SFBA Splunk Usergroup meeting October 1, 2025

BeckyBurwell 0 views 37 slides Oct 15, 2025
Slide 1
Slide 1 of 37
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35
Slide 36
36
Slide 37
37

About This Presentation

SFBA Splunk Usergroup meeting October 1, 2025: conf25 recap; Learn how Fabrix.ai and Splunk are colloborating


Slide Content

© 2019 SPLUNK INC.
Welcome to the October SF Bay
Area Splunk User Group Meeting!
SFBA User Group Leaders
Becky Burwell, Sr. Production Engineer, Yahoo
[email protected]
Manan Grover, Splunk
[email protected]

© 2019 SPLUNK INC.
Agenda
●Welcome!
*Start Recording
●Announcements
●.conf25 recap
●Short Break
●Fabrix.ai and Splunk

© 2019 SPLUNK INC.
Announcements
●Thanks Fabrix.ai for the pizza!
●Splunk .conf25 recordings
○https://conf.splunk.com/watch/conf-online.html
●Next UserGroup: tentatively Wed Dec 10, 6 pm

© 2019 SPLUNK INC.
.conf25 recap

.conf25 highlights
from Becky
●Big user conference
○Boston in September
○5500 attendees
●Migrating to Splunk 10 talk
●Job inspector talk (Clara M and Martin
Mueller): always useful
○Improve Search Efficiency:
Understanding the Job Inspector
●Innovation Lab
○Forward looking but AI to help
diagnose Admin issues looks
promising
●Talk on using new Edge Hub to monitor
car diagnostics
●Great to see Splunk community members
●Becky inducted again into SplunkTrust!

Conf25 Highlights from Manan
1.Splunk 10.0
2.Splunk MCP Server
3.AI Assistant for SPL
4.Conf 26 is in Denver!! Sept 14-17th

Splunk 10
Introducing Splunk 10
Preparing to upgrade from 9.x to Splunk 10
Splunk Health Assistant Add-on

USB-C
MCP EXPLAINED
MCP Clients
Model Context Protocol
Splunk MCP Server
Splunk Enterprise/Cloud

SF BA Community Comments on
.conf25
San Francisco Bay Community Comments on .conf25

Shailesh Manjrekar, Chief AI and Marketing Officer at Fabrix.ai

How Fabrix.ai and Splunk are collaborating

1 Fabrix.ai Proprietary and Confidential. © 2015 -2025
Fabrix.ai + Splunk
The Future of Intelligent IT Operations
Introducing the next evolution in IT operations management —
•combining automated service assurance with
•AI-powered insights for unprecedented visibility, efficiency, and intelligence
AI Agents
Unified Observability &
Assurance
Intelligent Automation
Shailesh Manjrekar, Chief AI and Marketing Officer

2 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
From Automation to AI-Driven Operations
Journey from unified observability and cross-domain automation to AI-driven management. The strategic
partnership unites leading platforms and introduces the next wave of intelligent operations.
Unified Observability: Visibility & Assurance Cross domain visibility
Automation: Streamlined Operations
Integration of Fabrix.ai with Splunk ITSI for automated service assurance and cross-domain visibility.
Automated ITSI content pack creation, service decomposition, and multi-vendor data integration across 1000+ sources.
Unified Observability Cross-domain Intelligence
Accelerated Deployment
Intelligence: AI-Powered Future
Advanced AI Agents & Copilot enabling natural language operations, intelligent insights, and conversational workflows.
Enriched Data Sources
AI Agents & Copilot Conversational Ops MCP Tools
Strategic
Value:
Evolving from basic automation to AI-driven intelligence delivering measurable
business outcomes

3 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Business Value: Amplified by AI
The Fabrix.ai + Splunk partnership delivers enhanced ROI through AI -powered automation, enabling
organizations to achieve operational excellence with intelligent workflows.
Accelerated ROI & Reduced MTTR
AI-driven automation reduces deployment time by 80% while
cutting mean-time-to-resolution through intelligent insights and
predictive analytics.
ITSI Setup Time Alert Noise MTTR
-80% -65% -40%
Conversational Ops Reduce Skill Barriers
Natural language AI interfaces enable operations teams of all
skill levels to perform complex tasks through simple
conversations with AI assistants.
"Show current health score and KPIs for OLB Infra
service"
Instant, actionable
results
Scalable Automation Accelerates Outcomes
AI-powered automation scales across environments, enabling
consistent operations from small deployments to enterprise-
scale implementations.
Self-healing systems Predictive maintenance
AI-enhanced decisioning
Tool Consolidation & Integration
Replace multiple point solutions with a unified AI-driven
platform, reducing tool sprawl and licensing costs while
improving cross-domain visibility.
Before AI Integration After AI Integration
7-10 separate tools Single unified platform
Key Takeaway: AI-driven automation elevates the value proposition from cost reduction to business transformation

4 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Unified Network
Observability Offering:
•Splunk ITSI Content pack
for Unified Network
Observability
•Splunk ITSI Workflow
Manager
Unified Network Observability with Splunk ITSI + Fabrix.ai

5 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Comprehensive Network Topology Ingestion:
Automated discovery and mapping of network devices,
protocols (CDP, OSPF, BGP, LLDP, ISIS), and relationships
ITSI Data Enrichment and Ingestion :
Unified monitoring of applications, servers, VMs, network, and
storage for optimal performance
Telecom/Service Provider Network Insights:
IP transport, backhaul networks, and evolved packet core
analytics for telecom and CSPs
Multi-Vendor IT & Infrastructure Content Packs :
Integrated views of diverse IT, infrastructure, and network
assets across Datacenter, Campus, Edge and SD -WAN
Data Ingest TO Splunk ITSI
Fabrix.ai and Splunk Integration Value

6 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Nexus Datacenter Fabric
E-Commerce
Catalyst Campus Network
UCS
192.133.243.247
AI POD
Cisco Validated Design with Splunk + Fabrix.ai –
End2End Customer Digital Experience

7 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Splunk + Fabrix.ai – End2End Customer
Digital Experience ITSI content pack

8 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
RDAF Datasource Integration Ecosystem
Application
performance
Faults
Telemetry
Network
performance
Collaboration
Notification
Incident
management
Automation &
Orchestration
Customer experience
Change Management
Any Source
SNMP
Ansible
SNMP
Telemetry
Fabrix.
ai
RDAF

9 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Cisco Validated Zone Splunk Lantern
Learn MoreWatch the video here
End to End Observability with
Fabrix.ai + Splunk + ITSI
Fabrix.ai on Splunk Lantern

10Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Splunk ITSI Workflow Automation for onboarding
Splunk ITSI Onboarding using RDAF’s Automation Fabric
➢RDAF does topology
discovery and dependency
mapping and leverages to -
➢Automate creation of
➢Splunk indices
➢Splunk entities, KPI’s,
service dependencies
➢Correlation searches,
aggregation policies
➢To generate episodes

11Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Automated & Intelligent - Technical Capabilities
Combining powerful automation with AI -driven intelligence to transform IT operations from manual tasks
to conversational workflows.
Core Automation Capabilities
Automated Content Pack Creation
Streamline ITSI content pack deployment for
network services and Telco environments
Service Decomposition
Multi-Vendor Integration
Automated entity creation, KPI setup, and
dependency mapping for ITSI services
1700+ data source connections across network,
infrastructure, and application domains
AI-Enhanced Features
Natural Language Operations
Query service health, metrics, and dependencies
using conversational language
Intelligent Index Management
AI-driven Splunk index discovery, monitoring,
and optimization recommendations
Automated Dependency Visualization
Generate real-time dependency maps and
visualizations through simple requests
Combined Power: Automation + AI Intelligence
Evolution from automation scripts to conversational AI delivers unprecedented operational efficiency, reduced complexity,
and faster time-to-value
Benefits:80% faster service setup • Reduced complexity • Intuitive operations • Cross-domain insights

12Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Proven Solutions: Splunk Apps & AI Tools
Explore battle-tested solutions: Asset Analytics, Unified Network Observability, and new AI-driven agent
tools and copilots – all validated with major Cisco environments and over 1700+ data sources.
Asset Analytics
Cisco Validated
Data center modernization & asset lifecycle analytics
Single source of truth for multi-vendor assets
Automated dependency mapping & capacity planning
License & certificate management with alerts
View on Splunkbase
Unified Network Observability & Telco
Assurance
Multi-vend or Comp atible
Comprehensive network device & Tools integration
Holistic visibility across campus, data center & edge
Proactive troubleshooting & performance optimization
Data-driven insights with protocol-level analytics
View on Splunkbase
Next-Generation
Natural language interface for Splunk operations
Automated service health monitoring & KPI analysis
AI-powered dependency visualization
Conversational troubleshooting workflows
AI Agents & Copilot
Ex pan ding Toolkit
MCP Server Tools
Intelligent Splunk index management & monitoring
ITSI service interactions & health tracking
Automated entity type management
Cross-platform integration with App/Dev, Cloud, LoB
1700+ Data Source
Integrations
Cisco Validated
Designs
Enterprise-Grade
Security

13Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Seamless Integration & Real-World Use Cases
Integrated with Splunk Core, ITSI, and multi-vendor platforms (Cisco, AppDynamics, DNAC, AWS, Azure, etc.). Real-world
cases include automated asset discovery, health scoring, service mapping, and more.
Cross-PlatformIntegration
App/Dev
Cloud
E-commerce App
Integration
Fabrix.ai Native
Major Platforms
AppDynamics Kubernetes
CI/CD
IT
Cisco DNAC UCS
Meraki
Business
Line of Business
Azure GCP
AI-PoweredUse Cases
Analytics Contact CenterAWS
E-Commerce
Conversational ITSI Service Monitoring
Automated Dependency Visualization
Intelligent Index Management
Entity Health Analysis
Natural language queries reveal health scores, status, and KPIs for
services like "OLB Infra" with AI-generated insights.
AI Agents identify and map service dependencies with a simple prompt:
"Get dependent services for 'OLB App' and create visualization."
Effortlessly monitor and optimize Splunk indexes through natural
language: "Show metadata for rdaf_domain_ssl_expiry index."
Quickly assess entity status with automated analytics: "What is the
current state of 'HR App Entity' and its vital metrics?"
"AI Agents have reduced our MTTR by 60% through automated dependency
mapping and natural language troubleshooting." — Enterprise Customer
Integration:Bridging the gap between technical complexity and
conversational operations across platforms

14Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Asset Analytics
•Use Cases for ITOps, IT Planning and Network Admins
•Data Center Modernization and Refresh
•Application Modernization
•Asset Lifecycle analytics
•Capacity utilization
•Change Management
•Real-time asset data collection and CMDB update
•Multi-vendor Compute, Network, Storage, Licensing Insights
•Customer Benefits Datacenter Modernization
•Consolidate multiple asset tools
•Provide single source of truth
•Application Dependency mapping, License and Certificate
management
https://splunkbase.splunk.com/app/7541

15Fabrix.ai Proprietary and Confidential. © 2015 - 2025
https://splunkbase.splunk.com/app/7541
•Typical Integrations
•Network Devices: Routers, switches, firewalls, wireless access points
•Network Management Systems (NMS): Cisco Prime Infrastructure, Cisco
DNA Center, SolarWinds
•Ticketing Systems: ServiceNow, Jira
•Key Insights
•Comprehensive Network Visibility: Provides a holistic view of network
infrastructure, including devices, flows, and performance metrics.
•Proactive Problem Resolution: Enables early detection of network
anomalies and rapid root cause analysis.
•Optimized Network Performance: Improves network performance and
reduces downtime.
•Data-Driven Decision Making: Leverages data-driven insights to
optimize network operations.
Unified Network Observability

16Fabrix.ai Proprietary and Confidential. © 2015 - 2025
AI-Powered Interactions
IT Operations
IT Operations
"Show current health score and last 3 notable KPIs for the OLB Infra service"
"Get me the list of services dependent on 'OLB App' and create a visualization"
Fabrix.ai Assistant
Fabrix.ai Assistant
OLB Infra service is at 72% health. Notable KPIs: CPU Utilization (critical),
Memory Usage (warning), Transaction Latency (degraded)
Found 4 dependent services. Generating visualization with dependency map...
Key Capabilities
Natural Language
Queries
Ask questions about Splunk
indexes, ITSI services, and
entities using everyday
language
Dependency
Visualization
Real-time Health
Monitoring
Index Intelligence
Automatically generate and
visualize service dependencies and
relationships
Track service health scores
and identify critical KPIs
affecting performance
Query and analyze Splunk indexes
for size, state, and metadata insights
Transforming Splunk Operations
AI Agents & Copilot evolve Splunk from a data platform to an intelligent assistant that anticipates needs, automates
complex tasks, and delivers insights through natural conversation.
Reduced MTTR AI-Enhanced Skill Amplifier
Integration: Works with Splunk Core, ITSI, and multi-vendor environments including Cisco and cloud platforms
Fabrix.ai AI Agents & Copilot Next-Generation Automation
Discover the AI Agents & Copilot layer for Splunk: seamlessly enabling conversational operations,
advanced automation, and real-time actionable insights for Splunk Core and ITSI.

17Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Splunk Index Discovery
Intelligent discovery and listing of
Splunk indexes with advanced
filtering capabilities.
Real-time index state analysis, size
tracking, and metadata inspection
for operational excellence.
Monitor ITSI service health scores,
status, and notable KPIs through
natural language queries.
"list all Splunk indexes starting with
prefix 'rdaf_'"
"What is the current state and
size of 'rdaf_domain_ssl_expiry'?"
Index State Monitoring Service Health Analysis
"Show health score and KPIs for
'OLB Infra' service"
Expanding MCP Toolkit Capabilities
Dependency
Visualization
Entity Type
Management
Conversational
Workflows
Automated
Insights
MCP Tools: Expanded Intelligent Operations
Leverage the evolving suite of Model Control Protocol (MCP) tools for Splunk, empowering automated
index discovery, optimization, and AI-enhanced management functions.

18Fabrix.ai Proprietary and Confidential. © 2015 - 2025 Stay tuned for more tools.
Available Splunk MCP Tools

19Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Fabrix.ai ITSI Assistant Conversational Queries
What is the current state, size, type and meta data of the Splunk
index rdaf_domain_ssl_expiry
Show current health score, status, and last 3 notable KPIs for the ITSI service named OLB Infraget me the list of Splunk ITSI services that are dependent on 'OLB
App' service
get me the list of Splunk ITSI services that are dependent on
'OLB App' service
what is the current state of Splunk ITSI entity type 'HR App Entity‘
and get me the list of vital metrics for it

20Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Fabrix.ai AI Agents – ITSI and Data Ingestion

21Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Fabrix.ai ITSI assistant – Episodes & RCA

22Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Cisco Validated Design
Global Telecom Provider
Automated service assurance for 5G infrastructure using
Fabrix.ai + Splunk ITSI with conversational AI workflows.
Cisco + Splunk Solution
Unified observability across campus, datacenter and cloud
with AI-powered dependency mapping and KPI insights.
"MCP Tools and Splunk integration have revolutionized our ability to visualize
dependencies and resolve complex issues."
Fortune 500 Financial Services
"The natural language interface to Splunk ITSI transformed how our operations
team troubleshoots network issues."
83% faster service mapping 62% MTTR reduction AI-driven RCA 90% alert noise reduction Conversational queries Automated mapping
Cisco Catalyst Network
Healthcare Provider E-Commerce Platform
AI-powered network observability with natural language
exploration of ITSI service health and automated remediation.
"The Fabrix.ai ITSI Assistant allows our staff to quickly assess service
health using simple language queries."
Cisco Datacenter Design
Intelligent index management and ITSI service visualization
enabling proactive service assurance with natural language
exploration.
AI-guided resolution99.99% service uptime 5-min setup time
40% faster resolution Automated content packs Full-stack visibility
"The AI Agents' ability to visualize dependencies has transformed
our incident response capabilities."
Customer Insight: AI-powered operations drive measurable business outcomes across enterprise environments
Customer Success: AI-Driven Outcomes
See how real customers leverage automated content packs, root cause analysis, and natural language
workflows to streamline operations and deliver actionable insights – especially in Cisco-validated use cases.

23Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Thank You

24 Fabrix.ai Proprietary and Confidential. © 2015 - 2025
➢End-to-End Digital Experience and Resiliency /
Observability for E-commerce Application
➢Splunk ITSI Content Pack
➢Splunk ITSI AI Assistant and MCP Server
➢Splunk ITSI Workflow Manager
➢Splunkbase Applications

25Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Fabrix.ai – Splunk ITSI Telco Observability / AIOps
Splunk
SIEM
Splunk
ITSI
Ingest enriched data to Splunk,
Splunk Content pack for Telcos and
Fabrix.ai Apps in Splunkbase

26Fabrix.ai Proprietary and Confidential. © 2015 - 2025
Splunk + CloudFabrix => Better Together

© 2019 SPLUNK INC.
Questions/Discussion