Integrating Splunk Cloud Platform with AI Canvas
AI Canvas is where agentic work happens. As the industry's first multiplayer, generative workspace, it provides a shared live environment where human operators and AI agents collaborate in real time to investigate and resolve complex, cross-domain issues end-to-end.
- AI agents drive cross-domain investigation and resolution
- Persistent context survives team escalations and handoffs—no lost work, no repeated triage
- Every action is grounded in platform data, organizational policy, and real workflows
The result: operations at agentic speed, with faster resolution, less friction, and governed AI work anchored in your organization's own policies.

Key capabilities
- Generate SPL searches and visualizations from natural language prompts.
- Explain SPL queries and results in plain language to help you understand what the search is doing.
- Answer questions about Splunk commands, concepts, features, and best practices, particularly those for which official Splunk documentation offers guidance.
Prerequisites
- Splunk Cloud Platform 10.5.2605.3 is needed to use AI Canvas with Splunk Cloud Platform. If you are not on 10.5.2605.3, you should receive an email before your next scheduled upgrade, and you can request to be upgraded to 10.5.2605.3.
- You must have completed Integrating Splunk Cloud Platform with Cisco Cloud Control. AI Canvas will not work unless Cisco Cloud Control is enabled.
- You must be a Splunk Cloud Platform admin to complete the installation and configuration steps.
Integration overview
The steps in this article show you how Splunk Cloud Platform admins connect AI Canvas with Splunk Cloud Platform:
- Install Splunk AI Assistant.
- Install Splunk Model Context Protocol (MCP) Server.
- Configure user access.
Install Splunk AI Assistant
To use AI Canvas with Splunk Cloud Platform, install the latest version of Splunk AI Assistant (SAIA) on your instance.
- Follow the steps to install Splunk AI Assistant.
- Under Settings, configure your Context settings.
- Under Settings, configure your Agent mode settings.
Install Splunk MCP Server
To use AI Canvas with Splunk Cloud Platform, install the latest version of the Splunk Model Context Protocol (MCP) Server app on your instance. Do this by following the steps to install and configure the Splunk MCP Server.
Configure user access
All users require the mcp_tool_execute capability to use AI Canvas with Splunk Cloud Platform.
Access AI Canvas
After you complete all onboarding steps, you can access AI Canvas in two ways:
- In the top navigation bar in Splunk Cloud Platform, select the AI Canvas icon.

- From the Cisco Cloud Control home page, select AI Canvas..
Both options open the same AI Canvas experience in Cisco Cloud Control.
Known issues and limitations
The following are known issues and limitations for the Splunk Cloud Platform integration:
- If you select a Splunk Cloud Platform visualization type that is incompatible with the data source, the visualization does not render.
- Results data is limited to 100 rows per card.
- Some commands are forbidden in AI Canvas with Splunk Cloud Platform. You can launch a card with a forbidden command, but a "Failed to execute skill…" error occurs if you try to refresh or run the search.

