DevOps & Infra
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
-
chambear2809 Bundle Splunk Github Ta SetupUse when the user asks to onboard, configure, render, or validate GitHub audit/security data in Splunk. Install, render, configure, and validate the Splunk Add-on for GitHub (Splunk_TA_github, Splunkbase 6254). Renders GitHub Cloud audit, user, and code/dependabot/secret scanning alert inputs; emits PAT and HEC token runbooks, GitHub Cloud HEC audit streaming guidance, GHES syslog/SC4S handoffs, expanded github_audit readiness coverage, and validation SPL. Use for GitHub audit logs, GitHub Enterprise Cloud, GHES audit, GitHub security scanning alerts, or Splunk_TA_github onboarding.
-
chambear2809 Bundle Splunk Platform SizingUse when the user asks to size a Splunk cluster, decide how many indexers or search heads they need, plan reference hardware, evaluate an All-In-One vs distributed deployment, size Splunk on Kubernetes, or estimate storage for a retention requirement. Size a Splunk deployment from a use case (daily ingest, retention, search load, premium apps, high availability) and render a sizing recommendation report plus machine-readable sizing.json. Covers All-In-One single-server standalone, distributed Splunk Validated Architectures (C/M series), Splunk on Kubernetes (SOK and Splunk POD), and Splunk Cloud, with Enterprise Security and ITSI workload multipliers.
-
chambear2809 Bundle Cisco Thousandeyes MCP SetupUse when the user asks to register the ThousandEyes MCP, set up TE in Cursor/Claude/Codex/VS Code/Kiro, configure the Cisco ThousandEyes Cursor plugin, or pair an AI assistant with TE. Render and (optionally) apply Model Context Protocol client configurations for the official ThousandEyes MCP Server (https://api.thousandeyes.com/mcp, GA per docs.thousandeyes.com/.../thousandeyes-mcp-server). Supports Cursor, Claude Code, Codex, VS Code, and AWS Kiro clients with both OAuth Bearer and OAuth2 flows. Surfaces TE rate limits, the unit-consumption warning for Instant Tests, and gates the write/Instant- Test tool group behind an explicit acknowledgement.
-
chambear2809 Bundle Splunk Appdynamics Apm SetupUse when the user asks for AppDynamics APM, business applications, tiers, nodes, business transactions, snapshots, service endpoints, remote services, information points, metrics, AWS Lambda/serverless APM, development monitoring, OpenTelemetry ingestion, OTel collector setup, or application server agent instrumentation snippets. Render and validate Splunk AppDynamics APM workflows for business applications, tiers, nodes, business transactions, service endpoints, remote services, information points, snapshots, metrics, serverless APM, Development Level Monitoring, Splunk AppDynamics for OpenTelemetry, OTel collector/access-key validation, and app-server agent snippets.
-
chambear2809 Bundle Splunk Cloud Acs Admin SetupUse when the user asks to manage Splunk Cloud ACS, acs admin, ACS indexes, ACS HEC tokens, ACS users and roles, app permissions, private connectivity, outbound ports, DDSS, ACS limits, maintenance windows, restart current-stack, ACS license state, Observability pairing, or to audit Splunk Cloud control-plane configuration. Render, preflight, inventory, apply, audit, and validate Splunk Cloud Admin Config Service (ACS) administration across IP allowlists, indexes, HEC tokens, users, roles, capabilities, app permissions, private connectivity, outbound ports, DDSS self-storage, limits.conf settings, maintenance windows, restarts, apps, authentication tokens, deployment task status, license state, and Observability pairing handoffs.
-
chambear2809 Bundle Splunk Connect For Syslog SetupUse when the user asks about SC4S, Splunk Connect for Syslog, syslog-ng collector setup, or syslog ingestion through HEC. Deploy and validate Splunk Connect for Syslog (SC4S) for Splunk Enterprise or Splunk Cloud. Prepares Splunk indexes and HEC, renders Docker/Podman/systemd or Kubernetes Helm configuration, and validates SC4S startup.
-
chambear2809 Bundle Splunk Observability Native OpsUse when configuring native Splunk Observability Cloud operations beyond collection and classic dashboards, including detectors, alert routing, On-Call handoffs, APM service maps and traces, RUM session workflows, Synthetic tests and waterfall artifacts, and modern logs chart handoffs.
-
chambear2809 Bundle Galileo On Prem Kubernetes SetupUse when planning, reviewing, doctoring, or checking full deployment coverage for Galileo On-Prem on Kubernetes. Render a non-mutating, immutable orchestration packet for the Galileo Stack, galileoctl, packaged Agent Control, Luna Studio, Wizard GPU/local inference, air-gapped supply chains, and production-readiness handoffs. Route implementation to the owning child skill; reject install, upgrade, rollback, uninstall, registry writes, and all other live mutations.
-
chambear2809 Bundle Splunk Cloud Acs Allowlist SetupUse when an existing handoff or slash command still references splunk-cloud-acs-allowlist-setup. Compatibility alias for the older Splunk Cloud ACS IP allowlist workflow. Use splunk-cloud-acs-admin- setup for new ACS work, including allowlists, indexes, HEC tokens, users, roles, capabilities, app permissions, private connectivity, outbound ports, DDSS self-storage, limits, maintenance windows, and restarts.
-
chambear2809 Bundle Splunk MCP Server SetupUse when the user asks about Splunk MCP server setup, Splunk MCP TA, Splunk_MCP_Server, /services/mcp, the hosted SCS MCP Gateway for Splunk Observability Cloud, Cursor MCP, Codex MCP, Claude Code MCP connectivity to Splunk, or Cisco Data Fabric agentic/tool access through Splunk MCP. Install, configure, validate, and uninstall the Splunk MCP Server app for Cisco Data Fabric agentic/tool access (Splunk_MCP_Server / "Splunk MCP TA"). Configures mcp.conf server settings, rate limits, encrypted token issuance, and renders a shared client bridge bundle that works with Cursor, Codex, and Claude Code.
-
chambear2809 Bundle Splunk Microsoft Cloud SetupUse when the user asks about Splunk_TA_o365, Office 365, Microsoft 365, Entra ID, Azure AD audit/sign- in, Microsoft Graph, Splunk Add-on for Microsoft Cloud Services, or Microsoft cloud log onboarding in Splunk. Install, render, configure, and validate the Splunk add-ons for Microsoft cloud telemetry: the Splunk Add-on for Microsoft Office 365 (splunk_ta_o365, Splunkbase 4055) and the Splunk Add-on for Microsoft Cloud Services (Splunk_TA_microsoft-cloudservices, Splunkbase 3110). Renders real inputs.conf stanzas for Office 365 Management Activity (Entra/Azure AD, Exchange, SharePoint, General, DLP), Microsoft Graph Entra ID metadata, and Azure audit, emits an Entra app-registration account runbook, creates the o365 and azure indexes, maps source types to CIM, and validates ingestion.
-
chambear2809 Bundle Galileo On Prem Air Gap SetupBuild and verify a digest-bound Galileo On-Prem air-gap supply-chain bundle covering Helm charts, galileoctl, every ordinary/init/hook/job/test image, OCI archives, model bundles, architectures, private-registry mappings, scanning evidence, and no-egress endpoints, while surfacing explicit model/runtime and endpoint-rewrite evidence gates. Use when preparing, transferring, mirroring, upgrading, or auditing Galileo for an offline Kubernetes cluster.
-
chambear2809 Bundle Splunk Connect For Otlp SetupUse when the user asks to deploy the OTLP modular input, expose OTLP gRPC/HTTP listeners, configure OTel SDK or Collector senders to Splunk Platform, verify HEC token/index routing, or troubleshoot Splunk Connect for OTLP. Install, administer, validate, diagnose, repair, and render sender handoffs for Splunk Connect for OTLP (`splunk-connect-for-otlp`, Splunkbase app 8704).
-
chambear2809 Bundle Splunk Connect For Snmp SetupUse when the user asks about SC4SNMP, Splunk Connect for SNMP, SNMP polling, or SNMP trap ingestion through HEC. Deploy and validate Splunk Connect for SNMP (SC4SNMP) for Splunk Enterprise or Splunk Cloud. Prepares Splunk indexes and HEC, renders Docker Compose or Kubernetes Helm configuration, and validates SC4SNMP polling or trap readiness.
-
chambear2809 Bundle Splunk Security Essentials SetupUse when a user asks to set up SSE, Security Essentials, MITRE/Kill Chain content exploration, Security Content recommendations, or starter security posture dashboards. Install, configure readiness, and validate Splunk Security Essentials (`Splunk_Security_Essentials`, Splunkbase app 3435) on Splunk Cloud or Splunk Enterprise.
-
chambear2809 Bundle Splunk Universal Forwarder SetupUse when the user asks to install, upgrade, enroll, or check Universal Forwarders separately from full Splunk Enterprise host bootstrap or Agent Management server-class work. Bootstrap Splunk Universal Forwarder runtimes on Linux, macOS, and Windows, resolve official UF downloads, render first-class enrollment assets for deployment servers, static Enterprise indexers, or Splunk Cloud credentials packages, and validate installed forwarders.
-
chambear2809 Bundle Splunk Dashboard Studio SetupUse when the user asks to create a Splunk Dashboard Studio dashboard, build a platform dashboard as code, push a dashboard JSON to data/ui/views, or replicate a dashboard between Splunk environments. Not for Splunk Observability Cloud dashboards, which use splunk-observability-dashboard-builder. Render, validate, and apply Splunk Platform Dashboard Studio dashboards: build a version 2 JSON definition (dataSources, visualizations, inputs, layout, defaults), wrap it in the data/ui/views eai:data XML, and create or update the view via REST with ACL governance.
-
chambear2809 Bundle Splunk Federated Search SetupUse when configuring Cisco Data Fabric federated search or standalone Splunk Federated Search, cross- domain search, federated analytics, S3 data-lake search, or querying data where it resides. Render, preflight, apply, and validate FSS2S standard/transparent providers and reviewed legacy FSS3 payloads; render 10.5 migration guidance and current Data Management handoffs for S3, Azure, Databricks, Snowflake, and DDSS; distinguish Glue, Iceberg REST, and Splunk-native catalogs; preserve handoff-only Amazon Security Lake (`aws_lake`) and Cisco SAL (`aws_s3_sal`) identities; and manage supported global- switch, status, file, SHC, and REST workflows.
-
chambear2809 Bundle Splunk Ingest Processor SetupUse when the user asks to configure Ingest Processor, author Ingest Processor pipelines, route or transform data at ingest time, validate Ingest Processor readiness, or compare Ingest Processor with Edge Processor and Data Manager, including Cisco Data Fabric or telemetry pipeline management requests that involve Splunk Cloud ingest-time routing and transformation. Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and monitoring searches, metrics, OCSF, decrypt, S3 archive, custom pipeline templates, AI-powered data management readiness, Automated Field Extraction, Guided Onboarding with Auto-Schematization, and downstream readiness checks.
-
chambear2809 Bundle Splunk Observability Synthetics SetupUse when the user asks to create, configure, validate, or operate Splunk Synthetic Monitoring tests without loading the broader native-ops workflow first. Render and validate focused Splunk Observability Cloud Synthetic Monitoring setup plans, including browser, API, HTTP/uptime, SSL, and port tests, locations, frequency, run-now and waterfall artifact handoffs, native-ops delegated specs, and dashboard/detector follow-ups.
-
chambear2809 Bundle Splunk Observability Azure IntegrationUse when the user asks to connect Splunk Observability Cloud to Azure Monitor, configure the Azure integration, manage service-principal credential files, onboard multiple subscriptions, or set up Azure dashboards, detectors, logs, AKS telemetry, Log Observer Connect, or HEC-token handoffs. Render, apply, validate, discover, and diagnose the Splunk Observability Cloud Azure integration for Azure Monitor metrics. Covers REST payloads, Terraform, Azure CLI service-principal creation, Bicep role assignments, subscriptions, service selection, custom namespaces, resource filters, credential-hash drift detection, poll-rate and namedToken checks, and Azure Government guards.
-
chambear2809 Bundle Splunk Observability Dashboard BuilderUse when creating, planning, rendering, validating, or applying Splunk Observability Cloud dashboards from natural-language dashboard requests, JSON or YAML dashboard specs, SignalFlow chart definitions, or Observability dashboard-as-code workflows. Supports native classic Observability dashboard/chart APIs with render-first safety; treats modern dashboard sections, logs charts, service maps, and Dashboard Studio as advisory/secondary paths unless a verified API is available.
-
chambear2809 Bundle Splunk Index Lifecycle Smartstore SetupUse when the user asks to inventory index age/size/retention, decide whether indexes are unused, change searchable retention, configure SmartStore remote volumes, enable Cloud archive handoffs, restore/thaw archived data, disable indexes, delete indexes, clean standalone index data, configure S3/GCS/Azure object storage for indexes, set indexes.conf lifecycle settings, maxTotalDataSizeMB, maxGlobalDataSizeMB, maxGlobalRawDataSizeMB, frozenTimePeriodInSecs, cache manager settings, limits.conf remote-storage localization settings, cluster-manager bundle deployment, or standalone indexer lifecycle assets. Render, preflight, apply, and validate Splunk index lifecycle and SmartStore workflows.
-
chambear2809 Bundle Splunk Observability Otel Collector SetupUse when rendering, preflighting, applying, validating, diagnosing, and removing the Splunk Distribution of OpenTelemetry Collector for Kubernetes and Linux; audit and stage Splunkbase apps 7125, 8698, and 8699 through deployment servers, Linux heavy forwarders, or Linux Universal Forwarders; configure guarded Splunk Platform HEC or Splunk Connect for OTLP destinations; and route specialized Observability products to their owning skills.
-
chambear2809 Bundle Splunk Appdynamics K8S Cluster Agent SetupUse when the user asks for AppDynamics Cluster Agent, Kubernetes monitoring, AppDynamics Kubernetes auto-instrumentation, Splunk OTel Collector through Cluster Agent, O11y export, or workload rollout validation. Render, validate, and gate Splunk AppDynamics Kubernetes Cluster Agent, Kubernetes auto- instrumentation, and Splunk OpenTelemetry Collector setup through the Cluster Agent, including dual- signal combined-agent plans for Java, .NET Core Linux, Node.js, Machine Agent handoff, and Splunk Observability Cloud export validation.
-
chambear2809 Bundle Galileo On Prem Luna Studio SetupRender, preflight, validate, observe, and prepare Galileo/CSE joint-session install, upgrade, rollback, and retirement handoffs for Galileo Luna Studio on Kubernetes with dedicated PostgreSQL, object storage, backend and UI, routing, four out-of-band Secrets, GPU Jobs, Vertex AI, and remote or hybrid training. Use when operating Luna Studio for Galileo On-Prem or when an exact umbrella package requires a reviewed Luna overlay instead of its standalone release.
-
chambear2809 Bundle Splunk Enterprise Kubernetes SetupUse when planning, installing, upgrading, or validating either runtime. Render, preflight, apply, and validate Splunk Enterprise on Kubernetes with Splunk Operator for Kubernetes 3.1.0 or Splunk POD 10.4.0_1.6.0 on Cisco UCS. Covers SOK S1/C3/M4, guarded C3 indexing and ingestion separation, reviewed Helm overlays, and POD Small through X-Large with ES, ITSI, and TLS variants.
-
chambear2809 Bundle Splunk Observability Deep Native WorkflowsUse when the user asks for full native UI/product workflow coverage beyond collection, classic dashboards, or basic detector setup, including emerging Cisco/Splunk Observability routes such as Digital Experience Analytics, DXA, Metrics Pipeline Management, MPM, or telemetry pipeline management. Render and validate Digital Experience Analytics (DXA), Metrics Pipeline Management (MPM), and deep native Splunk Observability Cloud operator workflows for modern dashboards, APM service maps, service views, business transactions, Trace Analyzer and trace waterfalls, AlwaysOn Profiling flame graphs, RUM session replay for browser and mobile, RUM error analysis, RUM URL grouping, Database Monitoring query and explain-plan triage, Synthetic waterfall details and artifacts, SLO creation and burn-rate alerting, Infrastructure/Kubernetes/Network Explorer navigators, Related Content, AI Assistant investigations, and Splunk Observability Cloud for Mobile app workflows.
-
chambear2809 Bundle Splunk Observability Isovalent IntegrationUse when wiring Cilium, Tetragon, or Hubble metrics into Splunk Observability Cloud, shipping Tetragon logs to Splunk Platform, or validating Isovalent telemetry after platform install. Wire an installed Isovalent stack (Cilium, Hubble, Tetragon, optional Hubble Enterprise or cilium-dnsproxy) to Splunk Observability Cloud and Splunk Platform. Renders Splunk OTel Collector scrape overlays, metric filters, Tetragon filelog ingestion defaults, stdout and legacy fluentd alternatives, dashboards, detectors, and handoff scripts for base collector, HEC, and Cisco Security Cloud ingestion.
-
chambear2809 Bundle Splunk Microsoft Security Ta SetupUse when the user asks to onboard, configure, render, or validate Microsoft Security / Defender data in Splunk. Install, render, configure, and validate the Splunk Add-on for Microsoft Security (Splunk_TA_MS_Security, Splunkbase 6207). Renders package-backed Defender incidents, endpoint alerts, machines, simulations, Event Hub / Advanced Hunting, and Threat Intelligence inputs; emits Entra app account runbooks, Splunk Cloud UI-only and Event Hub egress caveats, macros for package dashboards/searches, migration notes, and validation SPL. Use for Microsoft 365 Defender, Defender for Endpoint, Microsoft Security, or Splunk_TA_MS_Security onboarding.
-
chambear2809 Bundle Cisco Meraki Aam Thousandeyes SetupUse when the user asks to link Meraki Dashboard to ThousandEyes, deploy ThousandEyes Enterprise Agents on supported Meraki MX networks, claim or use Meraki AAM free tests, create ThousandEyes tests from Meraki Insight / Active Application Monitoring, monitor an application from agents inside Meraki networks, inspect or summarize Meraki Dashboard HAR/POST requests for the AAM wizard, or validate the resulting ThousandEyes agents, tests, and results. Render, capture, validate, and safely operate Cisco Meraki Active Application Monitoring with ThousandEyes.
-
chambear2809 Bundle Galileo On Prem Agent Control SetupRender, validate, preflight, observe, and prepare Galileo/CSE joint-session install, upgrade, rollback, and retirement handoffs for the packaged Galileo Agent Control Kubernetes lifecycle, including database policy, migrations, routing, UI proxy wiring, feature flags, resilience, and immutable chart or umbrella-overlay evidence. Use when deploying or upgrading Agent Control as part of Galileo On-Prem; use galileo-agent-control-setup instead for runtime controls and Splunk sinks.
-
chambear2809 Bundle Splunk Data Source Readiness DoctorUse when the user asks for data-source readiness, ES/ITSI/ARI readiness scoring, CIM or OCSF validation, data-model acceleration checks, dashboard population checks, ingest pipeline health, knowledge-object enrichment, federated data usability, ITSI summary health, or fix handoffs after app/input setup. Diagnose whether onboarded Splunk data sources are usable by Enterprise Security, ITSI, Asset and Risk Intelligence, CIM, OCSF, and dashboards.
-
chambear2809 Bundle Widefield Saviynt Integration SetupUse when the user asks to connect WideField Security to Saviynt, map WideField detections to Saviynt remediation policies, or collect Saviynt evidence while failing closed for unsupported live Saviynt mutation. Render and validate Saviynt Identity Cloud remediation mappings for WideField Security findings, including access revocation, password reset, and micro-certification handoffs.
-
chambear2809 Bundle Splunk Amazon Kinesis Firehose SetupUse when the user asks to send AWS Firehose data to Splunk. Render and validate Amazon Kinesis Firehose to Splunk HEC onboarding for CloudTrail, VPC Flow Logs, CloudWatch events, and raw or JSON data, including HEC token/index handoffs, delivery stream settings, buffering, retry, S3 backup, IAM policy stubs, CloudWatch delivery metrics, ACK guidance, and strict source/sourcetype readiness evidence.
-
chambear2809 Bundle Splunk Observability AWS IntegrationUse when the user asks to connect AWS to Splunk Observability Cloud, configure CloudWatch Metric Streams, render IAM policies, manage the AWSCloudWatch REST/Terraform object, monitor Bedrock metrics, set up multi-account AWS Organizations onboarding, audit drift, or migrate polling to Metric Streams. Hand off Lambda APM, AWS logs, dashboards, detectors, and EC2/EKS host telemetry to their owning skills. Render, preflight, apply, validate, discover, and diagnose the Splunk Observability Cloud AWSCloudWatch integration across polling, Splunk-managed Metric Streams, AWS-managed Metric Streams, and Terraform paths. Covers IAM trust and policy stubs, External ID and SecurityToken auth, CloudFormation and StackSets assets, Terraform payloads, field conflict checks, recommended stats, namespace sync rules, PrivateLink ingest stubs, drift adoption, and troubleshooting.
Frequently asked questions
What are DevOps & Infra agent skills?
DevOps agent skills automate the delivery side of software: CI/CD pipelines, Dockerfiles, infrastructure as code, releases, and incident checklists. A skill gives your AI agent the exact runbook to follow, so deployments and configs come out consistent every time.
Which DevOps & Infra skills are most installed?
Popular DevOps & Infra skills on SkillMD right now include splunk-github-ta-setup, splunk-platform-sizing, cisco-thousandeyes-mcp-setup. Rankings shift as installs change; sort this page by "Most installs" for the live list.
Do DevOps & Infra skills work with Claude Code and Cursor?
Yes. Every skill here ships as a SKILL.md file, an open format that works in Claude Code, Claude.ai, Cursor, Codex, Windsurf, and 60+ other agents. Install one with npx skillmds@latest add <owner>/<name>, or copy the file into your agent's skills directory.