{"_id":"@dxvapor/pi-splunk-cloud-logs","name":"@dxvapor/pi-splunk-cloud-logs","dist-tags":{"latest":"1.0.0"},"versions":{"1.0.0":{"name":"@dxvapor/pi-splunk-cloud-logs","version":"1.0.0","description":"Pi coding agent extension for querying Splunk Cloud logs via REST API. Supports OAuth2 client credentials and bearer token auth.","type":"module","keywords":["pi-package","pi-extension","splunk","splunk-cloud","logs","observability"],"author":{"name":"dxvapor"},"license":"MIT","repository":{"type":"git","url":"git+https://github.com/dxvapor/pi-splunk-cloud-logs.git"},"bugs":{"url":"https://github.com/dxvapor/pi-splunk-cloud-logs/issues"},"homepage":"https://github.com/dxvapor/pi-splunk-cloud-logs#readme","pi":{"extensions":["./extensions"]},"engines":{"node":">=18.0.0"},"peerDependencies":{"@mariozechner/pi-coding-agent":"*","@sinclair/typebox":"*"},"devDependencies":{"@mariozechner/pi-coding-agent":"^0.68.1","@sinclair/typebox":"^0.34.49","typescript":"^5.9.3"},"gitHead":"7796ae3a610cb80dc974560add85ad1e91e34ffb","_id":"@dxvapor/pi-splunk-cloud-logs@1.0.0","_nodeVersion":"25.9.0","_npmVersion":"11.12.1","dist":{"integrity":"sha512-jOTVQugC2jejshFxAcnzlNjzrxExjrhiCMBZy29IhsitZs7rTwWsIPh0/jbkaAmwBRfmNR8t7jx5wEdBc5OyMQ==","shasum":"0d53582adc60b7c3c0c97852a85660db81f48bf6","tarball":"https://registry.npmjs.org/@dxvapor/pi-splunk-cloud-logs/-/pi-splunk-cloud-logs-1.0.0.tgz","fileCount":8,"unpackedSize":37253,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDEaD/ZFyUADxHeizhWfc9tPVmIPWIIy45XtR1oezXhrgIhAPwX6pWWy8v2wOFMASY5cx4bLri4DxR94e2Q+dp14+K6"}]},"_npmUser":{"name":"dxvapor","email":"npmjs.elevation906@passmail.com"},"directories":{},"maintainers":[{"name":"dxvapor","email":"npmjs.elevation906@passmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pi-splunk-cloud-logs_1.0.0_1776834687525_0.465076335736905"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-22T05:11:27.397Z","1.0.0":"2026-04-22T05:11:27.661Z","modified":"2026-04-22T05:11:27.932Z"},"maintainers":[{"name":"dxvapor","email":"npmjs.elevation906@passmail.com"}],"description":"Pi coding agent extension for querying Splunk Cloud logs via REST API. Supports OAuth2 client credentials and bearer token auth.","homepage":"https://github.com/dxvapor/pi-splunk-cloud-logs#readme","keywords":["pi-package","pi-extension","splunk","splunk-cloud","logs","observability"],"repository":{"type":"git","url":"git+https://github.com/dxvapor/pi-splunk-cloud-logs.git"},"author":{"name":"dxvapor"},"bugs":{"url":"https://github.com/dxvapor/pi-splunk-cloud-logs/issues"},"license":"MIT","readme":"# pi-splunk-cloud-logs\n\n[![npm](https://img.shields.io/npm/v/@dxvapor/pi-splunk-cloud-logs?style=flat-square)](https://www.npmjs.com/package/@dxvapor/pi-splunk-cloud-logs)\n[![pi-package](https://img.shields.io/badge/pi-package-blue?style=flat-square)](https://shittycodingagent.ai/packages)\n[![License: MIT](https://img.shields.io/badge/License-MIT-green?style=flat-square)](LICENSE)\n\nA [pi coding agent](https://github.com/badlogic/pi-mono) extension that gives the LLM direct access to **Splunk Cloud** logs via the Splunk REST API.\n\n## Features\n\n- 🔍 **`splunk_search`** — Async SPL search with live progress polling\n- ⚡ **`splunk_oneshot`** — Fast synchronous search for quick/narrow queries\n- 📋 **`splunk_list_indexes`** — Discover available indexes before writing queries\n- 🗂️ **`splunk_list_jobs`** — Inspect recent search jobs\n- 🔐 **OAuth 2 client credentials** (preferred) or **static bearer token**\n- 🖥️ `/splunk-config` — Interactive TUI setup\n- 🩺 `/splunk-test` — One-command connectivity check\n\n## Installation\n\n```bash\npi install npm:@dxvapor/pi-splunk-cloud-logs\n```\n\nOr try it without installing:\n\n```bash\npi -e npm:@dxvapor/pi-splunk-cloud-logs\n```\n\n## Authentication\n\n### Option 1 — OAuth 2 client credentials (recommended)\n\nCreate an OAuth 2.1 client in your Splunk Cloud instance\n(**Settings → Identity Provider → Manage OAuth 2.0 Clients**), then:\n\n```bash\nexport SPLUNK_HOST=myorg.splunkcloud.com\nexport SPLUNK_CLIENT_ID=your-client-id\nexport SPLUNK_CLIENT_SECRET=your-client-secret\n```\n\nThe extension automatically obtains and refreshes access tokens.\n\n### Option 2 — Bearer token\n\nGenerate a token in Splunk Web (**Settings → Tokens**), then:\n\n```bash\nexport SPLUNK_HOST=myorg.splunkcloud.com\nexport SPLUNK_TOKEN=eyJ...\n```\n\n### Optional\n\n```bash\nexport SPLUNK_PORT=8089   # Default: 8089\n```\n\n### Interactive setup\n\nAlternatively, configure inside pi at runtime:\n\n```\n/splunk-config\n```\n\nCredentials entered via `/splunk-config` are **stored in memory only** and are\nnever written to disk or the session file.\n\n## Usage\n\nAfter starting pi with the extension loaded, just describe what you need:\n\n```\nSearch Splunk for HTTP 5xx errors in the last hour across all hosts.\n```\n\n```\nList all Splunk indexes and show me which ones have data from today.\n```\n\n```\nShow me the top 10 hosts by error count in the past 24 hours.\n```\n\nThe LLM uses the registered tools to run SPL queries automatically.\n\n### Manual tool calls (for testing)\n\n```\nRun: splunk_list_indexes\nRun: splunk_oneshot { \"query\": \"index=main error | head 5\", \"earliestTime\": \"-15m\" }\n```\n\n### Commands\n\n| Command | Description |\n|---------|-------------|\n| `/splunk-config` | Interactive connection setup |\n| `/splunk-test` | Test connectivity and show server info |\n\n## How it works\n\n```\nUser prompt\n    │\n    ▼\nLLM decides to call splunk_search\n    │\n    ├── POST /services/search/jobs        (create job)\n    ├── GET  /services/search/jobs/{sid}  (poll status)  ← repeats\n    └── GET  /services/search/jobs/{sid}/results (fetch)\n    │\n    ▼\nFormatted results returned to LLM → answer\n```\n\nFor `splunk_oneshot`, the export endpoint is used instead for a single\nround-trip response.\n\n## Environment Variables\n\n| Variable | Required | Description |\n|----------|----------|-------------|\n| `SPLUNK_HOST` | ✅ | Splunk Cloud hostname (e.g. `myorg.splunkcloud.com`) |\n| `SPLUNK_PORT` | ❌ | Management port. Default: `8089` |\n| `SPLUNK_CLIENT_ID` | ✅ (OAuth) | OAuth 2 client ID |\n| `SPLUNK_CLIENT_SECRET` | ✅ (OAuth) | OAuth 2 client secret |\n| `SPLUNK_TOKEN` | ✅ (token) | Static bearer token |\n\n## Requirements\n\n- Node.js ≥ 18 (for native `fetch`)\n- pi coding agent installed globally\n- Splunk Cloud Platform instance with REST API access on port 8089\n\n## Security notes\n\n- Credentials entered via `/splunk-config` are **in-memory only**.\n- OAuth tokens are cached in-process and refreshed automatically before expiry.\n- TLS is always used (Splunk Cloud enforces it).\n- Store long-lived secrets in environment variables, not in code or config files.\n\n## Contributing\n\nIssues and PRs welcome at\n[github.com/dxvapor/pi-splunk-cloud-logs](https://github.com/dxvapor/pi-splunk-cloud-logs).\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","readmeFilename":"README.md","_rev":"1-4dff60052e109b47ea5bcbbc5ea87d91"}