Skip to main content

 

Splunk Lantern

Integrating Splunk Cloud Platform with AI Canvas

AI Canvas is where agentic work happens. As the industry's first multiplayer, generative workspace, it provides a shared live environment where human operators and AI agents collaborate in real time to investigate and resolve complex, cross-domain issues end-to-end.

  • AI agents drive cross-domain investigation and resolution
  • Persistent context survives team escalations and handoffs—no lost work, no repeated triage
  • Every action is grounded in platform data, organizational policy, and real workflows

The result: operations at agentic speed, with faster resolution, less friction, and governed AI work anchored in your organization's own policies.

clipboard_705b00eb-8004-4553-ba86-6c4d262507b4.png

Key capabilities

  • Generate SPL searches and visualizations from natural language prompts.
  • Explain SPL queries and results in plain language to help you understand what the search is doing.
  • Answer questions about Splunk commands, concepts, features, and best practices, particularly those for which official Splunk documentation offers guidance.

Prerequisites

  • Splunk Cloud Platform 10.5.2605.3 is needed to use AI Canvas with Splunk Cloud Platform. If you are not on 10.5.2605.3, you should receive an email before your next scheduled upgrade, and you can request to be upgraded to 10.5.2605.3.
  • You must have completed Integrating Splunk Cloud Platform with Cisco Cloud Control. AI Canvas will not work unless Cisco Cloud Control is enabled.
  • You must be a Splunk Cloud Platform admin to complete the installation and configuration steps.

Integration overview

The steps in this article show you how Splunk Cloud Platform admins connect AI Canvas with Splunk Cloud Platform:

  1. Install Splunk AI Assistant.
  2. Install Splunk Model Context Protocol (MCP) Server.
  3. Configure user access.

Install Splunk AI Assistant

To use AI Canvas with Splunk Cloud Platform, install the latest version of Splunk AI Assistant (SAIA) on your instance.

  1. Follow the steps to install Splunk AI Assistant.
  2. Under Settings, configure your Context settings.
  3. Under Settings, configure your Agent mode settings.

Install Splunk MCP Server

To use AI Canvas with Splunk Cloud Platform, install the latest version of the Splunk Model Context Protocol (MCP) Server app on your instance. Do this by following the steps to install and configure the Splunk MCP Server.

Configure user access

All users require the mcp_tool_execute capability to use AI Canvas with Splunk Cloud Platform.

Access AI Canvas

After you complete all onboarding steps, you can access AI Canvas in two ways:

  • In the top navigation bar in Splunk Cloud Platform, select the AI Canvas icon.clipboard_92c0b118-b084-4600-87b0-a4ac3c035970.png
  • From the Cisco Cloud Control home page, select AI Canvas..

Both options open the same AI Canvas experience in Cisco Cloud Control.

Known issues and limitations

The following are known issues and limitations for the Splunk Cloud Platform integration:

  • If you select a Splunk Cloud Platform visualization type that is incompatible with the data source, the visualization does not render.
  • Results data is limited to 100 rows per card.
  • Some commands are forbidden in AI Canvas with Splunk Cloud Platform. You can launch a card with a forbidden command, but a "Failed to execute skill…" error occurs if you try to refresh or run the search.

  • Written by Ramit Batra (Engineering Product Management Specialist) and Lizzy Li (Senior Staff Engineering Product Manager)
  • Splunk, A Cisco Company