Use Splunk Enterprise Security data in Cisco Cloud Control AI Canvas
Use Cisco Cloud Control AI Canvas to ask read-only questions about Splunk Enterprise Security (ES) data that your organization has made available. AI Canvas displays information from Splunk Enterprise Security.
Benefits of integrating Splunk Enterprise Security with Cisco Cloud Control AI Canvas
When you configure Splunk Enterprise Security with Cisco Cloud Control AI Canvas in your organization, you can use AI Canvas to retrieve read-only context from Splunk Enterprise Security in the following categories:
-
Investigations: List and review investigations.
-
Findings: Review findings associated with an investigation.
-
Evidence and analyst context: Review investigation artifacts and analyst notes.
-
AI analysis: Review stored AI analysis for an investigation.
Prerequisites
Before you access ES data in AI Canvas, verify the following prerequisites.
-
Your organization has access to Cisco Cloud Control and AI Canvas.
-
An administrator has turned on the Splunk Enterprise Security integration for your Cisco Cloud Control environment.
-
You can sign in to Cisco Cloud Control and use AI Canvas. For more information, see Cisco Cloud Control Getting Started.
Access Splunk Enterprise Security in Cisco Cloud Control AI Canvas
Follow these steps to access Splunk Enterprise Security in Cisco Cloud Control AI Canvas:
- Sign in to Cisco Cloud Control.
- Navigate to a supported Splunk Enterprise Security page.
- Select the Cisco AI Assistant button in the navigation bar.
- If Splunk Enterprise Security context is available for the page, AI Canvas opens the Splunk Security Assistant experience with the available Splunk Enterprise Security context. If Splunk Enterprise Security context is not available, AI Canvas opens the general assistant experience.
- Ask a question about Splunk Enterprise Security data that you are authorized to access.
- Review the returned information and any indication that results are unavailable, incomplete, or outside your permissions.
The assistant displays only the Splunk Enterprise Security information available to your organization and role. If you do not have access to the requested data in Splunk Enterprise Security, the assistant cannot retrieve it.
Query Splunk Enterprise Security data
You can ask the following questions about Splunk Enterprise Security data:
- Show my open investigations
-
Summarize the investigation <investigation_id>
-
Identify the evidence that supports an investigation <investigation_id>
-
Show the findings for investigation <investigation_id>
-
Identify the latest analyst update on investigation <investigation_id>
Replace the <investigation_id> with an investigation identifier.
Limitations
The Splunk Enterprise Security information available to you can vary by deployment, role, and administrator configuration. A response can be partial when only some records are available or when you do not have access to all related records. Do not use AI Canvas to request actions that modify Splunk Enterprise Security data or change Splunk Enterprise Security configuration. The Cisco AI Assistant entry point and the Splunk Enterprise Security context available in AI Canvas can vary by the Splunk Enterprise Security page and the integration that your organization has turned on.