Access Cisco Cloud Control from your Splunk Cloud Platform deployment

Cisco Identity (CUI) is the authentication service that Splunk Cloud Platform uses to connect your Splunk Cloud Platform users to Cisco Cloud Control. Turning on CUI for your deployment gives your Splunk Cloud Platform users access to Cisco Cloud Control features such as AI Canvas, a natural language interface for data analysis.

What is Cisco Cloud Control?

Cisco Cloud Control is a unified administration platform that gives you access to Cisco portfolio products and features from a single interface. To use Cisco Cloud Control from your Splunk Cloud Platform deployment, all users must authenticate through CUI, which uses a verified email address as the unique identifier for every user across Cisco systems.

What is Cisco Identity?

CUI is the authentication and identity management service that Cisco Cloud Control uses to verify users. When you turn on CUI for your Splunk Cloud Platform deployment, Splunk requires every user to verify their email address when they log in. Turning on CUI connects each user's Splunk account to their Cisco identity, which is the prerequisite for accessing Cisco Cloud Control features.

CUI doesn't replace your existing identity provider (IdP). Your IdP continues to handle authentication, and CUI adds a layer of email verification on top of your existing authentication flow.

Non-default search head URL format requirement

Splunk Cloud Platform deployments that include non-default search heads have an additional requirement before you can turn on CUI. CUI requires that the host name your users and your IdP use to access each non-default search head separates the search head name from the stack name with a period, a format also known as dot notation. For example:

CODE
sh.stack-name.splunkcloud.com

If your non-default search head host name currently uses a dash between the search head name and the stack name, update the following to use dot notation before you turn on CUI:

  • Your IdP's service provider URL configuration
  • User bookmarks and any saved links that point to the non-default search head
  • Any other places your organization uses to link to the search head

For example:

  • Use: es.acme.splunkcloud.com
  • Don't use: es-acme.splunkcloud.com

The stack name itself can contain dashes. This requirement applies only to the separator between the search head name and the stack name. This requirement doesn't apply to default search heads.

Note: Turning on CUI before your IdP uses dot notation for non-default search heads prevents users from logging in to those search heads. See Turn on Cisco Unified Identity for your Splunk Cloud Platform deployment for information about how to recover access if this happens.