← all publishers

chambear2809

@chambear2809 source repo

169 published skills · page 1 of 2

  1. Splunk Observability Cisco AI Pod Integration · chambear2809 bundle
    Use when deploying Splunk Observability Cloud for a Cisco AI Pod with UCS, Nexus, NVIDIA GPUs, NIM/vLLM inference, and storage telemetry. Hand off base collector, HEC, dashboards, and detectors to the owning skills. Compose Cisco Nexus, Cisco Intersight, and NVIDIA GPU Observability skills into a Cisco AI Pod overlay, then add NIM, vLLM, Milvus, NetApp Trident, Pure Portworx, Redfish exporter, OpenShift SCC, workshop tenancy, RBAC, receiver naming, DCGM discovery, dual-pipeline filtering, NIM model-name extraction, and existing-collector cleanup patterns.
    0 installs
  2. Splunk Observability Thousandeyes Integration · chambear2809 bundle
    Use when the user asks to wire ThousandEyes telemetry into Splunk Observability Cloud, configure Integrations 2.0 APM trace linking, manage TE tests/alert rules/templates for an O11y integration, or produce the per-test-type O11y dashboards. Render and (optionally) apply a guarded ThousandEyes -> Splunk Observability Cloud integration end-to-end: Integration 1.0 OpenTelemetry metric stream (POST /v7/streams to ingest.<realm>.signalfx.com/v2/datapoint/otlp), Integrations 2.0 Splunk Observability APM connector (generic connector + splunk-observability-apm operation), plus verified create/readback flows for tests, alert rules, and TE Templates. Renders labels, tags, and TE-side dashboards as reviewable handoffs until authoritative API ID/readback schemas are encoded. Covers the canonical TE OpenTelemetry Data Model v2 taxonomy. Generates SignalFlow dashboard specs and starter detectors for hand-off to splunk-observability-dashboard-builder and splunk-observability-native-ops.
    0 installs
  3. Splunk Observability AI Agent Monitoring Setup · chambear2809 bundle
    Use when setting up or auditing Splunk AI Agent Monitoring, GenAI telemetry packages, AI agent evaluation telemetry, or adjacent AI infrastructure observability. Render, validate, diagnose, and safely apply Splunk Observability Cloud AI Agent Monitoring setup plans, including GenAI Python instrumentation, instrumentation-side evaluations, Log Observer Connect handoffs, histogram collector readiness, and AI Infrastructure Monitoring coverage.
    0 installs
  4. Splunk Observability Database Monitoring Setup · chambear2809 bundle
    Use when handling DBMon receiver setup, database query analysis, explain-plan readiness, or database collector lifecycle work, including version-aware MySQL and MariaDB feature gaps. Render, validate, apply, verify, and roll back production Splunk Observability Cloud Database Monitoring configurations for Microsoft SQL Server, MySQL, MariaDB, Oracle Database, and PostgreSQL through the Splunk Distribution of OpenTelemetry Collector. Covers Kubernetes, Linux, and Windows outputs; query samples and top queries; infrastructure metrics; product UI validation; APM query correlation handoffs; and DBMon query AI Assistant readiness.
    0 installs
  5. Splunk Observability Codex Instrumentation Setup · chambear2809 bundle
    Use when instrumenting Codex itself for Splunk Observability or AI Agent Monitoring. Render, validate, diagnose, and safely apply Splunk Observability instrumentation for Codex CLI profiles, OTel destinations, JSONL runtime helpers, and optional hooks.
    0 installs
  6. Splunk Appdynamics Thousandeyes Integration Setup · chambear2809 bundle
    Use when Codex needs to configure AppDynamics ThousandEyes token readiness, Dash Studio ThousandEyes widgets, Browser/Mobile RUM ThousandEyes network metrics, ThousandEyes native AppDynamics integration runbooks for test recommendations and alert notifications, ThousandEyes API-backed tests/labels/tags/alert rules/dashboards/templates, or a custom webhook fallback that posts ThousandEyes alerts into AppDynamics custom events. Render, validate, and safely gate the AppDynamics-ThousandEyes integration across AppDynamics SaaS, On-Premises, and Virtual Appliance.
    0 installs
  7. Splunk Observability Cisco Intersight Integration · chambear2809 bundle
    Use when the user asks to send Cisco Intersight, UCS, HyperFlex, or UCS-X compute metrics to Splunk Observability Cloud, configure the cisco_intersight OTel receiver, or render UCS chassis health dashboards and detectors. This is independent of Cisco AI Pod and complements the Splunk Platform TA skill cisco-intersight-setup. Render and validate Cisco Intersight (UCS management plane) metrics into Splunk Observability Cloud through the Intersight OTel integration. Emits the namespace, Secret stub, Deployment, endpoint ConfigMap, Splunk OTel pipeline overlay, dashboards, detectors, and handoff scripts without reading key material.
    0 installs
  8. Splunk Appdynamics Infrastructure Visibility Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Machine Agent, Server Visibility, Network Visibility, Docker or container visibility, service availability, server tags, host metrics, or infrastructure health rules, NVIDIA GPU monitoring, DCGM, NVIDIA-SMI, or Prometheus exporter monitoring through Machine Agent. Render and validate Splunk AppDynamics Infrastructure Visibility workflows, including Machine Agent, Server Visibility, Network Visibility, Docker and container visibility, service availability, server tags, GPU Monitoring, Prometheus extension coverage, and infrastructure health rules.
    0 installs
  9. Splunk Observability K8S Auto Instrumentation Setup · chambear2809 bundle
    Use when wiring zero-code Java, Node.js, Python, .NET, Go, Apache, or Nginx instrumentation into Splunk Observability Cloud APM, adding AlwaysOn Profiling, discovering workloads, or reverting operator-managed instrumentation. Render, apply, verify, and uninstall Splunk/OpenTelemetry Operator auto-instrumentation overlays for Kubernetes workloads after the base Splunk OTel Collector skill has installed the operator and CRDs. Emits language Instrumentation CRs, workload and namespace annotations, backup ConfigMaps, Splunk OBI eBPF assets, profiling/runtime metric env vars, sampler settings, Fargate gateway paths, GitOps YAML, transactional rollback snapshots, and clean uninstall scripts.
    0 installs
  10. Splunk Appdynamics Machine Agent Otel Collector Setup · chambear2809 bundle
    Use when the user asks for Machine Agent bundled OTel Collector, combined agent for infrastructure visibility, AppDynamics collector YAML, local OTLP 4317/4318 listeners, or Splunk Observability plus AppDynamics OTel export from Linux, Docker, or Windows Machine Agent installs. Render, validate, preflight, apply, and rollback the bundled OpenTelemetry Collector that runs with AppDynamics Machine Agent combined mode.
    0 installs
  11. Splunk Observability Claude Code Instrumentation Setup · chambear2809 bundle
    Use when instrumenting Claude Code to emit metrics, log events, and distributed traces (beta) to Splunk Observability Cloud via a local OTel Collector fan-out, with optional Galileo OTLP trace ingestion for AI observability; covers all three destination modes (local-collector, splunk-direct, external- collector), env-block and settings.json rendering, collector overlay with dual fan-out, otelHeadersHelper for secret-safe direct-mode auth, Galileo project/log-stream handoffs, detailed beta tracing for Galileo Luna span scorers, non-public Galileo tenant support, and content-capture gating. Render, validate, and safely apply Claude Code CLI OpenTelemetry instrumentation to Splunk Observability Cloud and Galileo.
    0 installs
  12. Splunk Observability Coding Agent Instrumentation Setup · chambear2809 bundle
    Use when planning Splunk Observability instrumentation for Codex or future coding agents without applying agent-specific config. Route coding-agent telemetry requests to the right child skill and render a non-mutating orchestration plan.
    0 installs
  13. Splunk Observability GCP Integration · chambear2809 bundle
    Use when the user asks to connect Splunk Observability Cloud to GCP metrics, configure Service Account or official generated WIF credentials, manage the GCP REST integration, or set up GCP dashboards, detectors, logs, or GKE telemetry handoffs. Render, apply, validate, discover, and diagnose the Splunk Observability Cloud GCP integration for Cloud Monitoring metrics. Covers service-account key and Workload Identity Federation auth, poll-rate bounds, metric source quota, service enums, custom metric domains, label exclusions, namedToken warnings, service-account Terraform and gcloud IAM handoffs, multi-project support, credential-hash drift detection, and conflict checks.
    0 installs
  14. Splunk Platform Restart Orchestrator · chambear2809 bundle
    Use when the user asks to restart Splunk, avoid unnecessary restarts, recover from management API restart trouble, review repo-wide restart handling, choose between REST/CLI/systemd/ACS restart paths, or validate that a Splunk app/config change has been activated. Plan, validate, audit, and safely execute Splunk Platform restarts and reloads across Splunk Enterprise, Splunk Cloud, systemd-managed hosts, deployment servers, indexer clusters, and search head clusters.
    0 installs
  15. Splunk Security Content Update Setup · chambear2809 bundle
    Use when the user asks to install, upgrade, review, or validate ESCU or Splunk security content. Render, install, and validate Splunk Enterprise Security Content Update readiness for DA-ESS-ContentUpdate, ES search-head placement, package delivery, Analytic Story Detail navigation, content inventory checks, correlation-search activation review, and ES configuration handoff.
    0 installs
  16. Cisco Catalyst Enhanced Netflow Setup · chambear2809 bundle
    Use when installing or validating Cisco HSL/IPFIX mappings and Enhanced NetFlow dashboards in Splunk.
    0 installs
  17. Splunk Observability Mobile Rum Setup · chambear2809 bundle
    Use when instrumenting mobile apps with Splunk RUM, preparing Mobile Session Replay, preparing mobile- side Digital Experience Analytics (DXA), validating RUM-to-APM linking, or rendering mobile source patches. Do not use for AppDynamics EUM or Kubernetes Browser RUM injection. Render, validate, and optionally apply guarded source patches for Splunk Observability Cloud Mobile RUM and mobile-side Digital Experience Analytics (DXA) prerequisites across native iOS, native Android, React Native, and Flutter apps. Covers pinned agent versions, Session Replay enterprise gating, privacy controls, release attributes, dSYM and Android mapping upload helpers, React Native and Flutter native artifact handoffs, WebView Browser RUM bridge snippets, and RUM-to-APM Server-Timing traceparent validation.
    0 installs
  18. Splunk Observability Metrics Pipeline Setup · chambear2809 bundle
    Use when the user asks about MPM, metrics pipeline management, metric cardinality, MTS reduction, or Observability metric routing and aggregation. Render and validate focused Splunk Observability Cloud Metrics Pipeline Management plans, including metric usage review, cardinality and MTS controls, drop/archive/route/aggregate intent, exception planning, dashboard and detector handoffs, and deep- native-workflow delegated specs.
    0 installs
  19. Splunk Observability Nvidia Gpu Integration · chambear2809 bundle
    Use when the user asks to send NVIDIA GPU, DCGM, DCGM Exporter, GPU Operator, DGX, AI Pod, or CUDA workload telemetry to Splunk Observability Cloud, configure receiver_creator/dcgm-cisco, enable per-pod DCGM labels, or render GPU dashboards and detectors. Render NVIDIA GPU telemetry from DCGM Exporter into Splunk Observability Cloud. Uses receiver_creator/dcgm-cisco to avoid chart autodetect collisions, matches both common DCGM labels, defaults to an unfiltered NVIDIA metrics pipeline, optionally patches DCGM pod labels, and emits dashboard, detector, base-collector, and apply handoffs.
    0 installs
  20. Splunk Appdynamics Database Visibility Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Database Visibility, Database Agent, database collector creation or updates, Database Visibility API payloads, DB credential redaction, DB server validation, DB node validation, or database event checks. Render and validate Splunk AppDynamics Database Visibility workflows, including Database Agent readiness, Database Visibility API collector CRUD, file-backed database secrets, DB server, node, metric, and event validation.
    0 installs
  21. Splunk Observability Cisco Nexus Integration · chambear2809 bundle
    Use when the user asks to send Cisco Nexus, NX-OS, IOS-XE, or IOS-XR device metrics to Splunk Observability Cloud, configure the cisco_os receiver, set up multi-device Nexus telemetry, or render dashboards/detectors for Cisco data center fabric. Standalone reusable skill for sending Cisco Nexus 9000 metrics to Splunk Observability Cloud via the OTel cisco_os receiver (multi-device + global scrapers format, PR #45562, currently at v0.149.0+ in upstream contrib). Renders the clusterReceiver overlay, K8s Secret manifest stub for SSH credentials, dashboards and starter detectors. Hands off base collector to splunk-observability-otel-collector-setup, dashboards to splunk-observability-dashboard- builder, detectors to splunk-observability-native-ops. Independent of Cisco AI Pod -- useful for any data center with Nexus fabric. Companion to cisco-dc-networking-setup (Splunk Platform TA for Nexus / ACI / Nexus Dashboard).
    0 installs
  22. Splunk Observability Cloud Integration Setup · chambear2809 bundle
    Use when a user asks to pair Splunk Platform with Splunk Observability Cloud, set up Unified Identity or Centralized RBAC, configure the Discover app, install the Infrastructure Monitoring Add-on, configure Related Content or Log Observer Connect, bring O11y metrics into Splunk with sim, or navigate from Splunk Platform into Observability workflows. Render, preflight, apply, validate, and diagnose Splunk Platform to Splunk Observability Cloud pairing for Splunk Cloud Platform and Splunk Enterprise. Covers token-auth enablement, realm checks, Unified Identity or service-account pairing, multi-org defaults, Centralized RBAC, Discover Splunk Observability Cloud app configuration, Log Observer Connect, Related Content, Real Time Metrics, Dashboard Studio O11y metrics, and Splunk_TA_sim modular inputs.
    0 installs
  23. Splunk Appdynamics Log Observer Connect Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Log Observer Connect, AppDynamics logs in Splunk Platform, legacy Splunk integration disablement, service-account handoffs, or AppD to Splunk log deep links. Render, validate, and delegate Splunk Log Observer Connect for Splunk AppDynamics workflows, including new LOC setup, old Splunk integration detection and disablement, Splunk Cloud or Enterprise service-account handoffs, allow-list checks, and deep-link validation.
    0 installs
  24. Splunk Appdynamics Synthetic Monitoring Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Synthetic Monitoring, browser synthetic jobs, Synthetic API Monitoring, hosted synthetic locations, Private Synthetic Agent, PSA, Shepherd URL validation, synthetic waterfalls, or synthetic run checks. Render and validate Splunk AppDynamics Synthetic Monitoring workflows, including Browser Synthetic jobs, Synthetic API Monitoring, hosted locations, Private Synthetic Agents, Docker, Kubernetes, Minikube PSA assets, Shepherd URLs, screenshots, waterfalls, and run validation.
    0 installs
  25. Widefield Saviynt Integration Setup · chambear2809 bundle
    Use when the user asks to connect WideField Security to Saviynt, map WideField detections to Saviynt remediation policies, or collect Saviynt evidence while failing closed for unsupported live Saviynt mutation. Render and validate Saviynt Identity Cloud remediation mappings for WideField Security findings, including access revocation, password reset, and micro-certification handoffs.
    0 installs
  26. Cisco Secure Email Web Gateway Setup · chambear2809 bundle
    Use when onboarding Cisco ESA or WSA logs through supported Splunk add-ons and managed ingestion.
    0 installs
  27. Splunk Amazon Kinesis Firehose Setup · chambear2809 bundle
    Use when the user asks to send AWS Firehose data to Splunk. Render and validate Amazon Kinesis Firehose to Splunk HEC onboarding for CloudTrail, VPC Flow Logs, CloudWatch events, and raw or JSON data, including HEC token/index handoffs, delivery stream settings, buffering, retry, S3 backup, IAM policy stubs, CloudWatch delivery metrics, ACK guidance, and strict source/sourcetype readiness evidence.
    0 installs
  28. Splunk Appdynamics Security AI Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Secure Application, application security monitoring, Secure Application policies, Secure Application APIs, Secure Application `policyConfigs`, Secure Application for OTel Java, Observability for AI, OpenAI or LangChain monitoring, Bedrock checks, GPU telemetry, or Cisco AI Pod AppDynamics handoffs. Render, validate, and delegate Splunk AppDynamics security and AI workflows, including Application Security Monitoring, Secure Application, Secure Application runtime policies, Secure Application `policyConfigs`, Secure Application APIs, Secure Application for OpenTelemetry Java, Observability for AI, OpenAI, LangChain, Bedrock, GPU readiness, and Cisco AI Pod handoffs.
    0 installs
  29. Splunk Asset Risk Intelligence Setup · chambear2809 bundle
    Use when a user asks to set up ARI, Splunk Asset and Risk Intelligence, asset/identity risk inventory, or ARI-backed ES Exposure Analytics readiness. Install, prepare, validate, and plan Splunk Asset and Risk Intelligence (`SplunkAssetRiskIntelligence`, Splunkbase app 7180), including ARI indexes, KV Store, roles/capabilities, app readiness, data visibility, Enterprise Security integration, ES 8.5+ Exposure Analytics, ARI Technical Add-ons, ARI Echo, upgrade, and uninstall prerequisite handoffs.
    0 installs
  30. Splunk Observability AWS Integration · chambear2809 bundle
    Use when the user asks to connect AWS to Splunk Observability Cloud, configure CloudWatch Metric Streams, render IAM policies, manage the AWSCloudWatch REST/Terraform object, monitor Bedrock metrics, set up multi-account AWS Organizations onboarding, audit drift, or migrate polling to Metric Streams. Hand off Lambda APM, AWS logs, dashboards, detectors, and EC2/EKS host telemetry to their owning skills. Render, preflight, apply, validate, discover, and diagnose the Splunk Observability Cloud AWSCloudWatch integration across polling, Splunk-managed Metric Streams, AWS-managed Metric Streams, and Terraform paths. Covers IAM trust and policy stubs, External ID and SecurityToken auth, CloudFormation and StackSets assets, Terraform payloads, field conflict checks, recommended stats, namespace sync rules, PrivateLink ingest stubs, drift adoption, and troubleshooting.
    0 installs
  31. Splunk Appdynamics Tags Extensions Setup · chambear2809 bundle
    Use when the user asks for AppDynamics custom tags, tag APIs, extensions, Machine Agent custom metrics, Integration Modules, ServiceNow, Jira, Scalyr, Agent Command Center, or Log Auto-Discovery. Render and validate Splunk AppDynamics tags, extensions, and integration-module workflows, including Custom Tag APIs, tag enablement, Machine Agent custom metrics, Integration Modules, extensions, ServiceNow, Jira, Scalyr, Agent Command Center, and Log Auto-Discovery runbooks.
    0 installs
  32. Splunk Appdynamics Agent Management Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Smart Agent, Agent Management, remote agent installation, deployment groups, managed agent upgrade, rollback, auto-attach, auto-discovery, managed Apache, .NET, Database, Java, Machine, Node.js, PHP, or Python agents, package download automation, checksum validation, signature validation, or release compatibility. Render, validate, and gate Splunk AppDynamics Smart Agent and Agent Management workflows, including prerequisites, platform and permission checks, Smart Agent config, local and remote install, upgrade, uninstall, synchronization, deployment groups, auto-attach, auto-discovery, UI paths, smartagentctl lifecycle commands, deprecated Smart Agent CLI guidance, and supported managed agent types for Apache, .NET MSI, Database, Java, Machine, Node.js, PHP, and Python agents, plus software downloads, checksum validation, digital signatures, and release posture.
    0 installs
  33. Splunk Appdynamics Alerting Content Setup · chambear2809 bundle
    Use when the user asks for AppDynamics health rules, alert policies, actions, schedules, email digests, action suppression, anomaly detection, automated RCA, dynamic baseline behavior, automated transaction diagnostics, alerting content import/export, rollback, or alert validation. Render and validate Splunk AppDynamics alerting content, including health rules, schedules, policies, actions, email digests, action suppression, anomaly detection, automated root cause analysis, import, export, rollback, AIML dynamic baselines, automated transaction diagnostics, and post-apply readback validation.
    0 installs
  34. Splunk Appdynamics Controller Admin Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Controller administration, API clients, OAuth, RBAC, SAML, LDAP, user/group/role management, account permissions, licensing, license rules, sensitive data controls, SQL/log masking, environment variable filtering, or privacy validation. Render and validate Splunk AppDynamics Controller administration workflows, including SaaS and on-prem account checks, API clients, OAuth token-file flow, users, groups, roles, SAML, LDAP, account permissions, licensing, license rules, sensitive data collection controls, privacy settings, audit readiness, and data collection dashboards.
    0 installs
  35. Splunk Observability AWS Lambda Apm Setup · chambear2809 bundle
    Use when the user asks to instrument Lambda functions for APM/tracing, attach the Splunk OTel Lambda layer, wire SPLUNK_ACCESS_TOKEN safely, set up Lambda APM dashboards or detectors, or migrate from Datadog, New Relic, or ADOT to Splunk OTel. Render, validate, and optionally apply Splunk OpenTelemetry Lambda layer APM instrumentation for AWS Lambda functions in Splunk Observability Cloud. Covers Node.js, Python, and Java runtime wiring, safe token delivery through Secrets Manager or SSM SecureString, layer ARN snapshots, Lambda metrics extension opt-in, container-image snippets, SAM/CDK/Terraform/CloudFormation/AWS CLI assets, vendor coexistence checks, X-Ray coexistence, GovCloud/China refusal, rollback, discovery, and doctor reports.
    0 installs
  36. Splunk Observability Otel Collector Setup · chambear2809 bundle
    Use when rendering, preflighting, applying, validating, diagnosing, and removing the Splunk Distribution of OpenTelemetry Collector for Kubernetes and Linux; audit and stage Splunkbase apps 7125, 8698, and 8699 through deployment servers, Linux heavy forwarders, or Linux Universal Forwarders; configure guarded Splunk Platform HEC or Splunk Connect for OTLP destinations; and route specialized Observability products to their owning skills.
    0 installs
  37. Splunk Appdynamics K8S Cluster Agent Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Cluster Agent, Kubernetes monitoring, AppDynamics Kubernetes auto-instrumentation, Splunk OTel Collector through Cluster Agent, O11y export, or workload rollout validation. Render, validate, and gate Splunk AppDynamics Kubernetes Cluster Agent, Kubernetes auto- instrumentation, and Splunk OpenTelemetry Collector setup through the Cluster Agent, including dual- signal combined-agent plans for Java, .NET Core Linux, Node.js, Machine Agent handoff, and Splunk Observability Cloud export validation.
    0 installs
  38. Widefield Okta Integration Setup · chambear2809 bundle
    Use when the user asks to connect WideField Security to Okta, configure Okta event hooks for WideField, validate shared-signal risk events, or build Okta evidence for WideField detect-and-remediate workflows. Render, validate, and safely apply the Okta side of a WideField Security integration, including OIN handoffs, Shared Signals receiver evidence, and documented Okta event hook creation, update, verification, or deactivation.
    0 installs
  39. Cisco Enterprise Networking Setup · chambear2809 bundle
    Use when the user asks about Cisco Enterprise Networking app, cisco-catalyst-app, Catalyst dashboards, ISE dashboards, SD-WAN dashboards, or Cyber Vision dashboards. Automate Cisco Enterprise Networking for Splunk Platform (cisco-catalyst-app) setup. Configures index macros, sourcetype macros, saved searches, data model acceleration, and validates dashboards.
    0 installs
  40. Galileo On Prem Luna Studio Setup · chambear2809 bundle
    Render, preflight, validate, observe, and prepare Galileo/CSE joint-session install, upgrade, rollback, and retirement handoffs for Galileo Luna Studio on Kubernetes with dedicated PostgreSQL, object storage, backend and UI, routing, four out-of-band Secrets, GPU Jobs, Vertex AI, and remote or hybrid training. Use when operating Luna Studio for Galileo On-Prem or when an exact umbrella package requires a reviewed Luna overlay instead of its standalone release.
    0 installs
  41. Splunk Appdynamics Platform Setup · chambear2809 bundle
    Use when the user asks for AppDynamics On-Premises, Virtual Appliance, Enterprise Console, Controller host setup, Events Service, EUM Server, Synthetic Server, HA, upgrade, or secure platform runbooks. Render, validate, and gate Splunk AppDynamics On-Premises and Virtual Appliance platform workflows, including Enterprise Console, Controller, Events Service, EUM Server, Synthetic Server, planning, platform quickstart, release notes, compatibility, HA, backup, restore, upgrades, and secure platform hardening.
    0 installs
  42. Splunk Enterprise Security Config · chambear2809 bundle
    Use when the user asks to configure, tune, validate, or operationalize Splunk Enterprise Security. Configure and validate Splunk Enterprise Security (ES) after installation, including ES indexes, Splunk_TA_ForIndexers readiness, users and roles, managed custom roles, CIM data models, data model acceleration, assets and identities, threat intelligence, detections, risk-based alerting, Mission Control, exposure analytics, UEBA, native SOAR integrations, ES AI Assistant settings, Federated Analytics inventory/handoffs, and configuration health checks.
    0 installs
  43. Splunk Appdynamics Analytics Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Analytics, ADQL, Analytics Events API, custom event publishing, analytics schemas, transaction analytics, log analytics, browser or mobile analytics, synthetic analytics, IoT analytics, connected device analytics, Business Journeys, XLM, SLA, or experience-level reporting. Render, validate, and gate Splunk AppDynamics Analytics workflows for Transaction Analytics, Log Analytics, Browser Analytics, Mobile Analytics, Synthetic Analytics, IoT Analytics, Connected Devices Analytics, Business Journeys, Experience Level Management (XLM), ADQL, Analytics Events API schemas, event publishing, and query validation.
    0 installs
  44. Splunk Appdynamics Sap Agent Setup · chambear2809 bundle
    Use when the user asks for AppDynamics SAP Agent, ABAP Agent, HTTP SDK, SNP CrystalBridge Monitoring, BiQ Collector, SAP NetWeaver transports, SAP authorization runbooks, local or gateway HTTP SDK deployment, or SAP release or metric validation. Render, validate, and hand off Splunk AppDynamics SAP Agent workflows, including SAP Agent, ABAP Agent, HTTP SDK, SNP CrystalBridge Monitoring, BiQ Collector, local and gateway HTTP SDK deployment, SAP NetWeaver transports, SAP authorization checks, Controller node registration, SAP Agent release notes, and SAP metric validation.
    0 installs
  45. Splunk Enterprise Kubernetes Setup · chambear2809 bundle
    Use when planning, installing, upgrading, or validating either runtime. Render, preflight, apply, and validate Splunk Enterprise on Kubernetes with Splunk Operator for Kubernetes 3.1.0 or Splunk POD 10.4.0_1.6.0 on Cisco UCS. Covers SOK S1/C3/M4, guarded C3 indexing and ingestion separation, reviewed Helm overlays, and POD Small through X-Large with ES, ITSI, and TLS variants.
    0 installs
  46. Splunk Observability Deep Native Workflows · chambear2809 bundle
    Use when the user asks for full native UI/product workflow coverage beyond collection, classic dashboards, or basic detector setup, including emerging Cisco/Splunk Observability routes such as Digital Experience Analytics, DXA, Metrics Pipeline Management, MPM, or telemetry pipeline management. Render and validate Digital Experience Analytics (DXA), Metrics Pipeline Management (MPM), and deep native Splunk Observability Cloud operator workflows for modern dashboards, APM service maps, service views, business transactions, Trace Analyzer and trace waterfalls, AlwaysOn Profiling flame graphs, RUM session replay for browser and mobile, RUM error analysis, RUM URL grouping, Database Monitoring query and explain-plan triage, Synthetic waterfall details and artifacts, SLO creation and burn-rate alerting, Infrastructure/Kubernetes/Network Explorer navigators, Related Content, AI Assistant investigations, and Splunk Observability Cloud for Mobile app workflows.
    0 installs
  47. Splunk Observability Isovalent Integration · chambear2809 bundle
    Use when wiring Cilium, Tetragon, or Hubble metrics into Splunk Observability Cloud, shipping Tetragon logs to Splunk Platform, or validating Isovalent telemetry after platform install. Wire an installed Isovalent stack (Cilium, Hubble, Tetragon, optional Hubble Enterprise or cilium-dnsproxy) to Splunk Observability Cloud and Splunk Platform. Renders Splunk OTel Collector scrape overlays, metric filters, Tetragon filelog ingestion defaults, stdout and legacy fluentd alternatives, dashboards, detectors, and handoff scripts for base collector, HEC, and Cisco Security Cloud ingestion.
    0 installs
  48. Splunk Appdynamics Dashboards Reports Setup · chambear2809 bundle
    Use when the user asks for AppDynamics dashboards, custom dashboard migration, Dash Studio handoffs, reports, scheduled reports, report delivery, War Rooms, or dashboard and report validation. Render and validate Splunk AppDynamics dashboard and report workflows, including custom dashboards, Dash Studio handoffs, reports, scheduled reports, War Rooms, ThousandEyes dashboard handoff, dashboard inventory, report delivery checks, and validation runbooks.
    0 installs
  49. Splunk Enterprise Public Exposure Hardening · chambear2809 bundle
    Use when the user asks to expose Splunk Enterprise on the public internet, harden a Splunk search head against internet exposure, configure TLS / HSTS / CSP / mTLS / per-IP rate limit / DMZ heavy forwarder, lock down splunkd or the KV store, fix splunk.secret / pass4SymmKey defaults, evaluate against the latest SVD floor (10.4.0 / 10.2.2 / 10.0.5 / 9.4.10 / 9.3.11), or render nginx / HAProxy / WAF reference configs in front of Splunk. Render, preflight, apply, and validate hardening of an on-prem Splunk Enterprise deployment for public-internet exposure across all four edge surfaces (Splunk Web on 8000, HEC on 8088, Splunk-to-Splunk on 9997, splunkd REST on 8089) plus reference reverse-proxy / WAF / firewall templates and a structured operator handoff.
    0 installs
  50. Splunk Observability K8S Frontend Rum Setup · chambear2809 bundle
    Use when wiring a React, Vue, Angular, Next.js, Nuxt, Remix, nginx/httpd, SPA, or MPA frontend to Splunk Browser RUM, enabling Session Replay, configuring Frustration Signals, preparing browser-side Digital Experience Analytics (DXA), uploading source maps, validating trace linking, or uninstalling RUM. Do not use for AppDynamics BRUM. Render, apply, verify, and uninstall Splunk Browser RUM and browser-side Digital Experience Analytics (DXA) prerequisites plus optional Session Replay injection for Kubernetes- served frontends. Supports nginx sub_filter, ingress-nginx snippets, initContainer HTML rewrites, runtime config, backup and revert manifests, SplunkRum.init options, Frustration Signals, source-map upload helpers, RUM-to-APM Server-Timing validation, multi-workload specs, distroless detection, version pinning, SRI hashes, IE11 opt-in, and dashboard, detector, SIM, and backend auto-instrumentation handoffs.
    0 installs
  51. Splunk Enterprise Security Install · chambear2809 bundle
    Use when the user asks to install, upgrade, bootstrap, post-install, or validate Splunk Enterprise Security. Install, post-install, and validate Splunk Enterprise Security (ES), including SplunkEnterpriseSecuritySuite, essinstall, standalone search-head and SHC deployer workflows, required ES framework apps, local splunk-ta packages, and Splunkbase app 263 fallback.
    0 installs
  52. Splunk Microsoft Exchange Ta Setup · chambear2809 bundle
    Use when the user asks for Splunk Supported Add-on for Microsoft Exchange onboarding and validation. Render, install, and validate the package-verified Microsoft Exchange supported add-on bundle and Exchange Indexes package. Covers TA-Exchange-ClientAccess, TA-Exchange-Mailbox, TA-SMTP-Reputation, TA- Windows-Exchange-IIS, SA-ExchangeIndex, package-derived source types, Windows collection placement, msexchange/perfmon/windows/wineventlog/msad index readiness, and readiness-doctor handoffs.
    0 installs
  53. Splunk Microsoft Security Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate Microsoft Security / Defender data in Splunk. Install, render, configure, and validate the Splunk Add-on for Microsoft Security (Splunk_TA_MS_Security, Splunkbase 6207). Renders package-backed Defender incidents, endpoint alerts, machines, simulations, Event Hub / Advanced Hunting, and Threat Intelligence inputs; emits Entra app account runbooks, Splunk Cloud UI-only and Event Hub egress caveats, macros for package dashboards/searches, migration notes, and validation SPL. Use for Microsoft 365 Defender, Defender for Endpoint, Microsoft Security, or Splunk_TA_MS_Security onboarding.
    0 installs
  54. Splunk Security Appliance Ta Setup · chambear2809 bundle
    Use when the user asks for Carbon Black or Symantec EP supported add-on onboarding when package extraction has verified coverage. Render, install, and validate first-pass package-verified security appliance supported add-ons for Carbon Black and Symantec Endpoint Protection. Covers Splunk_TA_bit9-carbonblack and Splunk_TA_symantec-ep app IDs, versions, package-derived source types, file/syslog transport ownership, eventtypes, lookups, and readiness-doctor handoffs.
    0 installs
  55. Cisco Meraki Aam Thousandeyes Setup · chambear2809 bundle
    Use when the user asks to link Meraki Dashboard to ThousandEyes, deploy ThousandEyes Enterprise Agents on supported Meraki MX networks, claim or use Meraki AAM free tests, create ThousandEyes tests from Meraki Insight / Active Application Monitoring, monitor an application from agents inside Meraki networks, inspect or summarize Meraki Dashboard HAR/POST requests for the AAM wizard, or validate the resulting ThousandEyes agents, tests, and results. Render, capture, validate, and safely operate Cisco Meraki Active Application Monitoring with ThousandEyes.
    0 installs
  56. Galileo On Prem Agent Control Setup · chambear2809 bundle
    Render, validate, preflight, observe, and prepare Galileo/CSE joint-session install, upgrade, rollback, and retirement handoffs for the packaged Galileo Agent Control Kubernetes lifecycle, including database policy, migrations, routing, UI proxy wiring, feature flags, resilience, and immutable chart or umbrella-overlay evidence. Use when deploying or upgrading Agent Control as part of Galileo On-Prem; use galileo-agent-control-setup instead for runtime controls and Splunk sinks.
    0 installs
  57. Splunk Appdynamics Dual Agent Setup · chambear2809 bundle
    Use when the user asks for AppDynamics Java dual-agent, Java Dual Signal mode, AGENT_DEPLOYMENT_MODE=dual, -Dagent.deployment.mode=dual, Java OTLP export to a local collector, or coordinated collector-first then Java restart rollout on local or SSH hosts. Render, validate, preflight, apply, and rollback production Java Dual Signal AppDynamics agent configuration.
    0 installs
  58. Splunk Data Source Readiness Doctor · chambear2809 bundle
    Use when the user asks for data-source readiness, ES/ITSI/ARI readiness scoring, CIM or OCSF validation, data-model acceleration checks, dashboard population checks, ingest pipeline health, knowledge-object enrichment, federated data usability, ITSI summary health, or fix handoffs after app/input setup. Diagnose whether onboarded Splunk data sources are usable by Enterprise Security, ITSI, Asset and Risk Intelligence, CIM, OCSF, and dashboards.
    0 installs
  59. Splunk Dashboard Studio Setup · chambear2809 bundle
    Use when the user asks to create a Splunk Dashboard Studio dashboard, build a platform dashboard as code, push a dashboard JSON to data/ui/views, or replicate a dashboard between Splunk environments. Not for Splunk Observability Cloud dashboards, which use splunk-observability-dashboard-builder. Render, validate, and apply Splunk Platform Dashboard Studio dashboards: build a version 2 JSON definition (dataSources, visualizations, inputs, layout, defaults), wrap it in the data/ui/views eai:data XML, and create or update the view via REST with ACL governance.
    0 installs
  60. Splunk Federated Search Setup · chambear2809 bundle
    Use when configuring Cisco Data Fabric federated search or standalone Splunk Federated Search, cross- domain search, federated analytics, S3 data-lake search, or querying data where it resides. Render, preflight, apply, and validate FSS2S standard/transparent providers and reviewed legacy FSS3 payloads; render 10.5 migration guidance and current Data Management handoffs for S3, Azure, Databricks, Snowflake, and DDSS; distinguish Glue, Iceberg REST, and Splunk-native catalogs; preserve handoff-only Amazon Security Lake (`aws_lake`) and Cisco SAL (`aws_s3_sal`) identities; and manage supported global- switch, status, file, SHC, and REST workflows.
    0 installs
  61. Splunk Ingest Processor Setup · chambear2809 bundle
    Use when the user asks to configure Ingest Processor, author Ingest Processor pipelines, route or transform data at ingest time, validate Ingest Processor readiness, or compare Ingest Processor with Edge Processor and Data Manager, including Cisco Data Fabric or telemetry pipeline management requests that involve Splunk Cloud ingest-time routing and transformation. Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and monitoring searches, metrics, OCSF, decrypt, S3 archive, custom pipeline templates, AI-powered data management readiness, Automated Field Extraction, Guided Onboarding with Auto-Schematization, and downstream readiness checks.
    0 installs
  62. Splunk Supported Addons Setup · chambear2809 bundle
    Use when the user asks for Splunk-supported add-on coverage, supported-addons gap analysis, Unix or Linux add-on setup, database add-ons, Microsoft Exchange, Microsoft SCOM, NetApp ONTAP, Carbon Black, Symantec Endpoint Protection, Splunk_TA_nix, Splunk_TA_Linux, Linux CollectD, auditd, *nix scripted inputs, or router guidance before using splunk-app-install. Resolve Splunk Supported Add-ons to the correct install, configuration, forwarder, ingest, and post-ingest readiness workflow.
    0 installs
  63. Splunk Observability Synthetics Setup · chambear2809 bundle
    Use when the user asks to create, configure, validate, or operate Splunk Synthetic Monitoring tests without loading the broader native-ops workflow first. Render and validate focused Splunk Observability Cloud Synthetic Monitoring setup plans, including browser, API, HTTP/uptime, SSL, and port tests, locations, frequency, run-now and waterfall artifact handoffs, native-ops delegated specs, and dashboard/detector follow-ups.
    0 installs
  64. Galileo Lemonade Instrumentation Setup · chambear2809 bundle
    Use when adding Galileo OTLP fan-out to a Lemonade collector, capturing agent/workflow/tool traces around Lemonade, avoiding duplicate LLM records, or validating privacy-safe Galileo ingestion from an AMD Ryzen AI host. Instrument Lemonade Server inference and OpenAI-compatible calling applications for Galileo Observe while preserving Splunk OpenTelemetry delivery, privacy policy, rollback, and end-to-end readback.
    0 installs
  65. Splunk Observability Azure Integration · chambear2809 bundle
    Use when the user asks to connect Splunk Observability Cloud to Azure Monitor, configure the Azure integration, manage service-principal credential files, onboard multiple subscriptions, or set up Azure dashboards, detectors, logs, AKS telemetry, Log Observer Connect, or HEC-token handoffs. Render, apply, validate, discover, and diagnose the Splunk Observability Cloud Azure integration for Azure Monitor metrics. Covers REST payloads, Terraform, Azure CLI service-principal creation, Bicep role assignments, subscriptions, service selection, custom namespaces, resource filters, credential-hash drift detection, poll-rate and namedToken checks, and Azure Government guards.
    0 installs
  66. Splunk Observability Browser Rum Setup · chambear2809 bundle
    Use when the user asks for Splunk Browser RUM, JavaScript RUM, @splunk/otel-web, source maps, frontend Session Replay, DXA prerequisites, or non-Kubernetes browser instrumentation. Render, validate, apply, and hand off generic Splunk Observability Cloud Browser RUM and Session Replay setup for web applications outside the Kubernetes injection path, including CDN snippets, npm/TypeScript initialization, Next.js/Vite/ Webpack source-map upload helpers, CSP headers, Session Replay privacy controls, RUM-to-APM Server-Timing trace linking validation, and dashboard or detector handoffs.
    0 installs
  67. Splunk Observability Dashboard Builder · chambear2809 bundle
    Use when creating, planning, rendering, validating, or applying Splunk Observability Cloud dashboards from natural-language dashboard requests, JSON or YAML dashboard specs, SignalFlow chart definitions, or Observability dashboard-as-code workflows. Supports native classic Observability dashboard/chart APIs with render-first safety; treats modern dashboard sections, logs charts, service maps, and Dashboard Studio as advisory/secondary paths unless a verified API is available.
    0 installs
  68. Splunk Index Lifecycle Smartstore Setup · chambear2809 bundle
    Use when the user asks to inventory index age/size/retention, decide whether indexes are unused, change searchable retention, configure SmartStore remote volumes, enable Cloud archive handoffs, restore/thaw archived data, disable indexes, delete indexes, clean standalone index data, configure S3/GCS/Azure object storage for indexes, set indexes.conf lifecycle settings, maxTotalDataSizeMB, maxGlobalDataSizeMB, maxGlobalRawDataSizeMB, frozenTimePeriodInSecs, cache manager settings, limits.conf remote-storage localization settings, cluster-manager bundle deployment, or standalone indexer lifecycle assets. Render, preflight, apply, and validate Splunk index lifecycle and SmartStore workflows.
    0 installs
  69. Cisco Catalyst Ta Setup · chambear2809 bundle
    Use when configuring or validating Catalyst Center, ISE, Catalyst SD-WAN API or syslog collection, Cyber Vision, or the beta IOS-XE CLI collector with TA_cisco_catalyst.
    0 installs
  70. Cisco Data Fabric Setup · chambear2809 bundle
    Use when users need Cisco Data Fabric architecture, feature or product coverage, readiness assessments, gap analysis, machine-data activation, federation targets, storage tiering, AI-ready data, or AgenticOps data foundation requests. Distinguish this architecture from a single product, package, entitlement, or direct API. Research, map, render, doctor, validate, and safely delegate complete Cisco Data Fabric adoption plans across Splunk data management, Edge Processor, Ingest Processor, SPL2, Federated Search, Machine Data Lake, Data Catalog, Splunk indexes and external stores, AI Toolkit and hosted models, Agent Builder, MCP Server, AI Canvas, context, governance, and cross-domain consumers.
    0 installs
  71. Splunk DB Connect Setup · chambear2809 bundle
    Use when the user asks to install or plan DB Connect, configure DBX Java and JDBC drivers, prepare identities, connections, inputs, outputs, lookups, SQL Explorer, dbxquery, dbxoutput, dbxlookup, DB Connect over Federated Search, or validate DB Connect topology. Render, preflight, validate, and hand off production-safe Splunk DB Connect JDBC ingestion, lookup, enrichment, and export assets for Splunk Platform.
    0 installs
  72. Splunk MCP Server Setup · chambear2809 bundle
    Use when the user asks about Splunk MCP server setup, Splunk MCP TA, Splunk_MCP_Server, /services/mcp, the hosted SCS MCP Gateway for Splunk Observability Cloud, Cursor MCP, Codex MCP, Claude Code MCP connectivity to Splunk, or Cisco Data Fabric agentic/tool access through Splunk MCP. Install, configure, validate, and uninstall the Splunk MCP Server app for Cisco Data Fabric agentic/tool access (Splunk_MCP_Server / "Splunk MCP TA"). Configures mcp.conf server settings, rate limits, encrypted token issuance, and renders a shared client bridge bundle that works with Cursor, Codex, and Claude Code.
    0 installs
  73. Splunk Windows Ta Setup · chambear2809 bundle
    Use when the user asks about Splunk_TA_windows, the Splunk Add-on for Microsoft Windows, WinEventLog or Perfmon inputs, Windows Security event onboarding, Sysmon, or Windows CIM readiness in Splunk. Install, render, configure, and validate the Splunk Add-on for Microsoft Windows (Splunk_TA_windows, Splunkbase 742). Renders reviewable inputs.local.conf overlays for WinEventLog (Security/System/Application, Defender, PowerShell), Perfmon, and WinHostMon inputs, creates the wineventlog and perfmon indexes, enforces UF/HF/search-tier placement, and maps source types to CIM data models.
    0 installs
  74. Cisco Thousandeyes Setup · chambear2809 bundle
    Use when configuring ThousandEyes OAuth, HEC, streaming or polling inputs, dashboards, or ITSI in Splunk.
    0 installs
  75. Splunk Indexer Cluster Setup · chambear2809 bundle
    Use when the user asks to bootstrap an indexer cluster, configure site_replication_factor or site_search_factor, apply or roll back a cluster bundle, perform searchable rolling restarts, take a peer offline, migrate single-site to multisite, decommission a site, or set up cluster manager redundancy. Render, preflight, apply, validate, and operate Splunk Enterprise indexer clusters: single- site and multisite bootstrap, cluster manager redundancy, bundle validate/apply/rollback, rolling restart modes, peer offline/removal, maintenance mode, site migration, non-clustered indexer migration, and indexer-discovery output snippets.
    0 installs
  76. Splunk License Manager Setup · chambear2809 bundle
    Use when the user asks about configuring a Splunk Enterprise license manager, license master, license peer, License-Master-URI, license slave, license pool, license group, or license usage reporting. Render, preflight, apply, validate, and audit a Splunk Enterprise license manager and its license peers, including license install, license group activation (Enterprise, Forwarder, Free, Trial), license stacks, license pools (with byte or MAX quota and per-peer slave lists), license peer configuration via splunk edit licenser-localpeer, license messages and violations, and license usage reporting.
    0 installs
  77. Splunk Microsoft Cloud Setup · chambear2809 bundle
    Use when the user asks about Splunk_TA_o365, Office 365, Microsoft 365, Entra ID, Azure AD audit/sign- in, Microsoft Graph, Splunk Add-on for Microsoft Cloud Services, or Microsoft cloud log onboarding in Splunk. Install, render, configure, and validate the Splunk add-ons for Microsoft cloud telemetry: the Splunk Add-on for Microsoft Office 365 (splunk_ta_o365, Splunkbase 4055) and the Splunk Add-on for Microsoft Cloud Services (Splunk_TA_microsoft-cloudservices, Splunkbase 3110). Renders real inputs.conf stanzas for Office 365 Management Activity (Entra/Azure AD, Exchange, SharePoint, General, DLP), Microsoft Graph Entra ID metadata, and Azure audit, emits an Entra app-registration account runbook, creates the o365 and azure indexes, maps source types to CIM, and validates ingestion.
    0 installs
  78. Splunk Netapp Ontap Ta Setup · chambear2809 bundle
    Use when the user asks to onboard or validate NetApp Data ONTAP, ONTAP extractions, or ONTAP indexes in Splunk. Render, install, and validate package-verified NetApp ONTAP supported add-ons: Splunk_TA_ontap, TA-ONTAP-FieldExtractions, and SA-ONTAPIndex. Covers scheduler/worker placement, ontap index creation, ontap:* and Hydra source type validation, troubleshooting checks, and ITSI storage handoffs.
    0 installs
  79. Galileo On Prem Air Gap Setup · chambear2809 bundle
    Build and verify a digest-bound Galileo On-Prem air-gap supply-chain bundle covering Helm charts, galileoctl, every ordinary/init/hook/job/test image, OCI archives, model bundles, architectures, private-registry mappings, scanning evidence, and no-egress endpoints, while surfacing explicit model/runtime and endpoint-rewrite evidence gates. Use when preparing, transferring, mirroring, upgrading, or auditing Galileo for an offline Kubernetes cluster.
    0 installs
  80. Splunk Agent Management Setup · chambear2809 bundle
    Use when the user asks to manage universal forwarder or heavy forwarder fleets, create serverclass.conf, configure deploymentclient.conf, or prepare Splunk 10.x Agent Management / legacy Deployment Server workflows. Render, preflight, apply, and validate Splunk Enterprise agent management assets for deployment-server style server classes, deployment apps, and deployment clients.
    0 installs
  81. Splunk Connect For Otlp Setup · chambear2809 bundle
    Use when the user asks to deploy the OTLP modular input, expose OTLP gRPC/HTTP listeners, configure OTel SDK or Collector senders to Splunk Platform, verify HEC token/index routing, or troubleshoot Splunk Connect for OTLP. Install, administer, validate, diagnose, repair, and render sender handoffs for Splunk Connect for OTLP (`splunk-connect-for-otlp`, Splunkbase app 8704).
    0 installs
  82. Splunk Connect For Snmp Setup · chambear2809 bundle
    Use when the user asks about SC4SNMP, Splunk Connect for SNMP, SNMP polling, or SNMP trap ingestion through HEC. Deploy and validate Splunk Connect for SNMP (SC4SNMP) for Splunk Enterprise or Splunk Cloud. Prepares Splunk indexes and HEC, renders Docker Compose or Kubernetes Helm configuration, and validates SC4SNMP polling or trap readiness.
    0 installs
  83. Splunk Google Workspace Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate Google Workspace data in Splunk. Install, render, configure, and validate the Splunk Add-on for Google Workspace (Splunk_TA_Google_Workspace, Splunkbase 5556). Renders package-backed activity_report, gws_gmail_logs, gws_gmail_logs_migrated, gws_user_identity, gws_alert_center, and gws_usage_report inputs; emits a service-account certificate runbook, proxy/logging settings, the google_workspace readiness handoff, and validation SPL. Use for Google Workspace, G Suite, Gmail logs, Google Admin reports, Workspace Alert Center, or Splunk_TA_Google_Workspace onboarding.
    0 installs
  84. Splunk Lookup File Editing Setup · chambear2809 bundle
    Use when the user asks to install, configure, operate, or validate Lookup File Editing. Render and validate Splunk App for Lookup File Editing readiness, including install planning, CSV and KV Store lookup inventory checks, SHC allowRestReplay backup-replication runbook, app health checks, lookup ownership guidance, and handoffs to knowledge-object and KV Store skills.
    0 installs
  85. Splunk Search Head Cluster Setup · chambear2809 bundle
    Use when the user asks to bootstrap an SHC, push a deployer bundle, perform a searchable rolling restart, transfer the captain, add or remove a member, troubleshoot KV Store replication lag, migrate a standalone search head to SHC, or replace a deployer. Render, preflight, apply, validate, and operate Splunk Enterprise Search Head Clusters end-to-end: bootstrap (deployer + N-member init + captain election), deployer bundle push (validate / status / apply / apply-skip-validation / rollback with SHA and generation-drift tracking), rolling restart (default, searchable with health-check loop, forced), captain transfer, member add / decommission / remove, KV Store replication health (lag thresholds, oplog reset, captain re-election), standalone-to-SHC migration, deployer replacement, ES-on-SHC deployer placement, and failure-mode runbooks (split-brain, quorum loss, deployer mismatch, captain crash loop). SHC pass4SymmKey is templated as `$SHC_SECRET` for operator-managed rotation (see Out of Scope).
    0 installs
  86. Splunk Security Essentials Setup · chambear2809 bundle
    Use when a user asks to set up SSE, Security Essentials, MITRE/Kill Chain content exploration, Security Content recommendations, or starter security posture dashboards. Install, configure readiness, and validate Splunk Security Essentials (`Splunk_Security_Essentials`, Splunkbase app 3435) on Splunk Cloud or Splunk Enterprise.
    0 installs
  87. Splunk Syslog Web Proxy Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate these web, proxy, DNS/DHCP, ADC, or appliance logs in Splunk. Shared render, install, and validation workflow for Splunk Supported Add-on parser and web/proxy profiles: Apache, NGINX, IIS, Tomcat, HAProxy, Squid, Blue Coat ProxySG, Forcepoint Web Security, Check Point Log Exporter, F5 BIG-IP, Citrix NetScaler, and Infoblox. Renders product- specific local file/UF, Windows UF, or SC4S/syslog transport handoffs with package-backed source types.
    0 installs
  88. Splunk Universal Forwarder Setup · chambear2809 bundle
    Use when the user asks to install, upgrade, enroll, or check Universal Forwarders separately from full Splunk Enterprise host bootstrap or Agent Management server-class work. Bootstrap Splunk Universal Forwarder runtimes on Linux, macOS, and Windows, resolve official UF downloads, render first-class enrollment assets for deployment servers, static Enterprise indexers, or Splunk Cloud credentials packages, and validate installed forwarders.
    0 installs
  89. Splunk Workload Management Setup · chambear2809 bundle
    Use when the user asks to reserve search or ingest resources, configure workload_pools.conf, workload_rules.conf, workload_policy.conf, cgroups prerequisites, long-running search guardrails, or admission control for expensive searches. Render, preflight, apply, and validate Splunk Enterprise Workload Management pools, workload rules, and admission rules.
    0 installs
  90. Widefield Identity Threat Doctor · chambear2809 bundle
    Use when the user asks to investigate WideField findings, audit identity threat coverage, build remediation packets, or validate OAuth/NHI/AI-agent identity risks without destructive remediation. Diagnose WideField identity threat coverage for OAuth token abuse, rogue or over-privileged apps, non- human identity ownership, MFA and credential posture, AI-agent identities, and anomalous sessions using read-only Splunk, Okta, and evidence checks.
    0 installs
  91. Splunk Cim Data Model Setup · chambear2809 bundle
    Use when the user asks to accelerate a CIM data model, constrain CIM data model indexes, map data to CIM with tags and eventtypes, fix CIM compliance, or manage datamodels.conf for CIM or custom data models. Not for Enterprise Security-specific acceleration, which lives in splunk-enterprise-security-config. Render, validate, and apply Splunk Common Information Model (CIM) data model governance: install handoff for the CIM add-on (Splunk_SA_CIM), data model acceleration settings, allowed-index constraint macros (cim_<model>_indexes), and CIM eventtype/tag mapping to make sourcetypes CIM-compliant, with tstats validation.
    0 installs
  92. Splunk Edge Processor Setup · chambear2809 bundle
    Use when installing Edge Processor, managing EP pipelines, routing forwarders, or handling Cisco Data Fabric / telemetry pipeline management requests that need Splunk Platform edge routing and transformation. Render Cisco Data Fabric edge-routing workflows and the full Splunk Edge Processor lifecycle for Splunk Cloud Platform tenants and Splunk Enterprise 10.0+ data management control planes. Covers EP objects, TLS / mTLS, Linux or Docker instances, multi-instance scale-out, source types, destinations, SPL2 pipelines with splunk-spl2-pipeline-kit linting, apply handoffs, default destination guardrails, ACS allowlist stubs, and AI-powered data management readiness handoffs.
    0 installs
  93. Splunk Ingest Actions Setup · chambear2809 bundle
    Use when the user asks to set up Ingest Actions, evaluate or mask data at ingest, drop noisy events before indexing, or stage an RFS S3 destination for a route handoff. Not for Ingest Processor or Edge Processor pipelines. Render, validate, and apply eval, mask, and drop rules as props.conf RULESET and transforms.conf INGEST_EVAL through target-app REST endpoints on Splunk Enterprise or a customer-managed heavy forwarder. For route-s3, apply stages only outputs.conf [rfs:] and exits 2 with an explicit Splunk Web or supported rulesets-API handoff for the route rule. Splunk Cloud is render/handoff-only.
    0 installs
  94. Splunk Pci Compliance Setup · chambear2809 bundle
    Use when the user asks to install, configure, prepare, or validate PCI Compliance for Splunk. Render, install, and validate Splunk App for PCI Compliance readiness, including package delivery, cardholder data environment index and macro intake, Enterprise Security or standalone installer selection, CIM/data-model prerequisites, roles, reports, dashboard evidence, and dependency handoffs.
    0 installs
  95. Splunk Rsa Securid Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate RSA SecurID data in Splunk. Umbrella render, install, and validation workflow for RSA SecurID Splunk add-ons: RSA SecurID Authentication Manager syslog parsing (Splunk_TA_rsa-securid, Splunkbase 2958) and RSA SecurID Cloud Authentication Service API collection (Splunk_TA_rsa_securid_cas, Splunkbase 5210). Renders CAS inputs, AM syslog handoffs, encrypted account setup, metadata, and validation SPL.
    0 installs
  96. Splunk Secure Gateway Setup · chambear2809 bundle
    Use when the user asks about Splunk Secure Gateway, Connected Experiences, Spacebridge, Private Spacebridge, or mobile distribution. Apply only splunk_secure_gateway app enable/disable on an explicit Splunk Enterprise target. Render an Enterprise egress check, endpoint and instance-ID placeholder skeletons, and Splunk Web/MDM/device-registration operator runbooks; configure has no live API. Splunk Cloud permits plain render/support handoff only, with no local probe, session authentication, or live REST.
    0 installs
  97. Splunk Stream Windows Setup · chambear2809 bundle
    Use when the user asks to investigate, install, upgrade, configure, validate, troubleshoot, or roll back Splunk Stream Forwarder on a Windows host. Provides action-capable local PowerShell, Windows OpenSSH, WinRM, and AWS Systems Manager paths; enforces a drift-bound investigation and plan before installing the Windows x64 Splunk_TA_stream payload and bundled Npcap driver.
    0 installs
  98. Widefield Google Secops Setup · chambear2809 bundle
    Use when the user asks to ingest WideField Security into Google Security Operations, verify the WideField default parser, prepare feed handoffs, or collect parser evidence while failing closed for undocumented Google SecOps live feed mutation. Render and validate Google SecOps ingestion, webhook/feed, parser, and evidence assets for WideField Security log type WIDEFIELD_SECURITY.
    0 installs
  99. Cisco Isovalent Platform Setup · chambear2809 bundle
    Use when installing or validating Cilium, Tetragon, Hubble, or Isovalent platform workflows on Kubernetes. Install and operate Cisco Isovalent on Kubernetes: Cilium, Tetragon, Enterprise add-ons, and gated private Isovalent product packs. Renders OSS or Enterprise Helm assets, distribution and CNI- conflict preflights, feature coverage, apply plans, doctor reports, live validation, and day-2 discover/backup/upgrade/rollback/uninstall runbooks. NOT a Splunk TA skill; Splunk telemetry wiring is delegated to splunk-observability-isovalent-integration.
    0 installs
  100. Cisco Talos Intelligence Setup · chambear2809 bundle
    Use when validating Cisco Talos reputation enrichment and service-account readiness in Splunk ES Cloud.
    0 installs