Splunk Monitoring Use Cases

Read-only catalog of Splunk monitoring use cases — browse by category, compliance framework, MITRE ATT&CK mapping, sourcetype, CIM model, and data sizing estimates

Splunk Monitoring Use Cases

Browse a curated catalog of Splunk monitoring use cases. Agents search, filter, and recommend use cases by category, sourcetype, CIM model, compliance regulation, or MITRE ATT&CK technique — without touching your Splunk instance.


What It Does

The Splunk Monitoring Use Cases integration connects agents to a hosted catalog of Splunk use cases. Each use case describes a monitoring scenario — what data you need, which sourcetypes apply, what SPL to run, and which compliance or security frameworks it supports.

This is a read-only discovery tool. It does not execute SPL or connect to your Splunk instance. Use it alongside Splunk MCP when you want to find relevant monitoring use cases and then implement them in your environment.

Tool Capabilities

Use Case Discovery

  • Browse categories — list top-level categories and subcategories of monitoring use cases
  • Search use cases — find use cases by keyword, description, or tags
  • View use case details — get the full definition including required sourcetypes, SPL examples, data models, and related use cases

Data Source Mapping

  • Find by sourcetype — discover which use cases apply to a given sourcetype (e.g., linux:audit, pan:traffic)
  • Find by CIM model — see which use cases map to a specific CIM data model
  • Find by app — list use cases associated with a Splunk app

Compliance & Security Frameworks

  • List compliance regulations — browse supported regulatory frameworks (GDPR, PCI-DSS, HIPAA, SOX, NIST, and others)
  • Check compliance coverage — see which use cases satisfy requirements for a given regulation
  • Find compliance gaps — identify regulations with missing monitoring coverage based on your deployed use cases
  • View compliance sidecars — get detailed compliance metadata for individual use cases

MITRE ATT&CK

  • MITRE coverage map — see which ATT&CK techniques and tactics are covered by catalog use cases
  • D3FEND mapping — view defensive technique mappings for use cases

Equipment & Scorecard

  • Browse equipment — list monitored equipment types and see which use cases apply to each
  • Scorecard — get a high-level summary of catalog coverage metrics

Data Sizing

Estimate Splunk ingest volume, storage requirements, and license tiers using a built-in reference catalog of 206 source profiles across nine categories (Security, IT, OT, Network, Protocols, Business, Cisco Products, OT Vendor Systems, and OT Hardware). No live Splunk connection required — all sizing data is embedded offline.

  • Browse sizing categories — list the nine categories with subcategory rollups and source counts
  • Search sizing sources — find source profiles by keyword, category, or source type
  • View source details — see low, typical, and high EPS and byte-per-event ranges for any source
  • Estimate ingest volume — compute average and peak GB/day, total EPS, raw and compressed storage, and recommended license tier for a deployment plan
  • Recommend license tier — map a known peak GB/day value to the appropriate Splunk license tier
  • Map equipment to sources — convert equipment or vendor identifiers to sizing source IDs
  • Map use cases to sources — convert Splunk UC catalog IDs to sizing source IDs

Sizing estimates support both endpoint-typed sources (firewalls, hosts, IDS sensors — sized by endpoint count and EPS profile) and protocol-typed sources (Modbus, OPC UA, MQTT, SNMP — sized by tag count and poll interval). Default parameters (90-day retention, 1.3× burst factor, 0.5 compression ratio) can be overridden per estimate.

Results are community reference defaults for planning conversations. Measured collector telemetry and current license usage should always take precedence before production purchasing decisions.

Use Cases

  • "What monitoring use cases exist for Linux audit logs?"
  • "Which use cases help me meet GDPR requirements?"
  • "Show me MITRE ATT&CK coverage gaps in my monitoring"
  • "Find all use cases that use the Authentication CIM data model"
  • "What Palo Alto firewall monitoring scenarios are available?"
  • "How much data will 10 Palo Alto firewalls generate per day?"
  • "Size a Splunk deployment for our SOC with 50 endpoints, 4 firewalls, and a SIEM"
  • "What license tier do I need for 200 GB/day peak ingest?"

Setup

  1. Go to SettingsIntegrations.
  2. Add the Splunk Monitoring Use Cases integration.
  3. Save — no configuration fields are required.

The integration connects to a hosted catalog API. Attach it to any agent, or use the purpose-built Splunk UC Catalog agent, which comes pre-configured with this integration.

Pairing with Splunk MCP

The catalog tells you what to monitor. Splunk MCP lets you implement it. A typical workflow:

  1. Ask the Splunk UC Catalog agent to find use cases for your data sources
  2. Review the recommended use cases and their SPL examples
  3. Switch to an agent with Splunk MCP (e.g., Search Ninja) to implement the monitoring in your environment