splunk-spl-processing

Installation
SKILL.md

Splunk SPL — detection engineering

Author and review SPL for Splunk Enterprise / Enterprise Security. The discipline here mirrors the rigour applied to KQL in kusto-query-language — filter early, structure deliberately, and document every assumption.

Pair with: windows-event-logs (EventCode mapping), detection-engineering (hunt→rule lifecycle), opentide-detection-rule (configurations.splunk), kusto-query-language (conceptual KQL translation).

Distilled from: Analysis of 2009 production detections, 234 macros, and 104 lookups in splunk/security_content (ESCU v5.26+).


1. Search-time discipline

1.1 Always lead with index, sourcetype, time

Splunk searches without an index= constraint scan default indexes — in production, there is often no default, so nothing is searched.

index=wineventlog sourcetype="WinEventLog:Security" earliest=-7d@d latest=now
Installs
3
First Seen
Sep 16, 2026