Use Splunk Observability Cloud with Cisco Cloud Control

Use the Splunk Observability Cloud and Cisco Cloud Control integration to investigate application issues across network and application domains.

The Splunk Observability Cloud and Cisco Cloud Control integration combines application and network telemetry in a cross-domain investigation workflow. The Network to Application Impact application included with this integration uses Splunk Application Performance Monitoring (APM) service data and ThousandEyes measurements to help you review application health, network health, affected services, and supporting evidence together.

Before you begin

Make sure that the following requirements are met:

Table 1. Integration prerequisites
Requirement Details
Cisco Cloud Control access You have administrator access to a Cisco Cloud Control tenant with the integration enabled.
Splunk Observability Cloud access Your Cisco Cloud Control tenant is linked to a Splunk Observability Cloud organization.
APM service data The Splunk Observability Cloud organization contains recent Splunk Application Performance Monitoring (APM) or Splunk Real User Monitoring (RUM) data for the services that you want to investigate.
ThousandEyes network data The relevant ThousandEyes test provides network loss, latency, and jitter measurements. These tests are required to correlate network to application signals.
Service correlation Network measurements identify the corresponding APM service. The current implementation uses a service tag whose value matches the APM service name exactly.

Configure the integration

  1. Pair Splunk Cloud Platform to Splunk Observability Cloud. Confirm that the connection reports a successful or active status. For more information, see Unified Identity: Splunk Cloud Platform and Splunk Observability Cloud.

  2. Link your Cisco Cloud Control tenant to the Splunk Observability Cloud organization that contains your application telemetry.

  3. Configure the relevant ThousandEyes test and confirm that it provides the following network metrics:

    • Network loss
    • Network latency
    • Network jitter
  4. Add the service correlation value to the network test. The value must match the service name shown in Splunk APM, including capitalization and punctuation.

    TEXT
    service=your-apm-service-name
  5. Confirm that the application has recent APM request, error, latency, and topology data in order to use the Network to Impact application.
  6. If available, configure optional infrastructure or packet telemetry for additional cards and details:
    • Configure Kubernetes or host telemetry for infrastructure counts and details.

    • For packet cards, ingest NetworkPacketsIn and NetworkPacketsOut from AWS CloudWatch-derived telemetry.

Investigate an application issue

Use the Network Application Impact application to correlate network health with application and infrastructure impact​.

  1. Select Network Application Impact Analysis from the list of applications in Cisco Cloud Control.

  2. Select the application, service, or network alert that you want to investigate.

  3. Review the application context, including service health, requests, errors, latency, and topology.

    1. When you expand the service information, you can view related network, microservice, and infrastructure health metrics. Health statuses:

      1. Healthy: The available application and network signals do not indicate a material problem for the selected time range.

      2. Degraded: One or more signals indicate a performance change or emerging condition, but the available evidence does not indicate the most severe level of impact.

      3. Critical: The available evidence indicates a severe condition or high-impact risk for the selected service or application.

      4. Unknown: There is not enough usable data to calculate or display a health or impact status.

    2. Alternatively, you can select the service or application name to open a link to troubleshoot directly in Splunk Observability.

  4. Review the Network Impact details to troubleshoot and identify causes for service health degradation.

  5. Compare the application and network signals to determine whether the network condition may be contributing to the application issue.

  6. Review affected services and the available impact indicators.

  7. Continue the investigation in the related APM, ThousandEyes, or evidence view.

Use AI-assisted root cause analysis

From the Cisco Cloud Control homepage, select the Actions menu to view a list of AI-recommended actions in response to your alerts. The analysis provides a summary of the suggested root cause of an alert based on data from your integrated applications.

Troubleshooting

Identify your symptom, then follow the corresponding checks.

Network to Application Impact does not load

Symptoms: A 500 type error indicating a back-end or request failure.

  • Confirm that Cisco Cloud Control is linked to the expected Splunk Observability Cloud organization.
  • Confirm that your user has access to both products.
  • Confirm that the integration and Network to App Impact are available for your organization.
  • Refresh the page and retry with a known application or service.
  • If the problem persists, contact your approved support team.

Symptoms: unable to correlate any usable network telemetry to the service. The required network metrics are missing, or the TE test does not include the service tag needed to corrrelate the network data with the APM service.

  • If the problem persists, contact your approved support team.
  • Confirm that the ThousandEyes test is active and has recent data.
  • Confirm that the test provides network loss, latency, and jitter.
  • Confirm that the network data contains the expected service correlation value.
  • Confirm that the correlation value matches the APM service name exactly.

  • Confirm that the selected application, service, and time range contain recent telemetry.
  • Confirm that the relevant metric family is available.
  • Check whether the card depends on optional infrastructure or packet telemetry.
  • Confirm that the required application and network inputs are present.
  • Check for gaps in the selected time range.
  • Retry with a service that has known recent APM and ThousandEyes data.