Use Splunk Enterprise Security data in Cisco Cloud Control AI Canvas

Use Cisco Cloud Control AI Canvas to ask read-only questions about Splunk Enterprise Security (ES) data that your organization has made available. AI Canvas displays information from Splunk Enterprise Security.

This integration is designed to help you review investigation information. It does not modify Splunk Enterprise Security data or run response actions.
Note: The integration of Splunk Enterprise Security with Cisco Cloud Control AI Canvas is available as a Controlled Availability release.

Benefits of integrating Splunk Enterprise Security with Cisco Cloud Control AI Canvas

When you configure Splunk Enterprise Security with Cisco Cloud Control AI Canvas in your organization, you can use AI Canvas to retrieve read-only context from Splunk Enterprise Security in the following categories:

  • Investigations: List and review investigations.

  • Findings: Review findings associated with an investigation.

  • Evidence and analyst context: Review investigation artifacts and analyst notes.

  • AI analysis: Review stored AI analysis for an investigation.

Prerequisites

Before you access ES data in AI Canvas, verify the following prerequisites.

  • Your organization has access to Cisco Cloud Control and AI Canvas.

  • An administrator has turned on the Splunk Enterprise Security integration for your Cisco Cloud Control environment.

Access Splunk Enterprise Security in Cisco Cloud Control AI Canvas

Follow these steps to access Splunk Enterprise Security in Cisco Cloud Control AI Canvas:

  1. Sign in to Cisco Cloud Control.
  2. Navigate to a supported Splunk Enterprise Security page.
  3. Select the Cisco AI Assistant button in the navigation bar.
  4. If Splunk Enterprise Security context is available for the page, AI Canvas opens the Splunk Security Assistant experience with the available Splunk Enterprise Security context. If Splunk Enterprise Security context is not available, AI Canvas opens the general assistant experience.
  5. Ask a question about Splunk Enterprise Security data that you are authorized to access.
  6. Review the returned information and any indication that results are unavailable, incomplete, or outside your permissions.

The assistant displays only the Splunk Enterprise Security information available to your organization and role. If you do not have access to the requested data in Splunk Enterprise Security, the assistant cannot retrieve it.

Query Splunk Enterprise Security data

You can ask the following questions about Splunk Enterprise Security data:

  • Show my open investigations
  • Summarize the investigation <investigation_id>

  • Identify the evidence that supports an investigation <investigation_id>

  • Show the findings for investigation <investigation_id>

  • Identify the latest analyst update on investigation <investigation_id>

Replace the <investigation_id> with an investigation identifier.

Limitations

The Splunk Enterprise Security information available to you can vary by deployment, role, and administrator configuration. A response can be partial when only some records are available or when you do not have access to all related records. Do not use AI Canvas to request actions that modify Splunk Enterprise Security data or change Splunk Enterprise Security configuration. The Cisco AI Assistant entry point and the Splunk Enterprise Security context available in AI Canvas can vary by the Splunk Enterprise Security page and the integration that your organization has turned on.