Configure Splunk Network Intelligence
Understand how to set up data sources and begin using Splunk Network Intelligence to monitor relevant application metrics.
Configure data inputs for Network Intelligence
Network Intelligence does not collect network data. It reads events that supported Splunk apps, add-ons, and external collectors send to Splunk indexes, then normalizes that data for inventory, health, alerts, and topology.
Configure credentials, collection inputs, and collector health in the relevant app, add-on, or external collector. Network Intelligence does not manage those settings. Network Intelligence begins processing data after the events arrive in an index.
Configure supported data sources
Install the minimum supported version listed for your data source, then enable and configure the inputs in the following tables. The sourcetype identifies the format of each event. Configure every input to write to an index included in the Network Intelligence index configuration.
Store and protect HEC tokens according to your organization's credential-management requirements. Configure the destination index for both streams.
The collection intervals in these tables are defaults for the listed app and add-on versions. Collection and Network Intelligence processing use separate schedules, so data might not appear immediately after you enable an input. If you change a collection interval, verify that Network Intelligence receives and processes the resulting events.
Cisco Meraki Add-on for Splunk
| Expected sourcetype or endpoint | Input configuration | Default collection interval |
|---|---|---|
| meraki:devicesavailabilities | Enable Devices Availabilities. | 24 hours |
| meraki:switchportsbyswitch | Enable Switch Ports By Switch. | 24 hours |
| meraki:devicesuplinkslossandlatency | Enable Devices Uplinks Loss And Latency. | 24 hours |
| meraki:devicesuplinksaddressesbydevice | Enable Device Uplink Addresses By Device. | 24 hours |
| meraki:assurancealerts | Enable Assurance Alerts. Set the initial history window as needed. | 1 hour |
| meraki:organizationsnetworks | Enable Organization Networks. | 24 hours |
| meraki:devices | Enable Devices. | 24 hours |
| meraki:custom, endpoint_name="switch_ports_usage_history_by_device_by_interval" | Add a Custom API input. Set query parameters to {"timespan":7200,"interval":1200}. |
1 hour |
| meraki:custom, endpoint_name="switch_ports_statuses_by_switch" | Add a Custom API input. No query parameters are required. | 1 hour |
| meraki:custom, endpoint_name="devices_topology_l2_links" | Add a Custom API input. No query parameters are required. | 1 hour |
| meraki:custom, endpoint_name="devices_topology_nodes_discovered" | Add a Custom API input. No query parameters are required. | 1 hour |
Cisco Enterprise Networking Add-on for Splunk
Use version 4.0.35 or later for Catalyst Center data.
| Expected sourcetype or endpoint | Input configuration | Default collection interval |
|---|---|---|
| cisco:dnac:custom, endpoint_name="topology_physical_topology" | Add a Custom API input for the physical topology endpoint. Use the endpoint name shown. | 1 hour |
| cisco:dnac:site:topology | Enable the Site Topology input. | 1 hour |
| cisco:dnac:devicehealth | Enable the Device Health input. | 15 minutes |
| cisco:dnac:devicehealth:interface | On the Device Health input, enable interface statistics (enable_interface_stats=1). This is not a separate input. |
15 minutes |
| cisco:dnac:issue | Enable the Issue input. | 30 minutes |
Cisco ThousandEyes App for Splunk
Use version 0.9.0 or later. Configure the app to send stream data to a publicly reachable HTTPS HTTP Event Collector (HEC) endpoint.
| Expected sourcetype | Input configuration |
|---|---|
| cisco:thousandeyes:metric | Configure Tests Stream - Metrics. Select the account group, user, and tests or tags. Set the HEC endpoint, token, and destination index. The optional interval=300 setting applies to related Network Path API collection; it does not set the delivery interval for the metrics stream. |
| cisco:thousandeyes:alerts | Configure Alerts Stream. Select the account group, user, and alert rules. Set the HEC endpoint, token, and destination index. Alert delivery uses a webhook and does not have a polling interval. |
Verify your setup
After configuring an input:
-
Confirm that the collector is successfully sending events to Splunk.
-
Confirm that the events are in the configured index and have the expected sourcetype.
-
Open the Network Intelligence setup status view and review any missing-source diagnostics. If a sourcetype is missing, check the collector input, destination index, and
ni_indexesconfiguration.
The setup diagnostics report whether expected sourcetypes are present. They do not configure the collector or report its operational health.