splunk-spl-processing
Splunk Enterprise and Enterprise Security SPL authoring for detection engineering — index/sourcetype/time discipline, tstats/CIM acceleration, ESCU macro layers, ES correlation searches, notables, and RBA. Use when authoring or reviewing SPL, configurations.splunk MDR blocks, ES correlation searches, or translating KQL hypotheses to Splunk. Pair with detection-engineering and opentide-detection-rule.
Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/splunk-spl-processing/SKILL.md
- skills/splunk-spl-processing/references/Anti-Patterns.md
- skills/splunk-spl-processing/references/Best-Practices.md
- skills/splunk-spl-processing/references/CIM-Data-Models.md
- skills/splunk-spl-processing/references/Detection-Type-Patterns.md
- skills/splunk-spl-processing/references/Eval-and-Stats-Functions.md
- skills/splunk-spl-processing/references/SPL-Idioms.md
Every link opens the file at its source, pinned to the revision this page describes.