator, 137 stars), Web Application Testing (anthropics/skills, 180k stars), Diagnosing Bugs (fossasia/eventyay-interpretation, 1.6k stars) and TDD (fossasia/eventyay-interpretation, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
splunk (a GitHub organization) maintains it in splunk/splunk-connect-for-syslog, which has 180 GitHub stars. The repository was last updated on October 6, 2026.
Source: splunk/splunk-connect-for-syslog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.