← all publishers

chambear2809

@chambear2809 source repo

169 published skills · page 2 of 2

  1. Splunk Deployment Server Setup · chambear2809 bundle
    Use when the user asks to bootstrap a deployment server, tune Universal Forwarder phoneHome intervals, inspect enrolled clients, set up DS high availability, migrate clients to a new DS, scale to 5000+ forwarders, or diagnose DS runtime health. Hand off serverclass.conf and deploymentclient.conf authoring to splunk-agent-management-setup. Render, preflight, bootstrap, validate, and operate the Splunk Enterprise Deployment Server runtime: enable-deploy-server bootstrap, deployment-app layout checks, phoneHome tuning, REST inspection, large-fleet HA pairing, client re-enrollment, staged rollout, Splunk 9.4.3+ filterType handling, and failure-mode runbooks for 503 floods, app drift, and unenrolled clients.
    0 installs
  2. Splunk Knowledge Objects Setup · chambear2809 bundle
    Use when the user asks to create or govern saved searches, scheduled searches, alerts, macros, lookups, eventtypes, tags, or to set knowledge-object permissions, ownership, or app sharing. Not for Enterprise Security detections, which live in splunk-enterprise-security-config. Render, validate, and apply governance for Splunk knowledge objects: saved searches and alerts, search macros, CSV and KV Store lookups (with automatic lookup binding), eventtypes, and tags, plus sharing and ownership (ACL) governance across user, app, and global scopes. This does not implement fields.conf, field extractions, FIELDALIAS, calculated fields, bulk inventory, or arbitrary ACL endpoints.
    0 installs
  3. Splunk Microsoft Scom Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, or validate Microsoft System Center Operations Manager data in Splunk. Render, install, and validate the package-verified Splunk Add-on for Microsoft SCOM (Splunk_TA_microsoft-scom, Splunkbase 2729). Covers package-derived PowerShell inputs, microsoft:scom* source types, eventtypes, lookups, index readiness, and readiness-doctor handoffs.
    0 installs
  4. Splunk Observability Slo Setup · chambear2809 bundle
    Use when the user asks to create, validate, or operationalize Splunk Observability SLOs. Render and validate focused Splunk Observability Cloud service-level objective setup plans, including SLI source selection, objective/target placeholders, SLO API payload intent, /slo/validate handoffs, deeplinks, detector follow-up, and deep-native-workflow delegated specs.
    0 installs
  5. Splunk Cloud Data Manager Setup · chambear2809 bundle
    Use when the user asks to set up Splunk Cloud Data Manager, onboard cloud data sources through Data Manager, validate Data Manager prerequisites, handle Data Manager CloudFormation or ARM or Terraform templates, diagnose Data Manager ingestion health, migrate Azure Event Hubs from MSCS, promote historical AWS S3 data, or onboard CrowdStrike FDR data. Render, doctor, apply supported cloud-side artifacts for, and validate Splunk Cloud Platform Data Manager onboarding across AWS, Azure, GCP, and CrowdStrike with Data Manager 1.16 source coverage, HEC ACK/token guardrails, Data Manager-generated CloudFormation/ARM/Terraform template handling, provider prerequisite checks, health searches, migration warnings, and secret-file-only handoffs.
    0 installs
  6. Cisco Intersight Setup · chambear2809 bundle
    Use when configuring or validating Cisco Intersight audit, inventory, alarm, or metrics inputs in Splunk.
    0 installs
  7. Galileo Platform Setup · chambear2809 bundle
    Use when configuring an already-running Galileo instance for Splunk Platform or Splunk Observability Cloud, including multimodal traces and multi-model experiment comparison evidence. Render, validate, and optionally apply Galileo application readiness, object lifecycle, Observe export/runtime, Evaluate, Luna, Controls, multimodal, and Splunk wiring for Galileo SaaS or Enterprise deployments. Covers projects, log streams, datasets, prompts, experiments, metrics, annotations, feedback, RBAC, provider handoffs, trace maintenance/metrics APIs, Luna Studio training, metadata-only media export, AI Assistant beta readiness, global dashboards, generic alert webhook relay, SDK experiment groups, large-dataset batching, Annotation Queues GA, AI-assisted custom metrics, cost/billing review, Trace Count alerts, multimodal out-of-the-box metric variants, and the Splunk Agent Observability documentation epoch, HEC/OTLP/OTel handoffs, dashboards, and detectors; delegate On-Prem Kubernetes deployment and packaged services.
    0 installs
  8. Splunk Github Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate GitHub audit/security data in Splunk. Install, render, configure, and validate the Splunk Add-on for GitHub (Splunk_TA_github, Splunkbase 6254). Renders GitHub Cloud audit, user, and code/dependabot/secret scanning alert inputs; emits PAT and HEC token runbooks, GitHub Cloud HEC audit streaming guidance, GHES syslog/SC4S handoffs, expanded github_audit readiness coverage, and validation SPL. Use for GitHub audit logs, GitHub Enterprise Cloud, GHES audit, GitHub security scanning alerts, or Splunk_TA_github onboarding.
    0 installs
  9. Splunk Platform Sizing · chambear2809 bundle
    Use when the user asks to size a Splunk cluster, decide how many indexers or search heads they need, plan reference hardware, evaluate an All-In-One vs distributed deployment, size Splunk on Kubernetes, or estimate storage for a retention requirement. Size a Splunk deployment from a use case (daily ingest, retention, search load, premium apps, high availability) and render a sizing recommendation report plus machine-readable sizing.json. Covers All-In-One single-server standalone, distributed Splunk Validated Architectures (C/M series), Splunk on Kubernetes (SOK and Splunk POD), and Splunk Cloud, with Enterprise Security and ITSI workload multipliers.
    0 installs
  10. Splunk Sysmon Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate Microsoft Sysmon data in Splunk. Install, render, configure, and validate the Splunk Add-on for Microsoft Sysmon (Splunk_TA_microsoft_sysmon, Splunkbase 5709). Renders package-backed endpoint or Windows Event Collector WinEventLog inputs from extracted defaults, prevents duplicate direct-plus-WEC ingestion, hands off Universal Forwarder rollout, constrains readiness to the Sysmon source, and validates XmlWinEventLog Sysmon data. Use for Sysmon, WEC Sysmon, Microsoft Sysinternals Sysmon, or Splunk_TA_microsoft_sysmon onboarding.
    0 installs
  11. Splunk Vmware Ta Setup · chambear2809 bundle
    Use when the user asks about VMware, vCenter, ESXi logs, VMware metrics, VMware indexes, VMware extractions, or making VMware data ready for Splunk ITSI, Enterprise Security, Monitoring Console, or infrastructure dashboards. Install, render, configure, and validate Splunk Supported Add-on coverage for VMware, including the VMware app/add-on family, vCenter collection planning, ESXi syslog handoffs, event and metric index templates, deployment role placement, ITSI readiness, and post-ingest validation.
    0 installs
  12. Cisco Appdynamics Setup · chambear2809 bundle
    Use when the user asks about AppDynamics setup, Splunk_TA_AppDynamics, controller connections, analytics connections, or AppDynamics dashboards in Splunk. Automate Cisco Splunk Add-on for AppDynamics (Splunk_TA_AppDynamics) setup and configuration. Creates the AppDynamics index, sets add-on defaults, configures controller and optional analytics connections, enables common input groups, and validates the deployment.
    0 installs
  13. Widefield Splunk Siem Setup · chambear2809 bundle
    Use when the user asks to send WideField Security events to Splunk, create WideField HEC/index plumbing, validate WideField ingest, or prepare SIEM searches and dashboard readiness for identity threat detections. Render, apply, and validate Splunk SIEM readiness for WideField Security events using a WideField index, HEC token, schema-light spath searches, saved searches, macros, and starter dashboard assets.
    0 installs
  14. Cisco Thousandeyes MCP Setup · chambear2809 bundle
    Use when the user asks to register the ThousandEyes MCP, set up TE in Cursor/Claude/Codex/VS Code/Kiro, configure the Cisco ThousandEyes Cursor plugin, or pair an AI assistant with TE. Render and (optionally) apply Model Context Protocol client configurations for the official ThousandEyes MCP Server (https://api.thousandeyes.com/mcp, GA per docs.thousandeyes.com/.../thousandeyes-mcp-server). Supports Cursor, Claude Code, Codex, VS Code, and AWS Kiro clients with both OAuth Bearer and OAuth2 flows. Surfaces TE rate limits, the unit-consumption warning for Instant Tests, and gates the write/Instant- Test tool group behind an explicit acknowledgement.
    0 installs
  15. Splunk Appdynamics Apm Setup · chambear2809 bundle
    Use when the user asks for AppDynamics APM, business applications, tiers, nodes, business transactions, snapshots, service endpoints, remote services, information points, metrics, AWS Lambda/serverless APM, development monitoring, OpenTelemetry ingestion, OTel collector setup, or application server agent instrumentation snippets. Render and validate Splunk AppDynamics APM workflows for business applications, tiers, nodes, business transactions, service endpoints, remote services, information points, snapshots, metrics, serverless APM, Development Level Monitoring, Splunk AppDynamics for OpenTelemetry, OTel collector/access-key validation, and app-server agent snippets.
    0 installs
  16. Splunk Appdynamics Eum Setup · chambear2809 bundle
    Use when the user asks for AppDynamics EUM, Browser RUM, BRUM, Mobile RUM, IoT RUM, app keys, JavaScript injection, Session Replay, Mobile Session Replay, source maps, mobile SDKs, or EUM beacon validation. Render and validate Splunk AppDynamics End User Monitoring workflows, including Browser RUM, Mobile RUM, IoT RUM, EUM account and application keys, JavaScript injection, iOS, Android, React Native, Flutter, .NET MAUI snippets, Browser Session Replay, Mobile Session Replay, mapping, source-map upload, and beacon validation.
    0 installs
  17. Splunk Attack Analyzer Setup · chambear2809 bundle
    Use when a user asks for Attack Analyzer, SAA, phishing and malware analysis data ingestion, the `saa` index, `saa_indexes` macro, or Enterprise Security adaptive response readiness. Install, configure readiness, and validate Splunk Attack Analyzer platform integration using Splunk Add-on for Splunk Attack Analyzer (`Splunk_TA_SAA`, app 6999) and Splunk App for Splunk Attack Analyzer (`Splunk_App_SAA`, app 7000).
    0 installs
  18. Splunk Cloud Acs Admin Setup · chambear2809 bundle
    Use when the user asks to manage Splunk Cloud ACS, acs admin, ACS indexes, ACS HEC tokens, ACS users and roles, app permissions, private connectivity, outbound ports, DDSS, ACS limits, maintenance windows, restart current-stack, ACS license state, Observability pairing, or to audit Splunk Cloud control-plane configuration. Render, preflight, inventory, apply, audit, and validate Splunk Cloud Admin Config Service (ACS) administration across IP allowlists, indexes, HEC tokens, users, roles, capabilities, app permissions, private connectivity, outbound ports, DDSS self-storage, limits.conf settings, maintenance windows, restarts, apps, authentication tokens, deployment task status, license state, and Observability pairing handoffs.
    0 installs
  19. Splunk Enterprise Host Setup · chambear2809 bundle
    Use when the user asks to bootstrap a Splunk host, install a heavy forwarder, build a search/index/forwarder tier, or configure clustered Splunk Enterprise nodes. Install Splunk Enterprise packages on Linux hosts and configure them as a search-tier, indexer, heavy-forwarder, cluster manager, indexer peer, search head cluster deployer, or search head cluster member. Supports local or SSH execution, official URL or local package sources, role-aware forwarding, and single-site clustered topologies.
    0 installs
  20. Splunk Fraud Analytics Setup · chambear2809 bundle
    Use when the user asks to install, plan, configure, or validate Splunk Fraud Analytics. Render, install, and validate Splunk App for Fraud Analytics readiness, including ES dependency checks, Lookup File Editing prerequisite, fraud use-case intake, risk index and RBA prerequisites, correlation-search review, data-model prerequisites, package handoff, and validation SPL.
    0 installs
  21. Splunk Connect For Syslog Setup · chambear2809 bundle
    Use when the user asks about SC4S, Splunk Connect for Syslog, syslog-ng collector setup, or syslog ingestion through HEC. Deploy and validate Splunk Connect for Syslog (SC4S) for Splunk Enterprise or Splunk Cloud. Prepares Splunk indexes and HEC, renders Docker/Podman/systemd or Kubernetes Helm configuration, and validates SC4S startup.
    0 installs
  22. Splunk Monitoring Console Setup · chambear2809 bundle
    Use when the user asks to configure distributed or standalone Monitoring Console mode, splunk_monitoring_console_assets.conf auto-config, distsearch.conf search peer groups, forwarder monitoring, platform alerts, search peer onboarding checks, or Monitoring Console status validation. Render, preflight, apply, and validate Splunk Enterprise Monitoring Console configuration.
    0 installs
  23. Splunk Observability Native Ops · chambear2809 bundle
    Use when configuring native Splunk Observability Cloud operations beyond collection and classic dashboards, including detectors, alert routing, On-Call handoffs, APM service maps and traces, RUM session workflows, Synthetic tests and waterfall artifacts, and modern logs chart handoffs.
    0 installs
  24. Splunk Security Portfolio Setup · chambear2809 bundle
    Use when a user asks for total Splunk security portfolio coverage, product gap analysis, or which Splunk security skill handles ES Essentials, ES Premier, ES native SOAR, Automated Threat Analysis, Malware Reversing or Phishing Analysis agents, Security AI Assistant, Federated Analytics, SOAR, Security Essentials, UBA, Attack Analyzer, ARI, Mission Control, PCI, InfoSec, CIM, or related security apps. Resolve Splunk security products and associated security offerings to the correct local setup skill, install-only path, ES bundled workflow, or manual handoff.
    0 installs
  25. Cisco Defenseclaw Deskside Setup · chambear2809 bundle
    Use when deploying, upgrading, configuring, or validating DefenseClaw on an AMD Ryzen AI or other Lemonade-backed deskside. Install or upgrade the official Cisco AI Defense DefenseClaw release on a Linux Lemonade deskside, select a local Qwen model, configure the stable OpenAI-compatible API, wire the supported Codex hook connector, and verify observe or action enforcement.
    0 installs
  26. Galileo On Prem Kubernetes Setup · chambear2809 bundle
    Use when planning, reviewing, doctoring, or checking full deployment coverage for Galileo On-Prem on Kubernetes. Render a non-mutating, immutable orchestration packet for the Galileo Stack, galileoctl, packaged Agent Control, Luna Studio, Wizard GPU/local inference, air-gapped supply chains, and production-readiness handoffs. Route implementation to the owning child skill; reject install, upgrade, rollback, uninstall, registry writes, and all other live mutations.
    0 installs
  27. Splunk Cloud Acs Allowlist Setup · chambear2809 bundle
    Use when an existing handoff or slash command still references splunk-cloud-acs-allowlist-setup. Compatibility alias for the older Splunk Cloud ACS IP allowlist workflow. Use splunk-cloud-acs-admin- setup for new ACS work, including allowlists, indexes, HEC tokens, users, roles, capabilities, app permissions, private connectivity, outbound ports, DDSS self-storage, limits, maintenance windows, and restarts.
    0 installs
  28. Splunk GCP Ta Setup · chambear2809 bundle
    Use when the user asks about Splunk_TA_google-cloudplatform, the Splunk Add-on for Google Cloud Platform, GCP audit logs, Cloud Logging, Pub/Sub ingestion, or GCP log onboarding in Splunk. Install, render, configure, and validate the Splunk Add-on for Google Cloud Platform (Splunk_TA_google- cloudplatform, Splunkbase 3088). Centers on the high-value Cloud Logging to Pub/Sub ingestion path, rendering the real google_cloud_pubsub input (google:gcp:pubsub:message plus auto-classified audit subtypes), a service-account credential runbook, the gcp index, and ingestion validation; documents the monitor, billing, bucket, and resource-metadata inputs.
    0 installs
  29. Splunk Oncall Setup · chambear2809 bundle
    Use when the user asks about Splunk On-Call, VictorOps, on-call schedules, escalation, paging, X-VO-Api- Id/X-VO-Api-Key, the alert.victorops.com REST endpoint, or victorops_app. Render, validate, and apply the full Splunk On-Call (formerly VictorOps) lifecycle — teams, users + contact methods, rotations, escalation policies, routing keys, scheduled overrides, personal paging policies, alert rules / Rules Engine, maintenance mode, incidents, notes, chat, stakeholder messages, REST endpoint and generic email alert payloads — plus Splunk-side companions (Splunkbase 3546 alert action, 4886 Add-on, 5863 SOAR connector, ITSI NEAP, ES Adaptive Response).
    0 installs
  30. Splunk Stream Setup · chambear2809 bundle
    Use when the user asks about Splunk Stream, stream forwarder, streamfwd, wire data, network capture, NetFlow, or packet capture setup. Install and configure Splunk Stream, Splunk Stream Forwarder (Splunk_TA_stream), and Splunk Stream Wire Data (Splunk_TA_stream_wire_data). Creates indexes, configures the stream forwarder (ipAddr, port, NetFlow receivers), enables protocol streams, and validates the deployment.
    0 installs
  31. Lemonade Splunk Otel · chambear2809 bundle
    Use when installing or upgrading Lemonade, checking its telemetry, configuring a loopback OTLP receiver, or preparing Lemonade telemetry for Splunk or Galileo fan-out. Upgrade and operate Lemonade Server on Debian or AMD Ryzen AI hosts, enable its native OpenTelemetry traces, and route them through the Splunk Distribution of the OpenTelemetry Collector with secure credentials, privacy controls, rollback, and backend validation.
    0 installs
  32. Splunk Okta Ta Setup · chambear2809 bundle
    Use when the user asks about Splunk_TA_okta_identity_cloud, the Splunk Add-on for Okta Identity Cloud, Okta System Log, OktaIM2, Okta Universal Directory, or Okta authentication onboarding in Splunk. Install, render, configure, and validate the Splunk Add-on for Okta Identity Cloud (Splunk_TA_okta_identity_cloud, Splunkbase 6553). Renders real inputs.conf stanzas for the okta_identity_cloud modular input across the log, user, group, app, groupUser, and appUser metrics (OktaIM2:* source types), emits an OAuth 2.0 client-credentials or API-token account runbook, creates the okta index, maps source types to CIM, and validates ingestion.
    0 installs
  33. Cisco Meraki Ta Setup · chambear2809 bundle
    Use when configuring Cisco Meraki organization accounts, API inputs, or dashboards in Splunk.
    0 installs
  34. Splunk App Install · chambear2809 bundle
    Use when the user asks to install a Splunk app, TA, add-on, download from Splunkbase, deploy an app package, or manage installed apps. Install, update, and manage Splunk apps and add-ons (TAs). Supports installing locally from .tgz/.spl files, remotely from a URL, or from Splunkbase. Can also list installed apps and uninstall apps.
    0 installs
  35. Splunk Itsi Config · chambear2809 bundle
    Use when managing ITSI entities, services, KPIs, dependencies, service trees, selected guarded operations, or ITSI content-pack imports; do not use it to install, upgrade, license, or restart ITSI or install prerequisite apps. Configure and validate an existing, licensed Splunk IT Service Intelligence deployment from repo-local YAML.
    0 installs
  36. Cisco Product Setup · chambear2809 bundle
    Use when the user asks to set up Splunk for a Cisco product such as ACI, Nexus 9000, Duo, Meraki, ThousandEyes, ASA, or FTD, including choosing the dedicated ASA syslog TA versus Cisco Security Cloud API or eStreamer collection. Resolve a Cisco product name from the SCAN catalog and route installation, configuration, and validation through the correct existing setup skill.
    0 installs
  37. Splunk Admin Doctor · chambear2809 bundle
    Use when the user asks for a Splunk admin doctor, health audit, full feature coverage check, production- safe remediation plan, Cloud/Enterprise admin troubleshooting, or routing to existing Splunk admin skills. Diagnose Splunk Cloud Platform and Splunk Enterprise administration health, render full-coverage doctor reports, and create selected safe fix packets.
    0 installs
  38. Splunk AWS Ta Setup · chambear2809 bundle
    Use when the user asks about Splunk_TA_aws, the Splunk Add-on for AWS, CloudTrail, AWS Config, or GuardDuty log ingestion, SQS-based S3 inputs, or a manual AWS TA configuration alternative to Data Manager. Install, render, configure, and validate the Splunk Add-on for AWS (Splunk_TA_aws, Splunkbase 1876) as the manual TA path that complements splunk-cloud-data-manager-setup. Renders real inputs.conf stanzas for CloudTrail and GuardDuty via the SQS-based S3 input and AWS Config via the aws_config input, emits an IAM-role or access-key account-setup runbook, creates the aws index, maps source types to CIM, and validates ingestion.
    0 installs
  39. Splunk Box Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate Box data in Splunk. Install, render, configure, and validate the Splunk Add-on for Box (Splunk_TA_box, Splunkbase 2679). Renders Box historical event, live monitoring, and file-ingestion inputs, encrypted OAuth account handoffs, Box index creation, package-backed box:* source-type validation SPL, and readiness-doctor source-pack coverage.
    0 installs
  40. Cisco Security Cloud Setup · chambear2809 bundle
    Use when configuring Cisco Security Cloud API inputs, product flows, indexes, or dashboards in Splunk.
    0 installs
  41. Splunk AI Ml Toolkit Setup · chambear2809 bundle
    Use when the user asks about MLTK, Splunk AI Toolkit, Machine Learning Toolkit, PSC, Python for Scientific Computing, DSDL, Deep Learning Toolkit, Splunk anomaly detection assistants, AI Toolkit Agent Launchpad or the earlier Agent Builder preview, the `aiagent` command, Cisco Time Series Model, Cisco Deep Time Series Model, Smart Alerts Assistant, or AI/ML product coverage outside Splunk AI Assistant, including Cisco Data Fabric requests about AI Toolkit or machine-data model workflows. Install, render, validate, and audit Cisco Data Fabric AI Toolkit and Splunk-owned AI and machine-learning workflows beyond Splunk AI Assistant: Splunk AI Toolkit / MLTK (`Splunk_ML_Toolkit`), Python for Scientific Computing (PSC), Splunk App for Data Science and Deep Learning (DSDL), MLTK anomaly workflows, LLM/`ai` command readiness, external model runtimes, and legacy anomaly app migration.
    0 installs
  42. Splunk Kvstore Admin Setup · chambear2809 bundle
    Use when the user asks to back up or restore the KV Store, migrate the KV Store storage engine, upgrade the KV Store server version, reset or clean the KV Store, define a KV Store collection or lookup, or recover KV Store on an SHC. Render, validate, and apply Splunk App Key Value Store administration: backup and restore (point-in-time), clean/reset, storage-engine migration to WiredTiger, KV Store server-version upgrade (7.0/8.0), maintenance mode, collections.conf and KV Store lookup-definition governance, and standalone vs search head cluster paths.
    0 installs
  43. Splunk Salesforce Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate Salesforce data in Splunk. Install, render, configure, and validate the Splunk Add-on for Salesforce (Splunk_TA_salesforce, Splunkbase 3549). Renders Salesforce object and event log inputs, encrypted account setup handoffs, Salesforce index creation, package-backed sfdc:* source-type validation SPL, and readiness-doctor source pack coverage.
    0 installs
  44. Splunk Servicenow Ta Setup · chambear2809 bundle
    Use when the user asks about Splunk_TA_snow, the Splunk Add-on for ServiceNow, ServiceNow incident or change or CMDB ingestion, snow:// inputs, or ITSM data onboarding in Splunk. Install, render, configure, and validate the Splunk Add-on for ServiceNow (Splunk_TA_snow, Splunkbase 1928). Renders real per-table snow:// inputs.conf stanzas (incident, change_request, problem, em_event, sys_user, cmdb_ci, and more) with the correct account, table, timefield, and id_field, emits a basic-auth or OAuth account runbook, creates the snow index, maps tables to snow:<table> source types, and validates ingestion.
    0 installs
  45. Galileo Agent Control Setup · chambear2809 bundle
    Use when the user asks to govern runtime agent behavior with Agent Control and wire control events to Splunk Platform or Splunk Observability Cloud. Render, validate, and optionally apply Agent Control setup assets covering Docker or external server readiness, file-backed auth templates, policy controls, Python @control() snippets, TypeScript runtime snippets, OpenTelemetry and custom Splunk HEC event sinks, Splunk HEC and OTel Collector handoffs, and Splunk Observability dashboards/detectors.
    0 installs
  46. Galileo On Prem Stack Setup · chambear2809 bundle
    Inspect, render, connected-preflight, and observe a pinned Galileo On-Prem galileo-stack deployment on Kubernetes; produce secret-safe evidence and Galileo/CSE joint-session handoffs for every install, upgrade, rollback, uninstall, CRD, galileoctl, GPU, air-gap, and lab-bootstrap change. Use when planning reusable Galileo On-Prem Kubernetes deployment work without unattended mutation.
    0 installs
  47. Galileo MCP Server Setup · chambear2809 bundle
    Use when configuring Galileo MCP, registering Galileo with IDE/agent clients, inventorying live MCP tools, or auditing Galileo MCP product coverage. Covers Galileo API-key secret handling, self-hosted URL derivation, live MCP tool inventory and drift checks, write/generation tool gating, MCP tool-call observability handoffs, and explicit boundaries between Galileo MCP IDE workflows and broader Galileo platform, Agent Control, Splunk HEC/OTLP, dashboard, and detector automation. Render, validate, probe, and document safe client setup for the official Galileo MCP Server (`https://api.galileo.ai/mcp/http/mcp`) across Cursor, VS Code, Codex, Claude Code, and AWS Kiro.
    0 installs
  48. Splunk Appdynamics Setup · chambear2809 bundle
    Use when the user asks for AppDynamics setup, AppDynamics coverage, AppDynamics product routing, or a full AppDynamics doctor/gap report. Coverage-first parent router for the Splunk AppDynamics skill suite. Resolves AppDynamics SaaS, On-Premises, Virtual Appliance, SAP Agent, APM, agents, Smart Agent, Cluster Agent, Infrastructure Visibility, Database Visibility, Analytics, EUM, Synthetic Monitoring, Log Observer Connect, Controller/admin, alerting, dashboards/reports, ThousandEyes integration, tags, extensions, Sensitive Data Collection and Security, release notes and references, product announcements, AIML, GPU Monitoring, Splunk AppDynamics for OpenTelemetry, Secure Application, Observability for AI, and Splunk Platform integration requests to the owning child skill, then emits a machine-readable coverage report from the checked-in taxonomy.
    0 installs
  49. Splunk Cyberark Ta Setup · chambear2809 bundle
    Use when the user asks to onboard, configure, render, or validate CyberArk data in Splunk. Umbrella render, install, and validation workflow for CyberArk Splunk add-ons: supported CyberArk EPM API collection (Splunk_TA_cyberark_epm, Splunkbase 5160) and archived/not-supported CyberArk EPV/PTA CEF parsing (Splunk_TA_cyberark, Splunkbase 2891). Renders product-specific inputs, syslog/SC4S handoffs, encrypted account setup, metadata, and validation SPL.
    0 installs
  50. Splunk Database Ta Setup · chambear2809 bundle
    Use when the user asks to onboard SQL Server, MySQL, Oracle Database, database logs, or supported database TA readiness in Splunk. Render, install, and validate package-verified Splunk Supported Add-ons for Microsoft SQL Server, MySQL, and Oracle Database. Uses extracted Splunkbase packages as source of truth for app IDs, versions, source types, DB Connect handoffs, SQL Server file/perfmon inputs, and validation searches.
    0 installs
  51. Splunk Hec Service Setup · chambear2809 bundle
    Use when the user asks for reusable HEC token management, inputs.conf rendering, ACS HEC tokens, allowed index restrictions, indexer acknowledgement, HEC port/TLS settings, or a shared ingestion endpoint for apps and external collectors. Render, preflight, apply, and validate Splunk HTTP Event Collector service configuration for Splunk Enterprise and Splunk Cloud.
    0 installs
  52. Splunk Infosec App Setup · chambear2809 bundle
    Use when the user asks to install, configure, prepare, or validate the InfoSec app. Render, install, and validate InfoSec App for Splunk readiness, including package delivery, prerequisite security data-source checklist, dashboard and macro checks, CIM/data-model prerequisites, Cloud IDM support-request notes, Lookup Editor dependency, and validation SPL.
    0 installs
  53. Splunk Spl2 Pipeline Kit · chambear2809 bundle
    Use when the user needs SPL2 pipeline authoring, conversion review, compatibility linting, or shared templates for Ingest Processor or Edge Processor workflows, including Cisco Data Fabric or telemetry pipeline management requests that need reusable SPL2 pipeline logic. Render and lint reusable SPL2 pipeline templates for Cisco Data Fabric, Splunk Ingest Processor, and Edge Processor, including routing, redaction, sampling, lookups, metrics, OCSF, decrypt, stats, custom templates, SPL-to-SPL2 compatibility, and PCRE2 migration checks.
    0 installs
  54. Cisco Scan Setup · chambear2809 bundle
    Use when the user asks about SCAN, Cisco App Navigator, product catalog, ecosystem intelligence, or splunk-cisco-app-navigator setup in Splunk. Automate Splunk Cisco App Navigator (SCAN) setup and validation. Installs the splunk-cisco-app-navigator app from a local package, verifies the product catalog and Splunkbase lookup, triggers catalog sync from S3, and validates the deployment.
    0 installs
  55. Splunk Uba Setup · chambear2809 bundle
    Use when validating Splunk UBA / UEBA readiness, optional UBA Kafka ingestion app placement, and migration guidance to Splunk Enterprise Security Premier UEBA without installing standalone UBA servers.
    0 installs
  56. Cisco Webex Setup · chambear2809 bundle
    Use when configuring Webex OAuth, meetings, audit, calling, quality, or Contact Center data in Splunk.
    0 installs
  57. Splunk Itsi Setup · chambear2809 bundle
    Use when the outcome is ITSI product/package installation, upgrade, license readiness, restart, core-app health, or installation validation; route post-install entities, services, KPIs, dependencies, Event Analytics configuration, and content-pack import to splunk-itsi-config. Install and validate Splunk IT Service Intelligence (ITSI) on Splunk Cloud or Splunk Enterprise.
    0 installs
  58. Splunk Soar Setup · chambear2809 bundle
    Use when the user asks to install Splunk SOAR On-prem, build a SOAR cluster, onboard SOAR Cloud, install Automation Broker, install splunk-side SOAR apps, or wire up SOAR with Splunk Enterprise Security. Render, preflight, apply, and validate the full Splunk SOAR lifecycle: Splunk SOAR (On-prem) unprivileged single-instance install, On-prem cluster install with external services (PostgreSQL local or AWS RDS, GlusterFS, Elasticsearch, HAProxy), SOAR Cloud onboarding helper (JWT capture, IP allowlist, REST automation user provisioning), Splunk SOAR Automation Broker on Docker or Podman with FIPS detection, Splunk-side apps (Splunk App for SOAR Splunkbase 6361, Splunk App for SOAR Export Splunkbase 3411), and ES integration readiness with a fail-closed Mission Control UI handoff.
    0 installs
  59. Cisco Asa Ta Setup · chambear2809 bundle
    Use when onboarding or validating Cisco ASA or FTD syslog with Splunk_TA_cisco-asa and SC4S.
    0 installs
  60. Cisco Spaces Setup · chambear2809 bundle
    Use when configuring or validating Cisco Spaces meta stream accounts, firehose inputs, and data in Splunk.
    0 installs
  61. Cisco Ucs Ta Setup · chambear2809 bundle
    Use when configuring Cisco UCS Manager records, task inputs, templates, or cisco:ucs data in Splunk.
    0 installs
  62. Widefield Security Setup · chambear2809 bundle
    Use when the user asks to onboard WideField Security, plan identity threat detection and response, connect WideField to identity/SIEM/SOAR/governance tools, or coordinate WideField child skill execution without using undocumented WideField APIs. Render, route, validate, and optionally delegate a WideField Security adoption workflow across Okta, Saviynt, Splunk SIEM, Google SecOps, and identity-threat doctor skills.
    0 installs
  63. Cisco Cloud Control Setup · chambear2809 bundle
    Use when the user asks to prepare Cisco Cloud Control, AgenticOps, AI Canvas, Cloud Control Studio, Cloud Control Workflows, or governed Cisco/Splunk agent execution workflows. Render, validate, doctor, and optionally execute delegated setup plans for Cisco Cloud Control adoption, AI Canvas readiness, Cloud Control Studio handoffs, official Cloud Control feature coverage, Cisco Workflows API readiness, delegated Cisco Data Fabric architecture coverage, MCP connectors, Splunk AI Agent Monitoring, Observability content, and Cisco domain readiness.
    0 installs
  64. Cisco Collaboration Setup · chambear2809 bundle
    Use when planning or reviewing Splunk onboarding for Cisco Unified Communications Manager syslog, CDR, or CMR; Cisco Expressway syslog, CDR, or media evidence; Cisco Meeting Server syslog or XML CDR; or Cisco Meeting Management system and audit syslog. Render a privacy-safe, evidence-gated collaboration plan with deterministic SC4S classification and explicit RoomOS, BroadWorks, Webex, and ThousandEyes handoffs without applying changes.
    0 installs
  65. Cisco Dc Networking Setup · chambear2809 bundle
    Use when the user asks about Cisco DC networking, ACI, APIC, Nexus Dashboard, Nexus 9K TA setup, Splunk TA automation, or cisco_dc_networking_app_for_splunk. Automate Cisco DC Networking TA setup and configuration on Splunk. Creates indexes, configures ACI/Nexus Dashboard/Nexus 9K accounts, enables data inputs, stores credentials securely, and validates the deployment.
    0 installs
  66. Cisco Secure Access Setup · chambear2809 bundle
    Use when configuring Cisco Secure Access accounts, event collection, indexes, or Splunk dashboards.
    0 installs
  67. Splunk AI Assistant Setup · chambear2809 bundle
    Use when the user asks about splunk-ai-assistant, Splunk AI Assistant, Splunk AI Assistant for SPL, AI Assistant for SPL, or the `Splunk_AI_Assistant_Cloud` app. Install, validate, and help complete Splunk AI Assistant (`Splunk_AI_Assistant_Cloud`) setup on Splunk Cloud or Splunk Enterprise. Handles Splunkbase installation with the shared app installer, checks post-install health, and supports Enterprise cloud-connected onboarding, activation, and proxy configuration.
    0 installs
  68. Splunk Ddaa Archive Setup · chambear2809 bundle
    Use when the user asks to archive expired Splunk Cloud index data to the Splunk-managed archive, set or change DDAA archival retention, restore archived data, or move an index onto Splunk Archive. Not for DDSS self-storage or generic index administration, which live in splunk-cloud-acs-admin-setup. Render, validate, and apply Splunk Cloud Platform Dynamic Data Active Archive (DDAA): per-index archival retention via the ACS index splunkArchivalRetentionDays setting, retention math validation, and restore and disable runbooks for the Splunk Web-only operations.
    0 installs
  69. Splunk Platform Pki Setup · chambear2809 bundle
    Use when the user asks to build Splunk PKI, mint certs, prepare third-party CA CSRs, replace default certs, configure mTLS, fix KV Store cert validation, encrypt replication traffic, configure SAML/LDAPS trust, or rotate Splunk TLS certificates. Render, preflight, apply, validate, rotate, and inventory private or public PKI for Splunk Enterprise TLS surfaces: Splunk Web, splunkd REST, S2S, HEC, KV Store, indexer clusters, SHC, License Manager, Deployment Server, Monitoring Console, Federated Search, heavy forwarders, Universal Forwarders, Edge Processor, SAML SP signing, LDAPS trust, and CLI CA trust. Covers CSR handoffs, internal CA rendering, FIPS mode, TLS policy presets, KV Store EKU enforcement, default- cert refusal, SAN-aware leaf certs, mTLS, replication-port TLS, and delegated rotation runbooks.
    0 installs