Configure Splunk Network Intelligence

Understand how to set up data sources and begin using Splunk Network Intelligence to monitor relevant application metrics.

Configure data inputs for Network Intelligence

Network Intelligence does not collect network data. It reads events that supported Splunk apps, add-ons, and external collectors send to Splunk indexes, then normalizes that data for inventory, health, alerts, and topology.

Configure credentials, collection inputs, and collector health in the relevant app, add-on, or external collector. Network Intelligence does not manage those settings. Network Intelligence begins processing data after the events arrive in an index.

Configure supported data sources

Install the minimum supported version listed for your data source, then enable and configure the inputs in the following tables. The sourcetype identifies the format of each event. Configure every input to write to an index included in the Network Intelligence index configuration.

Store and protect HEC tokens according to your organization's credential-management requirements. Configure the destination index for both streams.

The collection intervals in these tables are defaults for the listed app and add-on versions. Collection and Network Intelligence processing use separate schedules, so data might not appear immediately after you enable an input. If you change a collection interval, verify that Network Intelligence receives and processes the resulting events.

Cisco Meraki Add-on for Splunk

Use version 3.5.0 or later. Enable the listed inputs for each organization where applicable.
Expected sourcetype or endpoint Input configuration Default collection interval
meraki:devicesavailabilities Enable Devices Availabilities. 24 hours
meraki:switchportsbyswitch Enable Switch Ports By Switch. 24 hours
meraki:devicesuplinkslossandlatency Enable Devices Uplinks Loss And Latency. 24 hours
meraki:devicesuplinksaddressesbydevice Enable Device Uplink Addresses By Device. 24 hours
meraki:assurancealerts Enable Assurance Alerts. Set the initial history window as needed. 1 hour
meraki:organizationsnetworks Enable Organization Networks. 24 hours
meraki:devices Enable Devices. 24 hours
meraki:custom, endpoint_name="switch_ports_usage_history_by_device_by_interval" Add a Custom API input. Set query parameters to {"timespan":7200,"interval":1200}. 1 hour
meraki:custom, endpoint_name="switch_ports_statuses_by_switch" Add a Custom API input. No query parameters are required. 1 hour
meraki:custom, endpoint_name="devices_topology_l2_links" Add a Custom API input. No query parameters are required. 1 hour
meraki:custom, endpoint_name="devices_topology_nodes_discovered" Add a Custom API input. No query parameters are required. 1 hour

Cisco Enterprise Networking Add-on for Splunk

Use version 4.0.35 or later for Catalyst Center data.

Expected sourcetype or endpoint Input configuration Default collection interval
cisco:dnac:custom, endpoint_name="topology_physical_topology" Add a Custom API input for the physical topology endpoint. Use the endpoint name shown. 1 hour
cisco:dnac:site:topology Enable the Site Topology input. 1 hour
cisco:dnac:devicehealth Enable the Device Health input. 15 minutes
cisco:dnac:devicehealth:interface On the Device Health input, enable interface statistics (enable_interface_stats=1). This is not a separate input. 15 minutes
cisco:dnac:issue Enable the Issue input. 30 minutes

Cisco ThousandEyes App for Splunk

Use version 0.9.0 or later. Configure the app to send stream data to a publicly reachable HTTPS HTTP Event Collector (HEC) endpoint.

Expected sourcetype Input configuration
cisco:thousandeyes:metric Configure Tests Stream - Metrics. Select the account group, user, and tests or tags. Set the HEC endpoint, token, and destination index. The optional interval=300 setting applies to related Network Path API collection; it does not set the delivery interval for the metrics stream.
cisco:thousandeyes:alerts Configure Alerts Stream. Select the account group, user, and alert rules. Set the HEC endpoint, token, and destination index. Alert delivery uses a webhook and does not have a polling interval.

Verify your setup

After configuring an input:

  1. Confirm that the collector is successfully sending events to Splunk.

  2. Confirm that the events are in the configured index and have the expected sourcetype.

  3. Open the Network Intelligence setup status view and review any missing-source diagnostics. If a sourcetype is missing, check the collector input, destination index, and ni_indexes configuration.

The setup diagnostics report whether expected sourcetypes are present. They do not configure the collector or report its operational health.