splunk-observability-isovalent-integration

Renders Splunk OTel collector overlays and generates handoff assets for Isovalent stacks.

36|7|Updated Mar 17, 2026
One-click install
npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-observability-isovalent-integration
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: splunk-observability-isovalent-integration
Source: https://github.com/chambear2809/splunk-cisco-skills/tree/main/skills/splunk-observability-isovalent-integration
Command: npx skills add https://github.com/chambear2809/splunk-cisco-skills --skill splunk-observability-isovalent-integration

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill requires yaml_compat, and includes scripts (resource) and references (resource) components.

What problem does it solve?

Wire an installed Isovalent stack (Cilium, Hubble, Tetragon, optional Hubble Enterprise or cilium-dnsproxy) to Splunk Observability Cloud and Splunk Platform. Renders Splunk OTel Collector scrape overlays, metric filters, Tetragon filelog ingestion defaults, stdout and legacy fluentd alternatives, dashboards, detectors, and handoff scripts for base collector, HEC, and Cisco Security Cloud ingestion. Use when wiring Cilium, Tetragon, or Hubble metrics into Splunk Observability Cloud, shipping Tetragon logs to Splunk Platform, or validating Isovalent telemetry after platform install.

Core Features & Use Cases

  • Render Splunk OTel Collector overlay with seven Prometheus scrape jobs for Cilium, Hubble, Tetragon, and optional components.
  • Generate dashboards and detectors; provide handoff scripts to downstream skills (base collector, HEC, Cisco Security Cloud, dashboard builder, native ops).
  • Supports file-based ingestion via Tetragon, stdout, and deprecated fluentd paths with token safety safeguards.

Quick Start

Render the overlay and handoff scripts, then review and apply them to your cluster.

Frequently Asked Questions about splunk-observability-isovalent-integration

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I wire Cilium and Tetragon telemetry into Splunk Observability Cloud?

To wire Cilium and Tetragon telemetry into Splunk Observability Cloud, you can render a Splunk OTel Collector overlay with Prometheus scrape jobs, metric filters, and file-based ingestion defaults to apply to your cluster.

How do I configure Splunk OTel Collector to scrape Hubble metrics?

Configuring Splunk OTel Collector to scrape Hubble metrics is done by rendering an overlay with seven Prometheus scrape jobs and a strict metric allow-list to filter telemetry from Hubble and other Isovalent components.

Does this integration support shipping Tetragon logs to Splunk Platform via HEC?

Yes, shipping Tetragon logs to Splunk Platform is supported through generated handoff scripts for HEC ingestion, alongside file-based ingestion defaults and stdout paths for Tetragon telemetry.

Can I use fluentd for Isovalent log ingestion with Splunk?

Yes, you can use fluentd for Isovalent log ingestion with Splunk through deprecated fluentd paths supported by the integration, alongside file-based and stdout ingestion methods for telemetry.

What is needed to validate Tetragon ingestion with hostPath coordination in Splunk?

Validating Tetragon ingestion with hostPath coordination requires token-safety checks and a set of validation steps across the workflow to ensure proper file-based log ingestion into Splunk.

How do I generate Splunk dashboards and detectors for Cilium metrics?

Generating Splunk dashboards and detectors for Cilium metrics is handled by the integration, which produces handoff scripts for base collector, HEC, and Cisco Security Cloud ingestion alongside the telemetry overlays.