Skip to content

Documentation

Guides, category explorer, compliance tools, architecture, API reference, and governance for the Splunk monitoring use case catalog.

Start Here
New to the catalog? These guides will get you oriented.
README
Guide
Project overview, quick start, repository structure, and key links.
Contributing Guide
Guide
How to add use cases, run audits, manage versions, and submit PRs.
Implementation Guide
Guide
Step-by-step guide for deploying use cases: inputs, props, transforms, dashboards.
GitHub Pages Setup
Guide
How to deploy the dashboard to GitHub Pages with custom domains.
Replication Guide
Guide
How to fork and adapt the catalog for your own organization or domain.
Domain Guides
In-depth guides for each monitoring domain — vendor best practices, Cisco product deep-dives, implementation guidance, and direct links to relevant use cases.
Infrastructure Monitoring
Guide
Server & compute, virtualization, network infrastructure, storage, data center physical, DC fabric/SDN, and compute/HCI. Gold-standard Cisco coverage for Catalyst Center, ThousandEyes, Meraki, SD-WAN, ACI, UCS, and HyperFlex.
Security Monitoring
Guide
Identity & access management, security infrastructure (NGFW, EDR, SIEM), and network security/zero trust. Gold-standard coverage for Cisco ISE, Duo, Secure Firewall, and ASA/AnyConnect.
Cloud & Containers Monitoring
Guide
Containers & Kubernetes, AWS/Azure/GCP cloud infrastructure, and cost/capacity management. Vendor best practices from CNCF, Red Hat, and FinOps Foundation.
Application & Service Monitoring
Guide
Databases, application infrastructure, DevOps/CI-CD, observability stack (Splunk ITSI), and ITSM. DORA metrics, ITIL v4 practices, and SRE burn rates.
Collaboration & IoT/OT Monitoring
Guide
Email & collaboration and IoT/operational technology. Gold-standard Cisco coverage for Webex, UCM, Cyber Vision, Edge Intelligence, and Splunk Edge Hub.
Industry Verticals
Guide
Energy, manufacturing, healthcare, transportation, oil & gas, retail, aviation, telecom, water utilities, and insurance — industry-specific monitoring with regulatory context.
Compliance & Business Analytics
Guide
Regulatory compliance frameworks (GDPR, NIS2, DORA, PCI DSS, HIPAA, SOX, NIST) and business analytics for executive intelligence, revenue, HR, supply chain, and ESG.
Category Explorer
Browse all 23 monitoring domains. Click a category to explore its use cases in the catalog.
Loading catalog data…
Compliance & Regulatory Tools
Interactive views for auditors, buyers, and compliance teams.
Regulatory Primer (Markdown)
Ref
Source markdown for the regulatory primer — covers every framework with Splunk mapping.
Coverage Methodology
Ref
How compliance clause coverage percentages are calculated and validated.
Compliance Coverage Map
Ref
Per-regulation clause coverage tables and assurance levels.
Compliance Gaps Analysis
Ref
Known gaps in regulatory coverage and planned remediation.
Legal Review Guide
Guide
Process for legal review of compliance claims and regulatory mappings.
Regulatory Change Watch
Ref
Automated monitoring for regulatory text updates and deadline changes.
Evidence Packs (12 regulations)
Tool
Auditor-facing evidence packs: GDPR, PCI DSS, HIPAA, SOX, SOC 2, ISO 27001, NIST CSF, NIST 800-53, NIS2, DORA, CMMC.
NIS2 Monitoring Methodology
Guide
Source hierarchy, coverage taxonomy, evidence-first design, and reviewer workflow for NIS2 Splunk monitoring.
NIS2 Maturity Benchmark
Ref
Crawl/walk/run maturity stages for NIS2 obligations with benchmark domains and control-family coverage.
NIS2 External Review Pack
Tool
Artifact bundle for counsel, auditor, or competent-authority review of the NIS2 implementation.
NIS2 Self-Validation Record
Ref
Validation evidence and audit commands for the NIS2 monitoring framework.
NIS2 Source Map
Ref
Authoritative source register with hierarchy, binding status, and retrieval dates for NIS2 legal sources.
Building the Catalog
Architecture, design decisions, content authoring, and AI integration.
Architecture
Ref
Build pipeline, data flow, file relationships, and deployment architecture.
Product Design
Ref
Target audiences, product principles, content philosophy, and feature phases.
Architecture Decision Records
Ref
ADRs: markdown source of truth, static SPA, catalog schema, stdlib-only, ID scheme.
Use Case Field Reference
Ref
Every field in a UC JSON file: name, type, constraints, and examples.
Gold Standard Template
Guide
The canonical template for writing high-quality use cases with all fields.
Gold Standard Authoring Playbook
Guide
Step-by-step playbook for uplifting UCs to gold standard quality.
Category Files & Names
Ref
Naming conventions for category directories, markdown files, and IDs.
Plain-Language Explanations
Ref
How grandmaExplanation fields are written — the non-technical voice guidelines.
Implementation Ordering (Crawl / Walk / Run)
Ref
How prerequisite chains and wave assignments drive the implementation roadmap.
CIM & Data Models
Ref
How CIM-normalised SPL and data model acceleration work across the catalog.
Content Gap Analysis
Ref
Identifies missing fields, incomplete UCs, and areas needing expansion.
Codebase Diagram
Ref
Visual map of the repository structure and file dependencies.
Pitch Deck
Ref
Elevator pitch and value proposition for the use case catalog.
AI Agent Entrypoint
API
Machine-readable entry point for AI agents: schemas, field maps, MCP tools.
MCP Server Reference
API
Model Context Protocol server: 10 tools, 4 URI schemes for LLM integration.
Deployment & Integration
Deploy the catalog in your Splunk environment and integrate with specific products.
Enterprise Deployment Guide
Guide
Deploying the catalog at scale: distributed Splunk, indexes, roles, and migration.
Splunk Cloud Compatibility
Ref
Which UCs and SPL work on Splunk Cloud vs on-prem Enterprise.
Recommender App
Tool
The Splunk app that recommends UCs based on your data sources and environment.
Splunk Apps vs Use Cases
Ref
How catalog UCs relate to packaged Splunk apps and content packs.
Equipment Table Reference
Ref
Technology and TA filter definitions used across the catalog.
Catalyst Center Integration
Guide
End-to-end guide for integrating Cisco Catalyst Center with the UC catalog.
Data Generator — Top 10 Use Cases
Tool
Synthetic data generation guide for the top 10 most-implemented UCs.
API & Schema
Technical reference for the catalog's data formats, APIs, and URL patterns.
Catalog Schema Reference
API
Top-level keys, field abbreviations, and the structure of catalog.json.
API Documentation (OpenAPI)
API
Interactive API reference for /api/v1/ endpoints.
API Versioning
Ref
How the /api/v1/ endpoints are versioned and stability guarantees.
Schema Versioning
Ref
How uc.schema.json is versioned with additive-only changes.
URL Scheme
Ref
Deep-link patterns for UCs, categories, filters, and search.
Source Catalog
Ref
Provenance and origin tracking for use case content.
Governance & Quality
Quality metrics, review processes, versioning, security, and project governance.
Quality Scorecard Methodology
Ref
Scoring methodology for use case completeness, accuracy, and coverage.
Provenance Coverage
Ref
Tracking the origin and review status of every UC in the catalog.
UC Quality Mandate
Ref
The quality mandate and tier definitions for use case content.
Peer Review Guide
Guide
Checklist and process for peer-reviewing use case content.
SME Review Guide
Guide
Subject matter expert review process for technical accuracy.
Sample Data Coverage
Ref
Which UCs have sample data for testing and validation.
Governance
Ref
Project governance model: roles, decision-making, and contribution tiers.
Security Policy
Ref
How to report vulnerabilities and the project security posture.
Changelog
Ref
Version history with all changes, additions, and fixes per release.
Roadmap
Ref
Planned features, content expansions, and infrastructure improvements.
Signed Provenance
Ref
Build provenance attestation and integrity verification for the catalog.