splunk-spl-processing
Installation
SKILL.md
Splunk SPL — detection engineering
Author and review SPL for Splunk Enterprise / Enterprise Security. The discipline here mirrors the rigour applied to KQL in kusto-query-language — filter early, structure deliberately, and document every assumption.
Pair with:
windows-event-logs(EventCode mapping),detection-engineering(hunt→rule lifecycle),opentide-detection-rule(configurations.splunk),kusto-query-language(conceptual KQL translation).
Distilled from: Analysis of 2009 production detections, 234 macros, and 104 lookups in splunk/security_content (ESCU v5.26+).
1. Search-time discipline
1.1 Always lead with index, sourcetype, time
Splunk searches without an index= constraint scan default indexes — in production, there is often no default, so nothing is searched.
index=wineventlog sourcetype="WinEventLog:Security" earliest=-7d@d latest=now