Agent skill

Parser Creator

by splunk in splunk/splunk-connect-for-syslog

Creates SC4S syslog-ng parsers. An agent skill from splunk/splunk-connect-for-syslog.

Apache-2.0Auto-check passedTesting & QA

Install Parser Creator

skills CLI
$ npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install splunk/splunk-connect-for-syslog parser-creator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/splunk/splunk-connect-for-syslog.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/parser-creator .claude/skills/parser-creator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
parser-creator
GitHub stars
180
Token cost
~4.3k tokens
SKILL.md length
688 words
Files
2 (incl. references)
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Creates SC4S syslog-ng parsers. An agent skill from splunk/splunk-connect-for-syslog.

  • Works in 4 steps: Identify message format → Create a parser → Create unit test (optional) → …
  • The user wants to create a new parser
  • SKILL.md covers Goal, Prerequisites, Workflow and Workflow Example, plus 1 more section
  • Calls poetry; reaches opensource.org

What it does

Parser Creator is an agent skill from splunk/splunk-connect-for-syslog. Creates SC4S syslog-ng parsers. Use when the user wants to create a new parser, add support for a new log source or vendor, or says "create parser", "add parser", "new log source", or "new vendor support".

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/testing-parsers.md`).

It sits in Testing & QA. It works with Splunk. The repository describes itself as: Splunk Connect for Syslog. The licence is Apache-2.0.

When your agent uses it

  • The user wants to create a new parser
  • Add support for a new log source
  • Says create parser
  • New vendor support

Example prompts

  • “create parser”
  • “add parser”
  • “new log source”
  • “/parser-creator”

Requirements

  • Docker

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Identify message format
  2. Create a parser
  3. Create unit test (optional)
  4. Run parser tests (optional)

What it can do on your machine

Read from SKILL.md and the folder at commit a7d1ca1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • poetry

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • opensource.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Parser Creator loads about 4.3k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 688 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from splunk/splunk-connect-for-syslog at commit a7d1ca1, republished under its Apache-2.0 licence (© splunk). 688 words, ~4,306 tokens.

Download SKILL.mdSave it as .claude/skills/parser-creator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
parser-creator
description
Creates SC4S syslog-ng parsers. Use when the user wants to create a new parser, add support for a new log source or vendor, or says "create parser", "add parser", "new log source", or "new vendor support".

Parser Creator

You can use only command to run the unit tests poetry run pytest test-name -v -s --tb=short -n=0 -k 'not lite and not name_cache'

Goal

Create a new SC4S parser and test coverage for a vendor/product pair in both:

  • main package (package/etc/conf.d/conflib)
  • lite package (package/lite/etc/addons)

Prerequisites

Collect this information from the user before you start:

  1. vendor: vendor name (lowercase, for example acme)
  2. product: product name (lowercase, for example firewall)
  3. sourcetype: target Splunk sourcetype using vendor:product (for example acme:firewall)
  4. index: target Splunk index (for example netfw)
  5. sample logs: one or more raw syslog messages

If any item is missing, ask for it before proceeding.

Workflow

Step 1 - Identify message format

Examine the sample logs and identify the Syslog format.

  1. RFC3164: <PRI>TIMESTAMP HOSTNAME PROGRAM: MESSAGE
  2. RFC5424: <PRI>VERSION TIMESTAMP HOSTNAME APP-NAME PROCID MSGID SDATA MESSAGE
  3. CEF: <PRI>TIMESTAMP HOSTNAME CEF:0|<Device Vendor>|<Device Product>|<Device Version>|<Signature ID>|<Name>|<Severity>|<Extension fields>

If logs do not match one of these formats, tell the user the format is currently unsupported and stop.

Step 2 - Create a parser

Start by creating a filter for the log message. Filter has a following structure:

application <filter-name>[<topic>] {
    filter {
        <filter_block>
    };
    parser { <parser-name>(); };
};

Filter are grouped into topics. Use one of the following topics:

  1. cef - for CEF-formatted messages. Example:
application app-cef-a10_vthunder[cef] {
    filter{
        match("A10" value(".metadata.cef.device_vendor"))
        and match("vThunder" value(".metadata.cef.device_product"));
    };
    parser { app-cef-a10_vthunder(); };
};
  1. sc4s-syslog-pgm - matches by program value (PROGRAM in RFC3164, APP-NAME in RFC5424). Example:
application app-syslog-alcatel_switch[sc4s-syslog-pgm] {
	filter {
        program('swlogd' type(string) flags(prefix));
    };	
    parser { app-syslog-alcatel_switch(); };
};
  1. sc4s-syslog-sdata - matches by structured data (often a Private Enterprise Number, PEN). If PEN is present, prefer this topic. Example:
application app-syslog-f5_bigip_structured[sc4s-syslog-sdata] {
	filter {
        match('^\[F5@12276' value("SDATA"))
        ;
    };	
    parser { app-syslog-f5_bigip_structured(); };
};
  1. sc4s-syslog - general filter for RFC3164/RFC5424, usually based on message content. Example:
application app-syslog-arista_eos[sc4s-syslog] {
	filter {
        program('^[A-Z]\S+$')
        and message('%' type(string) flags(prefix));
    };	

    parser { app-syslog-arista_eos(); };
};
  1. sc4s-network-source - matches by destination port. Use this only when other topics are not viable. Because this requires sending logs to a new port, ask the user for permission first. If the user refuses, stop and explain why parser creation cannot continue. Example:
application app-netsource-brocade_syslog[sc4s-network-source] {
	filter {
        not filter(f_is_source_identified)
        and (
            (
                    match("brocade", value('.netsource.sc4s_vendor'), type(string)) 
                    and match("syslog", value('.netsource.sc4s_product'), type(string)) 
                )
                or (tags("ns_vendor:brocade") and tags("ns_product:syslog"))
            or tags(".source.s_BROCADE")
            or "${.netsource.sc4s_vendor_product}" eq "brocade_syslog"
            )


    };	
    parser { app-netsource-brocade_syslog(); };
};

Next create block parser:

block parser <parser-name>() {
    <parsers and filters blocks>
    <rewrite block>
};

If structured data or repeated key/value data exists, include a parser stage (kv-parser, csv-parser, or regexp-parser) before rewrite. Only skip parsing when the message is truly unstructured; if so, explicitly state this in the final response.

There are two rewrite functions. Choose the correct one:

  1. r_set_splunk_dest_default — sets all base Splunk metadata. Every parser MUST call this exactly once as its first rewrite. Always include index, sourcetype, vendor, and product. Optionally include source and template.
  2. r_set_splunk_dest_update_v2 — conditionally overrides specific fields that were already set by r_set_splunk_dest_default. Use this ONLY in if/elif branches to change a subset of fields (e.g. sourcetype, index) based on message content. Never use it as the first or only rewrite.

r_set_splunk_dest_default example (required in every parser):

rewrite {
    r_set_splunk_dest_default(
        index('netops')
        sourcetype('alcatel:switch')
        vendor("alcatel")
        product("switch")
        template('t_hdr_msg')
    );
};

r_set_splunk_dest_update_v2 example (optional, only after default is set):

rewrite {
    r_set_splunk_dest_update_v2(
            sourcetype('citrix:netscaler:appfw') condition(message(':(\s+\S+)?\s+APPFW(\s+\S+){3}\s+:'))
    );
};

To choose correct template refer to the definitions in file: t_templates.conf.

Parser method selection:

Use kv-parser when logs contain key/value pairs (key=value, quoted values, RFC5424 SDATA blocks).

  • For RFC5424 SDATA, prefer template("${SDATA}").
  • Use a scoped prefix like .values.sdata..

Example:

block parser app-syslog-vendor_product() {
    channel {
        parser {
            kv-parser(prefix(".values.") template("$(template t_hdr_msg)"));
        };
        # Optional: validate parsing succeeded
        filter {
            "${.values.some_required_field}" ne ""
        };
        rewrite {
            r_set_splunk_dest_default(
                index('netfw')
                sourcetype('vendor:product')
                vendor("vendor")
                product("product")
                template('t_kv_values')
            );
        };
    };
};

Use csv-parser when logs are consistently delimited and have stable column order.

Example:

parser {
    csv-parser(
        columns("col1","col2","col3","col4")
        prefix(".values.")
        delimiters(',')
        quote-pairs('""')
        flags(escape-double-char)
    );
};

Use regexp-parser when logs are structured but not key/value or delimited. Combine methods when logs have multiple variants.

Example:

parser {
    regexp-parser(
        template("${MESSAGE}")
        patterns("^(?<field1>\\d+) (?<field2>[^ ]+) (?<field3>.*)")
        prefix(".parsed.")
    );
};

You can combine all methods and use conditional branches to parse different message variants:

block parser app-syslog-vendor_product() {
    channel {
        rewrite {
            r_set_splunk_dest_default(
                index("netops")
                sourcetype('vendor:log')
                vendor("vendor")
                product('product')
                template('t_msg_only')
            );
        };

        if (message(',TRAFFIC,' type(string) flags(substring))) {
            parser { csv-parser(columns(...) prefix(".values.") delimiters(',')); };
            rewrite {
                r_set_splunk_dest_update_v2(
                    index('netfw')
                    class('traffic')
                    sourcetype('vendor:traffic')
                );
            };
        } elif (message(',SYSTEM,' type(string) flags(substring))) {
            parser { csv-parser(columns(...) prefix(".values.") delimiters(',')); };
            rewrite {
                r_set_splunk_dest_update_v2(
                    index('netops')
                    class('system')
                    sourcetype('vendor:system')
                );
            };
        } else { };
    };
};
Show full SKILL.md (176 more words)Show less
Step 4 - Create unit test (optional)

Ask the user whether they want to create a unit test. Use this prompt:

Do you also want to create a unit test for this parser?

Create a unit test for the new parser. Testing instructions: testing-parsers.

Step 5 - Run parser tests (optional)

This step applies only if Step 4 was not skipped.

Ask the user whether they want to run the unit tests. Use this prompt:

We use Docker Compose to run containerized SC4S and Splunk instances for running unit tests. If you do not have Docker Compose or do not want to run the unit tests, skip this step.

Run the new test using poetry run pytest test-name -v -s --tb=short -n=0 -k 'not lite and not name_cache' and verify the parser works correctly.

Workflow Example

User input:

vendor: thinkst
product: canary
sourcetype: thinkst:canary
index: netfw
logs:
  <130>1 2025-04-30T12:09:54.681299+00:00 mycompany-com ThinkstCanary 3545385 newincident
  [BasicIncidentDetails@51136 Description="Web Bug Canarytoken triggered"
  Timestamp="2025-04-30 12:07:53 (UTC)" Reminder="q" Token="d7a7phdpurh2vs8gs1jbniyhb"
  SourceIP="192.168.1.97" IncidentHash="40a96cf3ba4596a81f18990143916b3c" eventid="17000"]

  [AdditionalIncidentDetails@51136
  Abbr="SAST" Accept="text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7"
  Accept-Encoding="gzip, deflate" Accept-Language="en-GB,en-US;q=0.9,en;q=0.8,ro;q=0.7"
  BackgroundContext="You have had 214 incidents from 192.168.1.97 previously."
  Browser="Chrome" Cache-Control="max-age=0" City="Cape Town" Connection="keep-alive"
  ContinentCode="AF" Country="South Africa" CountryCode="ZA" CountryCode3="ZAF" CurrencyCode="ZAR"
  Date="2025-04-30" DstPort="80" Enabled="1" Host="123456789abe[.\]o3n[.\]io" HostDomain=""
  Hostname="" Id="Africa/Johannesburg" Installed="1" Ip="192.168.1.97" IsBogon="False"
  IsProxy="False" IsTor="False" IsV4Mapped="False" IsV6="False" IsVpn="False" Language="en-GB"
  LanguageCode="zu" Latitude="-33.925552" Longitude="18.422857"
  Mimetypes="Portable Document Format;pdf;application/pdf|||Portable Document Format;pdf;text/pdf|||"
  Name="South Africa Standard Time" Offset="+02:00" Os="Macintosh" Platform="MacIntel"
  Region="Western Cape" RegionCode="WC" SrcPort="54290" Time="14:07:53.846452"
  Upgrade-Insecure-Requests="1"
  User-Agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
  Valid="True" Vendor="Google Inc." Version="135.0.0.0"]
  A Web Bug Canarytoken was triggered by '192.168.1.97'.


  <130>1 2025-04-30T12:54:52.796337+00:00 mycompany-com ThinkstCanary 3557764 newincident
  [BasicIncidentDetails@51136 Description="DNS Canarytoken triggered"
  Timestamp="2025-04-30 12:52:49 (UTC)" Reminder="q" Token="vv4x12n26ivmcgyd33pkb3drr"
  SourceIP="1.1.1.1" IncidentHash="adaa8486af78cc450417b027e2821a22" eventid="16000"]

  [AdditionalIncidentDetails@51136 BackgroundContext="This alert is the first from 1.1.1.1."
  DstPort="53" Hostname="VV4x12N26IvMcgyd33pKB3DRr[.\]123456789abe[.\]o3N[.\]Io" SrcPort="48908"]
  A DNS Canarytoken was triggered by a DNS query from the source IP 1.1.1.1.
  Please note that the source IP refers to a DNS resolver, rather than the host that triggered the token.

Created parser:

block parser app-syslog-thinkst_canary() {
    channel {
        parser {
            kv-parser(
                prefix(".values.sdata.")
                template("${SDATA}")
            );
        };
        rewrite {
            r_set_splunk_dest_default(
                index('netfw')
                sourcetype('thinkst:canary')
                vendor("thinkst")
                product("canary")
                template('t_5424_hdr_sdata_compact')
            );
        };
    };
};

application app-syslog-thinkst_canary[sc4s-syslog-sdata] {
    filter {
        filter(f_is_rfc5424)
        and program("ThinkstCanary")
        and match('@51136' value("SDATA"));
    };
    parser { app-syslog-thinkst_canary(); };
};

Created unit test:

# Copyright 2026 Splunk, Inc.
#
# Use of this source code is governed by a BSD-2-clause-style
# license that can be found in the LICENSE-BSD2 file or at
# https://opensource.org/licenses/BSD-2-Clause
import datetime
import pytest

from jinja2 import Environment, select_autoescape

from .sendmessage import sendsingle
from .splunkutils import splunk_single
from .timeutils import time_operations

env = Environment(autoescape=select_autoescape(default_for_string=False))


@pytest.mark.addons("thinkst")
@pytest.mark.parametrize(
    "procid,basic_details,additional_details,incident_message",
    [
        (
            "3545385",
            '[BasicIncidentDetails@51136 Description="Web Bug Canarytoken triggered" Timestamp="2025-04-30 12:07:53 (UTC)" Reminder="q" Token="d7a7phdpurh2vs8gs1jbniyhb" SourceIP="192.168.1.97" IncidentHash="40a96cf3ba4596a81f18990143916b3c" eventid="17000"]',
            '[AdditionalIncidentDetails@51136 Abbr="SAST" Accept="text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7" Accept-Encoding="gzip, deflate" Accept-Language="en-GB,en-US;q=0.9,en;q=0.8,ro;q=0.7" BackgroundContext="You have had 214 incidents from 192.168.1.97 previously." Browser="Chrome" Cache-Control="max-age=0" City="Cape Town" Connection="keep-alive" ContinentCode="AF" Country="South Africa" CountryCode="ZA" CountryCode3="ZAF" CurrencyCode="ZAR" Date="2025-04-30" DstPort="80" Enabled="1" Host="123456789abe[.\\]o3n[.\\]io" HostDomain="" Hostname="" Id="Africa/Johannesburg" Installed="1" Ip="192.168.1.97" IsBogon="False" IsProxy="False" IsTor="False" IsV4Mapped="False" IsV6="False" IsVpn="False" Language="en-GB" LanguageCode="zu" Latitude="-33.925552" Longitude="18.422857" Mimetypes="Portable Document Format;pdf;application/pdf|||Portable Document Format;pdf;text/pdf|||" Name="South Africa Standard Time" Offset="+02:00" Os="Macintosh" Platform="MacIntel" Region="Western Cape" RegionCode="WC" SrcPort="54290" Time="14:07:53.846452" Upgrade-Insecure-Requests="1" User-Agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" Valid="True" Vendor="Google Inc." Version="135.0.0.0"]',
            "A Web Bug Canarytoken was triggered by '192.168.1.97'.",
        ),
        (
            "3557764",
            '[BasicIncidentDetails@51136 Description="DNS Canarytoken triggered" Timestamp="2025-04-30 12:52:49 (UTC)" Reminder="q" Token="vv4x12n26ivmcgyd33pkb3drr" SourceIP="1.1.1.1" IncidentHash="adaa8486af78cc450417b027e2821a22" eventid="16000"]',
            '[AdditionalIncidentDetails@51136 BackgroundContext="This alert is the first from 1.1.1.1." DstPort="53" Hostname="VV4x12N26IvMcgyd33pKB3DRr[.\\]123456789abe[.\\]o3N[.\\]Io" SrcPort="48908"]',
            "A DNS Canarytoken was triggered by a DNS query from the source IP 1.1.1.1. Please note that the source IP refers to a DNS resolver, rather than the host that triggered the token.",
        ),
    ],
)
def test_thinkst_canary(
    record_property,
    get_host_key,
    setup_splunk,
    setup_sc4s,
    procid,
    basic_details,
    additional_details,
    incident_message,
):
    host = get_host_key

    dt = datetime.datetime.now(datetime.timezone.utc)
    iso, _, _, _, _, _, epoch = time_operations(dt)

    # Tune time functions
    epoch = epoch[:-3]

    mt = env.from_string(
        "{{ mark }} {{ iso }} {{ host }} ThinkstCanary {{ procid }} newincident {{ basic_details }} {{ additional_details }} {{ incident_message }}\n"
    )
    message = mt.render(
        mark="<130>1",
        iso=iso,
        host=host,
        procid=procid,
        basic_details=basic_details,
        additional_details=additional_details,
        incident_message=incident_message,
    )

    sendsingle(message, setup_sc4s[0], setup_sc4s[1][514])

    st = env.from_string(
        'search _time={{ epoch }} index=netfw host="{{ host }}" sourcetype="thinkst:canary"'
    )
    search = st.render(epoch=epoch, host=host)

    result_count, _ = splunk_single(setup_splunk, search)

    record_property("host", host)
    record_property("resultCount", result_count)
    record_property("message", message)

    assert result_count == 1

Completion Checklist

Before finishing, confirm all items:

  • Parser/filter created for main package.
  • Parser/filter created for lite package.
  • Parser includes field extraction (kv-parser, csv-parser, and/or regexp-parser) when sample logs are parseable.
  • Lite vendor metadata exists (addon_metadata.yaml) when required.
  • package/lite/etc/config.yaml updated for new lite vendor addon.
  • Unit tests created and passing for the new parser.
  • User informed about any constraints (for example, unsupported format or required network-source port changes).
  • The parser files have only one block parser definition and only one application definition.

© splunk, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .agents/skills/parser-creator of splunk/splunk-connect-for-syslog.

  • SKILL.md
  • references/testing-parsers.md

Open the folder on GitHubat commit a7d1ca1

Compare with similar skills

Parser Creator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Parser Creator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Parser Creator this skillsplunk/splunk-connect-for-syslog180—~4.3kAutomated safety check: PassApache-2.0
Spa Add Test Scenariosplunk/splunk-platform-automator137—~2.2kAutomated safety check: PassProprietary
Web Application Testinganthropics/skills180k51 repos~966Automated safety check: PassApache-2.0
Diagnosing Bugsfossasia/eventyay-interpretation1.6k31 repos~2.1kAutomated safety check: PassApache-2.0
TDDfossasia/eventyay-interpretation1.6k28 repos~1.1kAutomated safety check: PassApache-2.0
TDD WorkflowhellangleZ/burn-in-cceverywhere-ralph11211 repos~2.4kAutomated safety check: PassNone

Similar skills

  • Spa Add Test Scenario

    splunk/splunk-platform-automator

    A skill your agent uses when adding app scope/routing test coverage (deployer, CM, DS, direct).

    137 GitHub stars~2.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Web Application Testing

    anthropics/skills

    Official

    Tests local web applications with Python Playwright scripts, checking frontend behavior, capturing screenshots and reading browser console logs.

    180k GitHub starsUsed in 51 repos~966 tokens
    Testing & QAAuto-check passed
  • Diagnosing Bugs

    fossasia/eventyay-interpretation

    Diagnosis loop for hard bugs and performance regressions. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 31 repos~2.1k tokens
    Testing & QAAuto-check passed
  • TDD

    fossasia/eventyay-interpretation

    Test-driven development. An agent skill from fossasia/eventyay-interpretation.

    1.6k GitHub starsUsed in 28 repos~1.1k tokens
    Testing & QAAuto-check passed
  • TDD Workflow

    hellangleZ/burn-in-cceverywhere-ralph

    A skill your agent uses when writing new features, fixing bugs, or refactoring code.

    112 GitHub starsUsed in 11 repos~2.4k tokens
    Testing & QAAuto-check passed
  • TDD

    sanity-io/sanity

    Official

    Test-driven development with red-green-refactor loop. An agent skill from sanity-io/sanity.

    6.4k GitHub starsUsed in 20 repos~1k tokens
    Testing & QAAuto-check passed

Works with

Categories

Questions about Parser Creator

What does Parser Creator do?

Creates SC4S syslog-ng parsers. An agent skill from splunk/splunk-connect-for-syslog. Parser Creator is an agent skill from splunk/splunk-connect-for-syslog. Creates SC4S syslog-ng parsers.

When should I use Parser Creator?

Parser Creator fits situations like: the user wants to create a new parser; add support for a new log source; says create parser; new vendor support.

How do I install Parser Creator in Claude Code?

Run `npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a claude-code`. Or copy the skill folder (.agents/skills/parser-creator in splunk/splunk-connect-for-syslog) into .claude/skills/parser-creator in your project. Claude Code loads it when a task matches its description.

How do I install Parser Creator in Codex?

Run `npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a codex`. Or copy the skill folder (.agents/skills/parser-creator in splunk/splunk-connect-for-syslog) into .agents/skills/parser-creator in your project. Codex loads it when a task matches its description.

Can I use Parser Creator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add splunk/splunk-connect-for-syslog --skill parser-creator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/parser-creator, .gemini/skills/parser-creator, .github/skills/parser-creator and .opencode/skills/parser-creator in your project.

What does Parser Creator need to run?

Going by SKILL.md and its folder, Parser Creator needs the command-line tools its instructions call (poetry). Our summary lists: Docker.

Does Parser Creator access the network?

SKILL.md names 1 domain. In commands or code: opensource.org; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Parser Creator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Parser Creator use?

Parser Creator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Parser Creator use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1k tokens, read only when the agent opens those files.

What are the alternatives to Parser Creator?

Skills that share tags, products or a category with Parser Creator: Spa Add Test Scenario (splunk/splunk-platform-automator, 137 stars), Web Application Testing (anthropics/skills, 180k stars), Diagnosing Bugs (fossasia/eventyay-interpretation, 1.6k stars) and TDD (fossasia/eventyay-interpretation, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Parser Creator?

splunk (a GitHub organization) maintains it in splunk/splunk-connect-for-syslog, which has 180 GitHub stars. The repository was last updated on October 6, 2026.

Source: splunk/splunk-connect-for-syslog on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.