skills/smithery.ai/splunk-rule-conversion

splunk-rule-conversion

Installation
SKILL.md

Splunk Rule Conversion

Overview

Convert Splunk SPL detection rules to Microsoft Sentinel KQL, Google SecOps YARA-L 2.0, and CrowdStrike CQL. Includes field mappings, syntax patterns, and detection quality improvements.

Quick Reference

Source Target Key Differences
Splunk SPL Microsoft KQL Pipe vs chained operators, different aggregation syntax
Splunk SPL Google YARA-L Declarative rules vs procedural queries, UDM schema
Splunk SPL CrowdStrike CQL Similar pipe syntax, different field names

SPL to Microsoft Sentinel KQL

Syntax Mapping

Installs
2
First Seen
Mar 9, 2026
splunk-rule-conversion from smithery.ai