Skip to main content

 

Splunk Lantern

Enhancing visibility into OT operations with the Splunk platform and Cisco Cyber Vision

Cisco industrial security fuses security into the network itself to protect operational technology (OT) at scale. This involves OT visibility, segmentation, and secure remote access all embedded into your network equipment. But the depth of what you need to monitor to keep your manufacturing, utilities, and roadway infrastructure secure and performant is much deeper than many people realize.

This is where Cisco Cyber Vision comes in. Cyber Vision uses software application sensors tailor-made for OT environments and embedded in your devices for passive discovery of events and assets. Cisco Cyber Vision provides:

  • Visibility into connected industrial assets: Understand the identity of all assets in the environment including different vendors, makes, models, firmware, IP address, and even rack slot details for modular assets.
  • Communication map: View a highly performant rendering for thousands of nodes. The rich overlay capability allows you to turn on visuals as needed to reduce distractions and see key information on protocols, ports, the volume of data being exchanged, and more.
  • Vulnerability identification and tracking: Identify known asset vulnerabilities so you can patch or protect them before they are exploited. See vulnerability descriptions, mitigation information, CVSS scores, Cisco Security Risk Scores, and MITRE ATT&CK mapping.
  • Alerts: Use the rule engine to configure alert thresholds. You can also group alerts based on triggers to reduce the number of alerts generated and customize alerts on a per-user basis or by using different rules for different areas of a manufacturing plant.

Industrial.png

Cisco Cyber Vision adds a critical new source of OT telemetry, but security teams don't need another dashboard to manage. By bringing Cyber Vision data into the Splunk platform, organizations can extend their existing single view of security and operations across both IT and OT environments. Cyber Vision telemetry in the Splunk platform supports capabilities such as:

  • Aggregation of all Cyber Vision deployments
  • Focused view per local center
  • Operational and security overview
  • Vulnerabilities overview
  • Real-time syslog collection
  • Scheduled reports by email

How to use Splunk software for this use case

Using the Cisco Cyber Vision Splunk Add-on

The Cisco Cyber Vision Splunk Add-on is a background process that contains data parsing rules, field extractions, and configurations to ingest data from Cyber Vision correctly. The installation into the Splunk platform is simple. After downloading the add-on from Splunkbase, all you need is the name, IP address, and API token of your centers, and the add-on will pull in all your inputs and normalize the data. Then you are ready to use the app. 

clipboard_8f625614-8644-4c3c-a53e-e38b3f0528ae.png

Using the Cisco Cyber Vision Splunk App

The Cisco Cyber Vision app contains prebuilt dashboards, reports, saved searches, and custom navigation menus that Cyber Vision users are most likely to find helpful. These help you make more sense of your data right out of the box, but the widgets on each dashboard are also customizable to your specific environment. 

Global Overview: This dashboard shows all your centers in aggregate, providing information such as the riskiest devices in all locations, the global distribution of your centers, and communication information.

clipboard_20c066f3-c8a5-4eb1-9616-b8c4c48150eb.png

Cyber Vision Center Overview: This dashboard is similar to the Global Overview, but allows you to select one Cyber Vision Center at a time for more localized information about devices and risks.

clipboard_e9596409-adb3-44ba-845a-63d294b12439.png

Operational & Security Insights: Some of the key information that this dashboard shows are event distributions over time, high critical events, and riskiest events. This dashboard also allows you to trace events as they move through your network.

clipboard_fa0ac3ce-0686-4825-b010-4fb575a58596.png

Assets Summary: This dashboard shows what is connected to your network and what vendors are involved. The Top 10 Talkers and Top 10 Protocols widgets are also valuable as they help you discover if there is a problem or whether your devices are performing at the level expected.

clipboard_f22dc7d3-7fb8-4345-9030-783865c69727.png

Vulnerabilities: This dashboard allows you to take action on known vulnerabilities by pointing out top vulnerabilities in key categories such as vendor, device, and firmware. It allows you to easily determine whether you should upgrade devices to mitigate vulnerabilities.

clipboard_7d2f6f82-3d4a-4e30-a419-10553352bf76.png

Customizing app widgets

While all the pre-built dashboards and widgets are designed based on common customer use cases, they still might not fit your needs. They might be right for you out of the box, or they might only function as a starting point. The following demo shows how sending Cyber Vision data into the Splunk platform gives you access to the SPL behind each search so you can customize them. 

Additional resources

Now that you have an idea of how the Splunk platform can make your Cisco Cyber Vision data even more useful, watch the full talk from Cisco Live EMEA 2026, Enhancing Splunk with OT context using Cisco Cyber Vision. In the talk, you'll see more about the benefits of using the Splunk platform, a more detailed demo of each screen of the app, and how to export any dashboard from the app for reporting outside the Splunk platform.

In addition, the following resources might be of interest to you: