Skip to content

IP Fabric Splunk TA

Overview

The IP Fabric Splunk TA offers a potent solution for comprehensive network monitoring and analysis. By utilizing the official IP Fabric app, organizations can seamlessly merge IP Fabric’s advanced network visibility capabilities with Splunk’s robust data collection and analysis functionalities. This collaboration empowers teams to swiftly identify and troubleshoot network issues, proactively enhance security measures, and gain valuable insights from the amalgamation of IP Fabric’s network data and Splunk’s powerful analytics platform.

Installing the Add-on

Splunkbase

The IP Fabric Splunk TA is available on Splunkbase here.

Installing Via the Splunk Web Interface

  1. log in to Splunk and navigate to the Apps menu.
  2. click the Browse more apps button or the Find more apps link.
  3. search for IP Fabric.
  4. click the Install button.

Manual Installation

  1. download the IP Fabric Splunk TA from here.
  2. log in to Splunk and navigate to the Apps menu.
  3. click the Manage Apps button.
  4. click the Install app from file button.
  5. select the IP Fabric Splunk TA file and click Upload.
  6. restart Splunk.

Configuring the Add-on

Setting Up IP Fabric API Token

  1. log in to IP Fabric and navigate to Settings > Integrations > API Tokens.
  2. click the Create API Token button.
  3. enter a name for the token and click Create.
  4. copy the token and save it in a secure location.
  5. log in to Splunk and navigate to the IP Fabric TA.
  6. click the Configuration tab.
  7. paste the token into the API Token field.
  8. click Save.

Capturing Events

Configuring the IP Fabric app

  1. log in to Splunk and navigate to the IP Fabric app.
  2. click the Inputs tab.
  3. click the Create New Input button.
  4. enter a name for the input.
  5. enter an Interval for the input.
  6. enter an Index for the input.
  7. enter the URL for the IP Fabric instance.

Capturing Intent Checks

  1. Follow the steps above to configure the app.
  2. Select the Intent Check checkbox.
  3. press save/update.

Capturing Table Data

  1. Follow the steps above to configure the app.
  2. Select either ‘Inventory’ or ‘Technology’ from the Table dropdown.
  3. enter a table path in the Table Path field.
  4. add optional filters in the Filter field.
  5. press save/update.

Using the Add-on

Search an Index loaded with IP Fabric Data

Using the search bar, you can search for any data that has been loaded into the index. You can start correlating data in other splunk indexes with IP Fabric data.