Skip to content

Chat

The chat is where you work with the agent. Open it from Apps > Lynx AI Agent for Splunk, type a question, and the agent plans, runs searches against your data, and answers with what it found.

A new conversation offers a few suggested prompts - including a guided tour of the agent's capabilities - which you can click to get started.

Sending a Prompt

Type into the prompt box and press Enter to send, or Shift+Enter for a new line. You can keep typing while the agent is working; the message is sent once you press Enter again.

Tip

Press Ctrl together with the left or right Shift key to switch the prompt box between left-to-right and right-to-left writing.

Below the prompt box:

  • Model - The AI model that answers. Models marked with a bulb run in reasoning ("thinking") mode. See Model Performance for choosing one.

  • Auto scroll - Follows the response as it streams. Turn it off to read earlier parts of the conversation while the agent writes.

  • Send / Stop - The send button becomes a stop button while the agent works. Stopping ends the response and cancels any search the agent has running on the Search Head, so nothing keeps consuming resources after you stop.

Reading a Response

  • Thinking - Reasoning models show a Thinking header while they reason, which settles into Thought for n seconds. Click it to read the reasoning.

  • Tool calls - Each step the agent takes against Splunk is listed with the time it took. Click a step to see what it sent and what came back.

  • SPL blocks - Every query carries Copy and Open in Search, which opens it in Splunk's Search app in a new tab. Queries containing a risky command cannot be opened.

  • Dashboards - A response containing dashboard XML gets a Dashboard action that opens the preview.

Rating a Response

Use or under a response to rate it. A thumbs-down asks for a short reason, either from the list or in your own words.

Ratings are stored in the feedback KV store collection on your own Search Head, alongside the chat and message they belong to. The prompt and the response themselves are not stored with the rating.

Layout and Indicators

The 3-dot menu at the bottom of the chat sidebar switches between Wide Layout and Compact Layout, and reports the installed Agent Version. It also holds the export, import and compaction actions described in Chat History.

Next to it, the sidebar shows the context window indicator and, when the backend reports a newer app version is available, an update icon. The update icon is not shown in on-premises deployments.