AI Routines — Describe It Once, TrackMe Watches for It
Describe a monitoring task in plain English and TrackMe watches for it on a schedule — reasoning over your live environment, judging whether it truly matters, then notifying you or acting, under your explicit consent.
Key Capabilities
Describe It Once
Write the task the way you'd brief a colleague — thresholds, time windows, what to do when it happens. TrackMe compiles your sentence into a structured, reviewable instruction; what you approve is exactly what runs, on the cron schedule you choose.
Three Evaluation Strategies
You own the AI cost. Agentic reasons over live context every cycle; Hybrid gates a cheap SPL trigger in front of the model so quiet cycles cost zero tokens; Deterministic lets your SPL decide and the model just delivers. The form tells you the cost consequence before you save.
Evaluate Before You Commit
You cannot create a routine blind. Evaluate runs it against your live environment as a read-only dry-run — returning a would-it-fire verdict, the compiled instruction, a permission-coverage check, and a token-cost preview — before anything exists.
Notify or Act — On Your Terms
A routine delivers a formatted email or a structured Splunk event — or both. In act mode it goes further: tuning thresholds, attaching notes and labels, retraining ML models, triggering ITSM / Slack / PagerDuty, all under granular, capability-scoped consent.
Stateful, Anti-Noise Memory
Routines remember. They notify once when a condition is newly met, stay quiet while it persists, and re-notify only when it clears and recurs — or when the affected entities change. Exact entity names are remembered per fire, so "don't re-alert the same entity within 4 hours" is deterministic.
Inspect Every Run, See Every Cost
Each routine is its own Splunk scheduled search — full failure isolation, Splunk RBAC on everything it reads and does. Per-run token counts, a dedicated cost view, and an audit dashboard of runs by routine, outcome and cadence keep it fully accountable.



Deep Dive
Explore the key aspects of AI Routines in detail.

It doesn’t just watch and alert. It reasons, judges, decides — and acts.
Traditional alerting fires on a static threshold. An AI Routine reads the situation, correlates across entities, judges whether it actually matters — and decides what to do about it.
Describe a monitoring task in plain English — “Tell me if 4 or more high-priority feeds turn red within 15 minutes, correlate what they have in common, and add a note to each entity” — and TrackMe watches for it, the agentic way. On the schedule you choose, the routine evaluates its condition against your live environment, investigates with real Splunk searches, correlates and enriches what it finds — then delivers the outcome as an email or a Splunk event and, with your explicit consent, acts.
Routines understand movement, not just state: conditions like “N entities turn red within M minutes” are evaluated from the real flip history of your tenant, not guessed.
You own the AI cost
Every routine picks how its condition gets evaluated — this is the main cost dial, and the form tells you the consequence before you save, translating your cron into runs per day.
The trigger is a cost gate in front of the agent, never a replacement for it — the LLM remains central to understanding, correlating, and explaining.
Evaluate: a dry-run gate before anything exists
You cannot create a routine blind. Evaluate runs the routine against your live environment as a read-only dry-run — nothing is created, sent, or changed — and returns a would-it-fire verdict, the compiled instruction that will be persisted and replayed on every run, a permission-coverage check (if the intent implies an action the granted permissions can’t perform, it says so before creation), and a cost preview extrapolated to your cadence. Reply to the evaluation in plain English and re-evaluate until the compiled instruction says exactly what you mean.
It can act — autonomously, on your terms
A routine observes and delivers — a formatted email, a structured Splunk event, or both. In act mode it goes further and changes things on its own conclusion:
That autonomy runs inside strict, explicit guardrails:
- Permission families — capability-oriented grants (entity thresholds, labels/notes, ML changes, alert actions…). Each family exposes exactly its tools at fire time — nothing more.
- Consent is pinned — to the exact intent text and the exact granted families. Editing either invalidates the consent; the routine cannot act again until you re-affirm.
- Deterministic delivery — recipients and event targets are configuration, never AI output. Your SPL and alerts built on routine events never break because a model phrased something differently.
- Audited like everything else — every write lands in the entity audit trail with an
[AI Agent]stamp, exactly like the AI Advisors.
One honest outcome per run — Fired, or No fire. No notification noise.
It remembers — and acts on what it saw last time
Routines are stateful. Every evaluated cycle ends with the agent writing a compact state fingerprint — a snapshot it authors itself — and the most recent fingerprints are replayed to it on the next run. So a routine doesn’t just react to the current snapshot; it decides what to do now in light of what it did before: notify once when a condition is newly met, stay quiet while the same entities remain red, and re-notify only when it clears and recurs or the affected set changes materially.
Per-entity memory goes further — exact entity names are remembered with each fire, so intents like “don’t re-notify the same entity within 4 hours” or “only alert on entities that weren’t in the last fire” are decided deterministically, on names — never on fuzzy recall. Memory depth is tunable for deployments whose intents lean heavily on history.
Runs you can inspect, costs you can see
Each routine is its own Splunk scheduled search — full failure isolation, standard Splunk tooling, and Splunk RBAC on everything it reads and does. Ownership is an explicit choice: run as the tenant’s service account (survives personnel changes) or as yourself, with the resolved identity always visible in the management view. Every run is recorded with its outcome, duration and token counts; a dedicated cost view breaks consumption down over time, and an audit dashboard charts runs by routine, outcome and cadence — on top of the indexed events and execution logs.
Compatible and opt-in by construction
AI Routines share the AI Advisors’ platform requirements: Splunk 10.2.x and later (Python 3.13.x), plus at least one configured AI provider. The feature is opt-in by construction — completely inert until the AI Assistant is enabled and a provider is configured — and ships with its own kill switch and a creator-roles policy. TrackMe is provider-agnostic: connect OpenAI, Azure OpenAI, Anthropic, Google Gemini, Mistral, xAI, self-hosted Ollama, or Splunk Hosted (SLIM API). Nothing is sent anywhere until you choose to configure it.
Related Features
Ready to get started?
Request a free 90-day trial with all features enabled. No restrictions.









