Cisco Data Fabric Setup
Prerequisites
| Tool or access |
Purpose |
Verify |
| Bash and Python 3 |
Run bundled setup and validation helpers |
bash --version && python3 --version |
| Required product/platform access |
Inspect or configure the selected target |
Complete the documented preflight |
| Credential files for live modes |
Keep secrets out of chat |
Verify paths only |
Workflow Overview
┌───────────┐ ┌───────────────┐ ┌───────────────┐ ┌─────────────────┐
│ Preflight │ → │ Render/review │ → │ Apply/handoff │ → │ Validate evidence │
└───────────┘ └───────────────┘ └───────────────┘ └─────────────────┘
When to Activate
- Users need Cisco Data Fabric architecture, feature or product coverage, readiness assessments, gap analysis,
machine-data activation, federation targets, storage tiering, AI-ready data, or AgenticOps data foundation
requests. Distinguish.
- Preview and review the cisco data fabric setup workflow before any live apply phase.
- Diagnose failed prerequisites, generated assets, configuration, or validation evidence.
Scope
Follow the documented read-only or render-first path whenever it is available.
This skill does not imply permission to mutate live systems. Require explicit
apply flags, protected credentials, and operator review for state changes.
Examples
Inspect the supported setup modes before selecting one:
bash skills/cisco-data-fabric-setup/scripts/setup.sh --help
Expected output: usage, supported modes, and required arguments are displayed
without changing the target environment.
Inspect validation modes before running completion checks:
bash skills/cisco-data-fabric-setup/scripts/validate.sh --help
Expected output: offline, live, and completion options are displayed when the
skill supports them; help exits without mutation.
Troubleshooting
| Issue |
Cause |
Resolution |
| Preflight fails |
A required tool or access path is missing |
Resolve it before rendering or applying |
| Rendered assets are incomplete |
Required non-secret inputs are absent |
Complete intake and render again |
| Apply is blocked |
Review, credentials, or explicit acceptance is missing |
Use the documented handoff |
| Validation is incomplete |
Live evidence is unavailable |
Record the gap and keep completion open |
Treat Cisco Data Fabric as the architecture powered by the Splunk Platform,
not as a single installer, SKU, API, or storage product. Render a complete
coverage packet first, then execute only reviewed child-skill plans whose
public contracts and required non-secret inputs are available.
Decision Workflow
- Read
references/feature-matrix.md for the architecture, feature stages,
product owners, and boundaries.
- Read
references/research-ledger.md before changing availability claims,
federation targets, model status, or product naming.
- Collect a non-secret intake from
template.example.
- Render and validate the packet.
- Review
gap-register.md, doctor-report.md, and the product and federation
matrices before executing delegated renders.
- Apply or validate state through the owning child skill, never through a
fabricated Cisco Data Fabric API.
Architecture Lanes
- Data access and management: collect, inspect, filter, shape, redact,
route, tier, and monitor machine data with supported Splunk ingestion,
Edge Processor, Ingest Processor, SPL2, and Ingest Monitoring workflows.
- Federation: route Splunk-to-Splunk and current Splunk Cloud Data
Management connection/dataset work to
splunk-federated-search-setup.
Track Amazon S3, Microsoft Azure, Azure Databricks, Snowflake, DDSS, and
Amazon Security Lake separately; do not infer equal stage or entitlement.
Product lifecycle and tenant access are separate fields: for example,
Amazon S3 federation and Federated Analytics can be GA while still requiring
sales activation, scan entitlement, a premium add-on, or topology gates.
- Storage and catalog: distinguish the real-time Splunk index, external
stores, DDSS/DDAA/SmartStore adjacencies, and the alpha Machine Data Lake.
Built-in Data Catalog and Machine Data Lake remain readiness handoffs until
stable public administration contracts exist.
- Context and governance: cover schema and catalog metadata, knowledge
objects, CIM/OCSF, ITSI/business context, RBAC, lineage, audit, human
approval, and downstream data-readiness evidence.
- AI activation and action: delegate AI Toolkit/PSC/DSDL, hosted-model
readiness, and MCP Server. Distinguish the available open Cisco Time Series
Model 1.0 from the GA hosted Cisco Deep Time Series Model integration, keep Agent
Launchpad at its documented GA boundary with its region, egress, connection,
and enabled-agent gates, and keep AI Canvas at its CA boundary.
- Cross-domain experience: represent SecOps, ITOps, Engineering/DevOps,
NetOps, Splunk Enterprise Security, ITSI, Observability Cloud, Cisco Cloud
Control, AI Canvas, and Cisco product telemetry as consumers or handoffs,
not as interchangeable Data Fabric components.
Safe First Command
bash skills/cisco-data-fabric-setup/scripts/setup.sh --help
Primary Workflow
Render and validate the complete evidence-backed packet:
bash skills/cisco-data-fabric-setup/scripts/setup.sh \
--render --validate \
--spec skills/cisco-data-fabric-setup/template.example \
--output-dir cisco-data-fabric-rendered
Run the gap/readiness doctor:
bash skills/cisco-data-fabric-setup/scripts/setup.sh \
--doctor \
--spec skills/cisco-data-fabric-setup/template.example \
--output-dir cisco-data-fabric-rendered
Preview delegated commands without writing or executing:
bash skills/cisco-data-fabric-setup/scripts/setup.sh \
--execute data-management,federation,ai-activation,context-governance \
--dry-run --json \
--spec skills/cisco-data-fabric-setup/template.example
Execute only reviewed delegated render/doctor commands:
bash skills/cisco-data-fabric-setup/scripts/setup.sh \
--execute data-management,ai-activation \
--accept-execute \
--spec skills/cisco-data-fabric-setup/template.example \
--output-dir cisco-data-fabric-rendered
CLI Contract
setup.sh supports --render, --validate, --doctor,
--execute SECTION[,SECTION], --accept-execute, --dry-run, --json,
--spec PATH, and --output-dir DIR.
Delegated sections:
data-management
federation
ai-activation
context-governance
Handoff-only sections, which refuse explicit execution:
storage-catalog
experience
Child commands are render, doctor, or plan operations. Applying their output
requires the child skill's own explicit approval gates. A missing child spec,
tenant URL, MCP URL, entitlement, or public API is reported as a gap rather
than silently converted into a successful apply.
Non-dry-run delegation fails before any child command when gap-register.json
contains an error, a selected section is handoff-only, or any selected
executable section has no reviewed command. This prevents partial execution
when a later lane is missing required intake.
Non-Negotiable Boundaries
- Do not claim a direct Cisco Data Fabric management API.
- Do not call Machine Data Lake or its built-in Data Catalog GA; current
public material identifies Machine Data Lake as alpha.
- Do not collapse store-specific federation stage, region, role, catalog, and
entitlement requirements into a generic "Federated Search is GA" claim.
- Do not use
activation_required as a product lifecycle. Record lifecycle in
product_stage and tenant/commercial gates in access_requirement.
- Do not create new legacy Amazon S3 federated providers on Splunk Cloud
10.5; the old provider/index path is deprecated and migrated to the Data
Management connection/dataset model.
- Do not promote announcement dates to current availability. Cisco Time Series
Model 1.0 is published as an open Apache-2.0 model and the hosted Cisco Deep
Time Series Model integration is generally available since AI Toolkit
6.0.0,
but they remain separately governed layers and neither one settles the other.
- Do not pair AI Toolkit
6.0.2 with a PSC release below 4.3.4. The audited
baseline is 6.0.2 with PSC 4.3.4 on Python 3.13; PSC 4.3.2 only
applies back at AI Toolkit 5.7.4.
- Do not describe Splunk AI Toolkit Agent Launchpad as alpha, private preview,
or a Fall 2026 GA target. Current AI Toolkit documentation makes it generally
available since
6.0.0. Report it as unreachable only when a readiness gate
actually fails: an unsupported AWS region or a missing region egress IP in
the stack apiAllowlistIP, no supported LLM connection, or no enabled agent.
Splunk Enterprise reaches it through the Splunk Cloud Connect app rather than
being unsupported.
- Do not treat Cisco Security Analytics and Logging (SAL) as Splunk Machine
Data Lake or as an automatically configured federation target.
- For AI Canvas with Splunk, require Cloud Control enablement, Splunk Cloud
10.5.2605.3, current AI Assistant and MCP Server, and
mcp_tool_execute; retain the 100-row-per-card and forbidden-SPL-command
limitations in the production handoff.
- Never accept raw tokens, passwords, API keys, client secrets, or private
keys in chat, argv, specs, or rendered artifacts.
Validation
bash skills/cisco-data-fabric-setup/scripts/validate.sh \
--output-dir cisco-data-fabric-rendered
python3 -m py_compile \
skills/cisco-data-fabric-setup/scripts/render_assets.py
Read reference.md for the rendered artifact contract and delegated owner
map.
1---2name: cisco-data-fabric-setup3description: Use when users need Cisco Data Fabric architecture, feature or product coverage, readiness assessments, gap analysis, machine-data activation, federation targets, storage tiering, AI-ready data, or AgenticOps data foundation requests. Distinguish this architecture from a single product, package, entitlement, or direct API. Research, map, render, doctor, validate, and safely delegate complete Cisco Data Fabric adoption plans across Splunk data management, Edge Processor, Ingest Processor, SPL2, Federated Search, Machine Data Lake, Data Catalog, Splunk indexes and external stores, AI Toolkit and hosted models, Agent Builder, MCP Server, AI Canvas, context, governance, and cross-domain consumers.4---56# Cisco Data Fabric Setup78## Prerequisites910| Tool or access | Purpose | Verify |11|---|---|---|12| Bash and Python 3 | Run bundled setup and validation helpers | `bash --version && python3 --version` |13| Required product/platform access | Inspect or configure the selected target | Complete the documented preflight |14| Credential files for live modes | Keep secrets out of chat | Verify paths only |1516## Workflow Overview1718```text19┌───────────┐ ┌───────────────┐ ┌───────────────┐ ┌─────────────────┐20│ Preflight │ → │ Render/review │ → │ Apply/handoff │ → │ Validate evidence │21└───────────┘ └───────────────┘ └───────────────┘ └─────────────────┘22```2324## When to Activate2526- Users need Cisco Data Fabric architecture, feature or product coverage, readiness assessments, gap analysis,27 machine-data activation, federation targets, storage tiering, AI-ready data, or AgenticOps data foundation28 requests. Distinguish.29- Preview and review the cisco data fabric setup workflow before any live apply phase.30- Diagnose failed prerequisites, generated assets, configuration, or validation evidence.3132## Scope3334Follow the documented read-only or render-first path whenever it is available.35This skill does not imply permission to mutate live systems. Require explicit36apply flags, protected credentials, and operator review for state changes.3738## Examples3940Inspect the supported setup modes before selecting one:4142```bash43bash skills/cisco-data-fabric-setup/scripts/setup.sh --help44```4546Expected output: usage, supported modes, and required arguments are displayed47without changing the target environment.4849Inspect validation modes before running completion checks:5051```bash52bash skills/cisco-data-fabric-setup/scripts/validate.sh --help53```5455Expected output: offline, live, and completion options are displayed when the56skill supports them; help exits without mutation.5758## Troubleshooting5960| Issue | Cause | Resolution |61|---|---|---|62| Preflight fails | A required tool or access path is missing | Resolve it before rendering or applying |63| Rendered assets are incomplete | Required non-secret inputs are absent | Complete intake and render again |64| Apply is blocked | Review, credentials, or explicit acceptance is missing | Use the documented handoff |65| Validation is incomplete | Live evidence is unavailable | Record the gap and keep completion open |6667Treat Cisco Data Fabric as the architecture powered by the Splunk Platform,68not as a single installer, SKU, API, or storage product. Render a complete69coverage packet first, then execute only reviewed child-skill plans whose70public contracts and required non-secret inputs are available.7172## Decision Workflow73741. Read `references/feature-matrix.md` for the architecture, feature stages,75 product owners, and boundaries.762. Read `references/research-ledger.md` before changing availability claims,77 federation targets, model status, or product naming.783. Collect a non-secret intake from `template.example`.794. Render and validate the packet.805. Review `gap-register.md`, `doctor-report.md`, and the product and federation81 matrices before executing delegated renders.826. Apply or validate state through the owning child skill, never through a83 fabricated Cisco Data Fabric API.8485## Architecture Lanes86871. **Data access and management**: collect, inspect, filter, shape, redact,88 route, tier, and monitor machine data with supported Splunk ingestion,89 Edge Processor, Ingest Processor, SPL2, and Ingest Monitoring workflows.902. **Federation**: route Splunk-to-Splunk and current Splunk Cloud Data91 Management connection/dataset work to `splunk-federated-search-setup`.92 Track Amazon S3, Microsoft Azure, Azure Databricks, Snowflake, DDSS, and93 Amazon Security Lake separately; do not infer equal stage or entitlement.94 Product lifecycle and tenant access are separate fields: for example,95 Amazon S3 federation and Federated Analytics can be GA while still requiring96 sales activation, scan entitlement, a premium add-on, or topology gates.973. **Storage and catalog**: distinguish the real-time Splunk index, external98 stores, DDSS/DDAA/SmartStore adjacencies, and the alpha Machine Data Lake.99 Built-in Data Catalog and Machine Data Lake remain readiness handoffs until100 stable public administration contracts exist.1014. **Context and governance**: cover schema and catalog metadata, knowledge102 objects, CIM/OCSF, ITSI/business context, RBAC, lineage, audit, human103 approval, and downstream data-readiness evidence.1045. **AI activation and action**: delegate AI Toolkit/PSC/DSDL, hosted-model105 readiness, and MCP Server. Distinguish the available open Cisco Time Series106 Model 1.0 from the GA hosted Cisco Deep Time Series Model integration, keep Agent107 Launchpad at its documented GA boundary with its region, egress, connection,108 and enabled-agent gates, and keep AI Canvas at its CA boundary.1096. **Cross-domain experience**: represent SecOps, ITOps, Engineering/DevOps,110 NetOps, Splunk Enterprise Security, ITSI, Observability Cloud, Cisco Cloud111 Control, AI Canvas, and Cisco product telemetry as consumers or handoffs,112 not as interchangeable Data Fabric components.113114## Safe First Command115116```bash117bash skills/cisco-data-fabric-setup/scripts/setup.sh --help118```119120## Primary Workflow121122Render and validate the complete evidence-backed packet:123124```bash125bash skills/cisco-data-fabric-setup/scripts/setup.sh \126 --render --validate \127 --spec skills/cisco-data-fabric-setup/template.example \128 --output-dir cisco-data-fabric-rendered129```130131Run the gap/readiness doctor:132133```bash134bash skills/cisco-data-fabric-setup/scripts/setup.sh \135 --doctor \136 --spec skills/cisco-data-fabric-setup/template.example \137 --output-dir cisco-data-fabric-rendered138```139140Preview delegated commands without writing or executing:141142```bash143bash skills/cisco-data-fabric-setup/scripts/setup.sh \144 --execute data-management,federation,ai-activation,context-governance \145 --dry-run --json \146 --spec skills/cisco-data-fabric-setup/template.example147```148149Execute only reviewed delegated render/doctor commands:150151```bash152bash skills/cisco-data-fabric-setup/scripts/setup.sh \153 --execute data-management,ai-activation \154 --accept-execute \155 --spec skills/cisco-data-fabric-setup/template.example \156 --output-dir cisco-data-fabric-rendered157```158159## CLI Contract160161`setup.sh` supports `--render`, `--validate`, `--doctor`,162`--execute SECTION[,SECTION]`, `--accept-execute`, `--dry-run`, `--json`,163`--spec PATH`, and `--output-dir DIR`.164165Delegated sections:166167- `data-management`168- `federation`169- `ai-activation`170- `context-governance`171172Handoff-only sections, which refuse explicit execution:173174- `storage-catalog`175- `experience`176177Child commands are render, doctor, or plan operations. Applying their output178requires the child skill's own explicit approval gates. A missing child spec,179tenant URL, MCP URL, entitlement, or public API is reported as a gap rather180than silently converted into a successful apply.181182Non-dry-run delegation fails before any child command when `gap-register.json`183contains an `error`, a selected section is handoff-only, or any selected184executable section has no reviewed command. This prevents partial execution185when a later lane is missing required intake.186187## Non-Negotiable Boundaries188189- Do not claim a direct Cisco Data Fabric management API.190- Do not call Machine Data Lake or its built-in Data Catalog GA; current191 public material identifies Machine Data Lake as alpha.192- Do not collapse store-specific federation stage, region, role, catalog, and193 entitlement requirements into a generic "Federated Search is GA" claim.194- Do not use `activation_required` as a product lifecycle. Record lifecycle in195 `product_stage` and tenant/commercial gates in `access_requirement`.196- Do not create new legacy Amazon S3 federated providers on Splunk Cloud197 10.5; the old provider/index path is deprecated and migrated to the Data198 Management connection/dataset model.199- Do not promote announcement dates to current availability. Cisco Time Series200 Model 1.0 is published as an open Apache-2.0 model and the hosted Cisco Deep201 Time Series Model integration is generally available since AI Toolkit `6.0.0`,202 but they remain separately governed layers and neither one settles the other.203- Do not pair AI Toolkit `6.0.2` with a PSC release below `4.3.4`. The audited204 baseline is `6.0.2` with PSC `4.3.4` on Python `3.13`; PSC `4.3.2` only205 applies back at AI Toolkit `5.7.4`.206- Do not describe Splunk AI Toolkit Agent Launchpad as alpha, private preview,207 or a Fall 2026 GA target. Current AI Toolkit documentation makes it generally208 available since `6.0.0`. Report it as unreachable only when a readiness gate209 actually fails: an unsupported AWS region or a missing region egress IP in210 the stack `apiAllowlistIP`, no supported LLM connection, or no enabled agent.211 Splunk Enterprise reaches it through the Splunk Cloud Connect app rather than212 being unsupported.213- Do not treat Cisco Security Analytics and Logging (SAL) as Splunk Machine214 Data Lake or as an automatically configured federation target.215- For AI Canvas with Splunk, require Cloud Control enablement, Splunk Cloud216 `10.5.2605.3`, current AI Assistant and MCP Server, and217 `mcp_tool_execute`; retain the 100-row-per-card and forbidden-SPL-command218 limitations in the production handoff.219- Never accept raw tokens, passwords, API keys, client secrets, or private220 keys in chat, argv, specs, or rendered artifacts.221222## Validation223224```bash225bash skills/cisco-data-fabric-setup/scripts/validate.sh \226 --output-dir cisco-data-fabric-rendered227228python3 -m py_compile \229 skills/cisco-data-fabric-setup/scripts/render_assets.py230```231232Read `reference.md` for the rendered artifact contract and delegated owner233map.