Ask your data a question.
Get an answer you can check.
Inno AI Chat answers questions about your Splunk data in plain language — and shows you the SPL it used, so you can read it, re-run it, and disagree with it. It runs against a language model on your own hardware, which means it works in the environments that cannot send operational data to a hosted model and have therefore been locked out of this entire category.
On-premises model · answers grounded in your saved searches and schema · the SPL comes with the answer · nothing leaves your network
Talk to us about early accessWhat it does
Plain language in, SPL out
Ask "which hosts got slower this week" and get an answer plus the search that produced it. The SPL is the product as much as the sentence is — you can paste it into Splunk, change the window, and make it your own saved search.
Grounded in your environment
Indexes, sourcetypes, field names and values differ in every deployment, and a model that guesses them confidently is worse than one that says nothing. The assistant works from your schema and your existing saved searches rather than from what a model assumes Splunk data looks like.
Answers you can audit
Every answer carries the query behind it. If it is wrong, you can see why it is wrong — which is the difference between a tool an operations team will adopt and one they quietly stop opening.
Inside Splunk, not beside it
A Splunk app, in your Splunk, using your roles and permissions. No separate portal to log into and no copy of your data anywhere else.
Why on-premises
The environments that most need this are the ones that cannot use hosted models.
Regulated industries, defence, air-gapped sites, and anyone whose logs contain customer data have largely been unable to adopt AI assistants for operations — not because the models are not good enough, but because the data cannot leave. Inno AI Chat is built for that constraint rather than around it: the model runs on hardware you control, and no telemetry, query or answer is transmitted to us.
Where it is now
We are being deliberate here, because an assistant that is confidently wrong about production data is worse than no assistant. The work right now is accuracy: constraining what the model is allowed to assume, grounding it in the specific deployment, and measuring whether the answers hold up rather than whether they read well.
| Area | Status |
|---|---|
| Chat inside Splunk, on-premises model | Working |
| Answers grounded in your schema and saved searches | Working |
| Accuracy work — reducing confidently wrong answers | In progress, and the main effort |
| Per-deployment setup so it learns your data | In progress |
| Licensing, packaging, Splunkbase listing | Not started |
We will not put it on sale until the accuracy work is where it needs to be. If that timeline matters to you, tell us what you would use it for — the environments we hear about are what shape the order of work.
Interested?
Two things are genuinely useful to us right now:
- What you would ask it. The real questions your team asks Splunk today, in the words they would use.
- What your environment looks like. Roughly what you index, and whether an on-premises model is a requirement or a preference for you.
In the meantime
Our other Splunk apps are available today:
- Inno Observability — APM on your OpenTelemetry data, with AI root-cause analysis that already runs on your own model
- Inno Dashboard Studio — write SPL, get a dashboard
- Inno Streaming Add-on for AWS S3 — serverless S3 to Splunk