# Lynx AI Agent for Splunk > Lynx AI Agent for Splunk is an agentic AI assistant - a Splunk copilot - that installs as a native Splunk app and turns plain-language questions into working SPL, executed searches, and finished dashboards. Built for security operations and observability teams, it runs inside the user's own Splunk session, bound by their existing roles and permissions. This site is the product's official documentation. The agent works end to end rather than stopping at a suggested query: it discovers the relevant indexes, fields, and knowledge objects, writes best-practice SPL with explanations, runs it under the user's own permissions, reads the results, and turns them into Simple XML dashboards that can be previewed live and saved into any app the user can write to. Conversations persist across sessions, so context accumulates instead of restarting. It installs as an app on a Search Head (Splunk Cloud Platform, Splunk Enterprise, or a Search Head Cluster) and is configured from the Splunk Web setup page - there is no data pipeline to build, no index to duplicate, and nothing to stand up next to Splunk. It can run against Lynx AI's managed cloud backend, which operates under a strict Zero Data Retention policy, or be deployed entirely on-premises - including fully air-gapped networks - against a self-hosted OpenAI-compatible inference endpoint, so sensitive data never leaves the customer's perimeter. Lynx AI is multi-model by design: users switch between supported frontier models per task instead of being locked to a single built-in one. Its behavior is extended per user or per organization through Skills (specialized knowledge loaded on demand) and Connectors (external MCP servers). Everything it does stays inside Splunk's security model - it inherits the logged-in user's roles, cannot reach data the user cannot, and won't be able to execute destructive SPL commands. ## Getting started - [Home](https://docs.trylynx.ai/): Product overview and the core capabilities - natural language querying, best-practice SPL generation, automated dashboards - with quick-start entry points. - [Installation](https://docs.trylynx.ai/installation/): Deploying the app package on Splunk Cloud Platform, Splunk Enterprise, and Search Head Clusters. - [Configuration](https://docs.trylynx.ai/configuration/): First-time setup via the Splunk Web setup page or configuration files, including license key and backend settings. ## Usage - [Chat](https://docs.trylynx.ai/usage/chat/): Working in the chat itself - sending prompts, picking a model and reasoning mode, stopping a generation, reading tool calls and SPL blocks, and rating responses. - [Permissions](https://docs.trylynx.ai/usage/permissions/): The `lynx-ai` Splunk role, its capabilities, how the agent inherits the logged-in user's access to indexes, apps, and knowledge objects, and the risky SPL commands it will write but never run. - [Chat History](https://docs.trylynx.ai/usage/chat-history/): Per-user conversation storage in the Splunk KV store, export and import, the context window indicator, compacting a long conversation, and Infinite Chat for conversations that outgrow the context window. - [Dashboards](https://docs.trylynx.ai/usage/dashboards/): Generating Simple XML dashboards, previewing them, and saving them into a chosen app. - [Skills](https://docs.trylynx.ai/usage/skills/): The built-in skills coming from Lynx AI, and custom skills created by users or by admins for everyone - the recommended way to steer the agent. - [Connectors](https://docs.trylynx.ai/usage/connectors/): Attaching external MCP servers so their tools are available alongside the agent's built-in Splunk tools. ## Advanced - [Model Performance](https://docs.trylynx.ai/advanced/model-performance/): Benchmarks and comparison of the supported frontier models across Splunk knowledge, context retrieval, dashboard generation, and data intelligence, to guide per-task model choice. - [Activity Dashboard](https://docs.trylynx.ai/advanced/activity/): The bundled AI Agent Activity dashboard, available to admins - request volume, reliability, model, tool and skill usage, and the `_internal` usage events and app logs behind it. - [Architecture](https://docs.trylynx.ai/advanced/architecture/): Supported deployment architectures, the managed cloud service and its Zero Data Retention policy, and alignment with Splunk Validated Architectures. - [On-Premises](https://docs.trylynx.ai/advanced/on-premises/): Private-cloud and fully air-gapped deployments, bringing your own model - managed or open-weight - through any OpenAI-compatible inference endpoint, with the backend container's environment variables, monitoring endpoints, and ready-to-apply OpenShift Container Platform manifests. ## Configuration reference - [ai.conf](https://docs.trylynx.ai/advanced/config-spec/ai.conf/): Verbatim spec and example for `ai.conf` - backend, risky commands, AI model stanzas, SPL auto-formatting, and search defaults (time range, timeout, artifact TTL, result size). - [passwords.conf](https://docs.trylynx.ai/advanced/config-spec/passwords.conf/): Verbatim spec and example for how the license key is stored as a Splunk-encrypted credential. ## Optional - [CopyCat](https://docs.trylynx.ai/copycat/): A separate open-source Splunk add-on from Lynx AI that generates realistic mock logs, useful for evaluating the agent against sample data.