Splunk has launched a GenAI summary feature in splunk.com and docs.splunk.com search platforms designed to give users a quick and accurate glance of the most pertinent information they are looking for. This GenAI feature serves up a contextual high-level summary pulled from various relevant search results on topics ranging from Splunk product and feature usage to general Splunk terminology. Additionally, each of the search results will have descriptions created by GenAI that provide a comprehensive overview of the linked source. With the help of this revamped search experience, Splunk users can now get the information they need faster than ever before.
As Splunk has grown, so has our digital footprint. We have roughly 260,000 members on Community making over 147,000 posts — and that’s just one data source that users can tap into. Add in product docs, Knowledgebase articles, Splunk Blogs and our developer portal into the mix just to name a few, and knowing where to search suddenly becomes very convoluted.
This revamped experience is designed to save users both time and energy by providing a one-stop shop to not only search Splunk-related terminology across data sources, but also get high-level and document-level content summaries. The GenAI feature enables us to tap into our domain expertise by training our LLM on the gold mine of Splunk documentation, something that other solutions in the market do not have full access to.
Our LLM is trained on Splunk public documentation. By training it on Splunk-specific resources, this helps to filter out the noise of the greater world wide web. Documents used in our LLM are updated daily so you can rest assured that you are leveraging the most up-to-date information.
Data sources for the first release will include:
We are continuing to expand the data sources supported.
Type in your keywords to search granularly by product, feature, or even be as broad as asking how to get started using Splunk as a whole. In the screenshot below, the customer is searching by product to learn more about the AI Assistant for SPL app.
We leverage an open-source large language model (LLM) model as foundation for this service. The LLM is hosted on the Splunk AI Platform to generate summaries from user searches, the same platform that supports some of Splunk’s most powerful AI Assistants like the AI Assistant for SPL.
We continue to remain agile with marketplace solutions and have designed our infrastructure so that we are in a better position to swap out the models when a better solution for our needs surfaces. As is common among GenAI solutions, sometimes our LLM is subject to hallucinations and users are recommended to fact check their results with the data sources that went into the summary.
The LLM leverages a RAG-based approach to improve model performance. We have indexed a diverse set of data in a vector database. Every time a user executes a query, our system identifies the intent of the query, searches for relevant documents, and ranks the retrieved documents to determine which subset to show the Large Language Model (LLM).
We implement a series of guardrails designed to enhance the safety of the responses from our services. These guardrails include prompt injection detection, profanity detection, gibberish detection and PII detection.
Despite these measures, it's important to acknowledge the inherent limitations of Large Language Models (LLMs). LLMs can sometimes produce hallucinations, generating information that may appear plausible but is not based on real data. Additionally, while our guardrails enhance safety, they are not foolproof and may not catch every inappropriate or incorrect response. Continuous monitoring and improvement are essential to mitigate these limitations and enhance the reliability of our services.
With Splunk’s revamped search experience that leverages GenAI technology at scale, customers can now have a more seamless Splunk end user experience by having the domain-specific information they need at their fingertips. Try out the feature today in splunk.com and docs.splunk.com.
The Splunk platform removes the barriers between data and action, empowering observability, IT and security teams to ensure their organizations are secure, resilient and innovative.
Founded in 2003, Splunk is a global company — with over 7,500 employees, Splunkers have received over 1,020 patents to date and availability in 21 regions around the world — and offers an open, extensible data platform that supports shared data across any environment so that all teams in an organization can get end-to-end visibility, with context, for every interaction and business process. Build a strong data foundation with Splunk.