Vizzy: an AI harness for Splunk and Cribl
What a harness is, why a chatbot over docs isn't one, and how Vizzy puts your AI to work inside your live Splunk and Cribl environments with guardrails and a ticket trail.
By VisiCore · Sep 17, 2026

Most "AI for ops" products are a chat window in front of documentation. They can tell you what a Cribl route is. They can't tell you which of your routes is feeding the index that just blew your Splunk license, and they certainly can't fix it.
Vizzy is different because it's a harness, not a chatbot.
What a harness is
A harness is everything that sits between a language model and a production system so the model can act safely. On its own, a model has no idea what's live in your environment, no way to touch it, and no memory of what it did last week. A harness supplies all three:
- Context. Your knowledge base, docs, and preferences, so answers start from your environment, not a generic one.
- Memory. Tickets are the record. Every task Vizzy runs lands in your X10 board, and Vizzy reads them back the next time you ask.
- Guardrails. Scoped access and approvals. Vizzy can only reach what you've given it, and it asks before it writes.
- Discipline. Read first, deploy once. The agent loop is fixed: plan → approve → read → write → deploy → note.
Inside that harness, the model is swappable. Bring your own key (Anthropic, OpenAI, Google, Azure) or use VisiCore credits. The harness, tools, and guardrails are the same either way.
What Vizzy connects to
The harness drives the same CLI tools our engineers use every day:
vct-cribl-cliagainst the Cribl.Cloud API: Stream, Edge, Search, and Lake.vct-splunk-cliagainst the Splunk Cloud API, one stack per session.- X10 tickets for the record, and the VisiCore knowledge base for methodology.
Both CLIs are open source on GitHub. Self-paced teams can run them locally in their own harness; Vizzy adds the context, memory, guardrails, and ticket trail on top.
More SIEMs and destinations are coming, starting with Sentinel, CrowdStrike, and Google SecOps.
What that looks like in practice
Ask in plain English, on the web or in Slack:
- "Which source is driving our Splunk license this week, and which Cribl route feeds it?"
- "Onboard /var/log/nginx/access.log on the prod-web-linux fleet: create a pipeline that reformats it to CSV and send it to my S3 destination called s3-archive-prod."
- "Which nodes missed a heartbeat or are about to run out of disk?"
- "Add a Drop function for debug events on the k8s pipeline. Dry-run first."
Vizzy discovers the live state, correlates across Cribl and Splunk, proposes a change, dry-runs it, and writes only after you confirm. Findings, diffs, and deploy notes land in the ticket.
The human backstop
Vizzy isn't a replacement for an engineer. It's how our engineers scale. A Cribl certified VisiCore engineer is behind every ticket: they review, finish or fix, and note what was actually done. When Vizzy gets stuck, a human takes over, and the ticket shows the handoff.
Get it
Vizzy is included with X10 subscription and managed services, and available on credits as AI Services. Meet Vizzy · Open Vizzy in the portal · Request a demo