icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Catalyst Center Add-on
SHA256 checksum (catalyst-center-add-on_101.tgz) 4f3f48881ff3fec3ec37a493c76c8837684b05a35194d93582a5d2ef64df1868 SHA256 checksum (catalyst-center-add-on_100.tgz) d9346393f5feeaf2fcc35c1ccc841ecca184263298e0d6dfcc698279a82c0e1c
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Catalyst Center Add-on

Splunk Cloud
Overview
Details
The Cisco Catalyst Center Add-on for Splunk allows a Splunk® Enterprise or Splunk Cloud administrator to collect data from Cisco Catalyst Center APIs.

Cisco Catalyst Center Add-on for Splunk

APP ID: Splunk-TA-cisco-catalyst-center

The Cisco Catalyst Center Splunk App and Add-on are designed to work together. The App requires the Add-on to be installed. The Add-on can be used with or without the App.

This Add-on defines and creates the following sourcetypes:

  • cisco:catalyst:client
  • cisco:catalyst:clienthealth
  • cisco:catalyst:devicehealth
  • cisco:catalyst:compliance
  • cisco:catalyst:issue
  • cisco:catalyst:networkhealth
  • cisco:catalyst:securityadvisory

⚠️ This Add-on replaces the legacy Cisco DNA Center Add-on and supports the modern Cisco Catalyst Center APIs.


Installation Instructions

Install the Cisco Catalyst Center Add-on for Splunk by:

  • Downloading it from the App homepage, or
  • Installing it directly from within Splunk Enterprise or Splunk Cloud.

Setup

  1. After installing, verify the Add-on is located at: $SPLUNK_HOME/etc/apps/Splunk-TA-cisco-catalyst-center
  2. Restart Splunk to complete the installation.

Configuration

Step 1 – Configure a Cisco Catalyst Center User Account

Create and configure a Catalyst Center API user account that the Add-on will use to authenticate.

https://cdn.splunkbase.splunk.com/media/public/screenshots/017c30b3-b5ac-4b24-8f04-951151e4a1a1.png" alt="Add an account" width="1110"/>


Step 2 – Configure Data Inputs

To collect data from the Catalyst Center APIs, add one or more inputs:

  • Name: A unique name for this data input
  • Interval: Time interval (in seconds) to poll data
  • Index: Target Splunk index
  • Host: Cisco Catalyst Center base URL
  • Example: https://sandboxdnac.cisco.com:443
  • Ensure it includes the https protocol
  • User Account: Select the configured Catalyst Center user credentials

https://cdn.splunkbase.splunk.com/media/public/screenshots/bf8a2900-acca-4b09-8c9a-eed6198c6e8c.png" alt="Add cisco_catalyst_client" width="1110"/>

Repeat for additional data inputs as needed.


SSL Configuration

  1. By default, the API calls from the Cisco Catalyst Add-on for Splunk are verified by SSL.
    Configuration is located at:
    $SPLUNK_HOME/etc/apps/Splunk-TA-cisco-catalyst-center/default/splunk_ta_cisco_catalyst_center_settings.conf
    ini [additional_parameters] verify_ssl = True

  2. To disable SSL verification, create or edit the following file:
    $SPLUNK_HOME/etc/apps/Splunk-TA-cisco-catalyst-center/local/splunk_ta_cisco_catalyst_center_settings.conf
    And add:
    ini [additional_parameters] verify_ssl = False

  3. Restart Splunk to apply changes.


Modular Input API Reference

This section lists the primary Catalyst Center API endpoints used by each modular input included in the Add-on.

Client (cisco:catalyst:client)

  • GET /dna/data/api/v1/clients

Client Health (cisco:catalyst:clienthealth)

  • GET /dna/intent/api/v1/client-health

Compliance (cisco:catalyst:compliance)

  • GET /dna/intent/api/v1/compliance/count
  • GET /dna/intent/api/v1/compliance
  • GET /dna/intent/api/v1/compliance/detail
  • GET /dna/intent/api/v1/network-device/{id}
  • GET /dna/intent/api/v1/networkDevices/{id}/assignedToSite

Device Health (cisco:catalyst:devicehealth)

  • GET /dna/intent/api/v1/device-health
  • GET /dna/intent/api/v1/network-device
  • GET /dna/intent/api/v2/networkDevices/{deviceId}/interfaces/query

Issue (cisco:catalyst:issue)

  • GET /dna/intent/api/v1/issues
  • GET /dna/intent/api/v1/issue-enrichment-details
  • GET /dna/intent/api/v1/site
  • GET /dna/intent/api/v1/network-device/{id}

Network Health (cisco:catalyst:networkhealth)

  • GET /dna/intent/api/v1/network-health

Security Advisory (cisco:catalyst:securityadvisory)

  • GET /dna/intent/api/v1/security-advisory/advisory/aggregate
  • GET /dna/intent/api/v1/security-advisory/advisory
  • GET /dna/intent/api/v1/security-advisory/advisory/{advisoryId}/device
  • GET /dna/intent/api/v1/network-device/{id}
  • GET /dna/intent/api/v1/networkDevices/{id}/assignedToSite

Getting Help

Release Notes

Version 1.0.1
June 26, 2025

Catalyst Center Add-on: v1.0.1

  • add TRUNCATE settings for catalyst sourcetypes in props.conf
  • addon builder 4.5.0
Version 1.0.0
June 4, 2025

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.