This page describes how to integrate Cisco AppDynamics and Splunk.

New Integration Method

The new integration between Cisco AppDynamics SaaS and Splunk Platform (Splunk Cloud Platform or Splunk Enterprise) provides a unified observability experience for the performance of your applications. The integration enables you to view the in-context logs of any performance issues in applications. You can directly navigate from Controller UI to Splunk Platform by clicking the the View Logs in Splunk button on the following pages:

  • Application Dashboard
  • Tiers
  • Nodes
  • Business Transaction
  • Transaction Snapshot

With deep links from applications, tiers, nodes, business transactions, and transaction snapshots in Cisco AppDynamics SaaS, you can view the related logs in Splunk Cloud Platform or Splunk Enterprise. This process helps in streamlining the troubleshooting workflows, faster identification of the root causes, and resolution of the issues.

For information about the new integration steps, see Configure Cisco AppDynamics for Splunk Log Observer Connect.

Old Integration Method

This integration between Cisco AppDynamics SaaS and Splunk provides a single, cohesive view of data and allows you to launch Splunk searches using auto-populated queries from the Cisco AppDynamics Console based on criteria such as time ranges and the node IP address.

Configure Splunk Integration

  1. Log in to the Controller UI as an administrator. 
  2. Select Settings > Administration.
  3. Select Integration > Splunk.

  4. Click the Enabled checkbox.

  5. For the URL, enter the Splunk URL and port number.  

  6. Optionally, enter Extra Query Parameters. These parameters are appended to each Splunk search initiated from Cisco AppDynamics.
  7. Click Save. 

Launch a Splunk Search from Cisco AppDynamics

You can launch a search of Splunk logs for a specific time frame associated with a transaction snapshot from several places in Cisco AppDynamics.

To launch a Splunk search:

  • You need Splunk credentials. You will only enter your credentials the first time that you launch a Splunk search. Your credentials are cached by the browser after the first login.
  • Ensure the Splunk Server is running.
  • Configure your browser to allow popups.

Enable Pop-ups

If you do not see a login prompt at first login, either your browser is blocking the Splunk login popup or the Splunk Server is not running.

You can access the Search Splunk option from the node dashboard or the business transaction dashboard.

Node Dashboard Access

  1. Navigate to a node dashboard.
  2. Select Actions > Search Splunk.

Business Transaction Dashboard

  1. Select the Transaction Snapshot tab.
  2. Right-click a transaction snapshot.
  3. Select More Actions
  4. Select Search Splunk.