splunk__hint
Add analyst hints to ongoing Splunk investigations to guide the next analysis step.
Instructions
Inject an analyst hint into the investigation for the next iteration. The hint is included in the findings passed to the next reasoning step. Example: "focus on web-01 cert chain errors after 14:30 UTC"
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| hint | Yes | ||
| run_id | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |