Cisco Cloud Control Canvas

 
Updated July 23, 2026
PDF
Is this helpful? Feedback

AI Canvas

AI Canvas is an immersive, full-screen workspace designed for complex, exploratory, multi-step workflows that span across domains and timelines.

Unlike traditional data tools, AI Canvas emphasizes a collaborative, generative UI environment powered by Cisco’s Deep Network Model—the most advanced networking LLM. This allows teams to orchestrate tasks, query data across Cisco products, and resolve issues using Runbooks, Product Intents, and Generative cards.

Ideal use cases include:

  • Cross-domain incident investigation

  • Multi-hop troubleshooting

  • Root cause analysis

  • SLA compliance validation

  • Configuration baseline comparisons

  • Collaborative case handoffs

AI Assistant

AI Assistant is an embedded interface that supports operators in performing single-turn or short, focused tasks such as lookups, validations, or actions within the context of a product.

Cisco Cloud Control Assistant is designed for individual use, operates within the product’s UI, and provides quick results using text responses or simple widgets. It retains chat history but does not support real-time collaboration.

While AI Assistant operates within the product, it is designed to access data across multiple Cisco products as shared orchestration frameworks evolve. Therefore, data access scope does not distinguish AI Assistant from AI Canvas.

AI Assistant is best suited for

  • short, single-turn tasks with well-defined scopes

  • situations where direct text or simple visual answers are sufficient, and

  • product-specific workflows that do not require data correlation across time or systems.

Here are some examples of ideal use cases:

  • Alert interpretation: "What does this alert mean?"

  • Performance summarization: "How is my network performing today?"

  • Configuration guidance: "How do I enable AI-RRM on a Catalyst switch?"

  • Change visibility: "What changed in my firewall rules yesterday?"

  • Threat enrichment: "Is this IP address suspicious?"

  • Troubleshooting guidance: "Why did this Webex meeting fail?"

AI Canvas vs AI Assistant

The following points summarize the key differences between AI Assistant and AI Canvas.

  • Task duration

    • AI Assistant

      • Single-turn, short interactions

    • AI Canvas

      • Multi-turn, extended workflows

  • Response format

    • AI Assistant

      • Text-based responses or lightweight UI elements

    • AI Canvas

      • Rich visualizations and interactive widgets

  • Data sources

    • AI Assistant

      • Single-product context (currently)

      • Multiproduct support planned in future roadmap

    • AI Canvas

      • Multiproduct telemetry and historical data correlation

  • User collaboration

    • AI Assistant

      • Individual use only

      • No real-time collaboration

    • AI Canvas

      • Multiuser collaboration and shared investigations

      • Supports team handoffs

  • Context persistence

    • AI Assistant

      • Chat history only

    • AI Canvas

      • Full workspace state, artifacts, and investigation context retained

  • Time-based analysis

    • AI Assistant

      • Focused on current-state queries

    • AI Canvas

      • Supports historical trends and time-series analysis

  • Visual complexity

    • AI Assistant

      • Simple charts and inline displays

    • AI Canvas

      • Complex multi-panel dashboards and topology visualizations

  • Workflow type

    • AI Assistant

      • Direct question-and-answer interactions

    • AI Canvas

      • Exploratory investigations and collaborative analysis

Get started with AI Assistant

Use AI Assistant to ask questions, investigate issues, and work more quickly across Cisco Cloud Control.

AI Assistant use cases

The following examples describe common AI Assistant use cases and why they are effective.

  • Checking system status

    • A single response provides the required information

    • No follow-up investigation is typically needed

  • Understanding alerts

    • Direct explanations help users quickly understand the issue

    • Enables immediate troubleshooting or remediation

  • Getting configuration guidance

    • Step-by-step instructions can be delivered in a single response

    • Useful for operational and onboarding workflows

  • Reviewing recent changes

    • A concise list of changes with timestamps provides sufficient visibility

    • Helps identify recent modifications quickly

  • Checking security threats

    • Binary assessment with contextual information supports rapid decision-making

    • Helps determine whether immediate action is required

AI Assistant use case examples

These examples show common AI Assistant prompts and expected responses. Unlike Canvas workflows, responses are typically self-contained and do not require additional navigation.

  • Alert interpretation

    • Query: "What does this alert mean?"

    • Assistant Response: "This is a critical alert triggered by memory utilization exceeding 95 percent on switch CAT9300-01. The device has been in this state for 12 minutes. Recommended action: Check for memory leaks in running processes or consider upgrading memory modules."

    • Next Steps: No additional action required to interpret the alert. The user can proceed directly with troubleshooting.

  • Performance summarization

    • Query: "How is my network performing today?"

    • Assistant Response: Displays an inline KPI summary including:

      • Network Health: 96%

      • Average Latency: 28 ms

      • Packet Loss: 0.02%

      • 3 sites experiencing minor issues

    • Assistant Response also includes links to detailed reports.

    • Next Steps: Users can investigate affected sites if needed, while still receiving an immediate high-level summary.

  • Threat enrichment

    • Query: "Is this IP address suspicious?"

    • Assistant Response: "IP 192.168.100.45 flagged as HIGH RISK by Cisco Talos. Associated with the Emotet malware family, last seen targeting financial institutions in the first quarter of 2025. Confidence: 94%. Block recommendation: Immediate."

    • Next Steps: Users can immediately block the IP address or continue investigating based on the provided threat assessment.

Guidelines and limitations

You can use ssistant for Security Cloud Control documentation queries only in this release.

Key behaviors

  • Canvas-specific sessions: Each chat thread is associated with the specific canvas you are working on and switching to a different canvas starts a new chat session with its own context. This helps keep investigations, conversations, and generated outputs organized by workspace

  • Assistant-to-Canvas context continuity: You can move from the Assistant into a canvas without losing the current conversation context. The Assistant retains the existing conversation and investigation history within the canvas. This enables seamless transition from chat-based interactions to collaborative canvas workflows

  • Error handling: If a query fails (for example, due to a task execution failure or system limits), the AI Canvas Assistant displays an error message directly in the chat. This helps you understand what went wrong and how to address it.

  • Context awareness: The AI Canvas Assistant understands the context of the canvas you are working on, including tasks, cards, and runbooks. Based on this context, it can suggest next steps or link directly to relevant items on the canvas.

  • Private assistant sessions: You only see the assistant conversations from your own session. Assistant chats from collaborators working on the same canvas are not visible to you.

Use Assistant

To open AI Assistant, use one of these options:

  • On the Cisco Cloud Control Home page, click the Assistant tab.

  • Outside the Cisco Cloud Control Home page, click Assistant in the top navigation bar.

After the Assistant window opens, choose from several options to get started:

  • Selecting threads

    • Use New Thread to start a new conversation

    • Select a previous thread to continue an existing conversation

  • Predefined questions

    • Click a predefined question to quickly get started

  • Free-form queries

    • Type your query in the chat field to start a conversation tailored to your specific use case

  • Collaborate with team

    • Click Create canvas to collaborate with others in a shared workspace. When a conversation is associated with a canvas, the c3-canvas-icon.jpg icon appears next to it.

  • Display preferences

    • Set how the Assistant window appears:

      • Full screen

      • Docked

      • Floating

      • New tab

Get started with AI Canvas

AI Canvas includes a fully integrated Assistant with a Prompt library. You can use the Assistant to orchestrate tasks and retrieve data from multiple products using shared skills. You can collaborate, manage time-based workflows, and work in a generative UI environment. These features are prioritized over data scope.

AI Canvas supports:

  • Multi-user collaboration — multiple people can work in the same session

  • Persistent task contexts — tasks and context saved across time

  • Rich visualizations — cards and charts that provide insights

note.svg

AI Canvas follows the access permissions already assigned to your Cisco Cloud Control account. You can view and interact only with the products, data, and environments you already have access to. For investigations that span multiple products or domains, access must be available across all relevant environments so the assistant can correlate data and perform end-to-end analysis.


Prompt library in AI Canvas

The prompt library provides suggested prompts that help you get started with AI Canvas and AI Assistant across your Cisco Cloud Control environment. Prompts are organized by category are designed to show common ways you can ask questions, explore product data, and get insights from multiple Cisco products in one place.

Prompts are organized into six cross-domain categories that are consistent for every user, regardless of which products they are entitled to. The categories are:

  • Health & Availability — Overall system health, uptime, and readiness

  • Performance & Observability — Latency, throughput, quality metrics, and trends

  • Incidents, Anomalies & Outages — Active alerts, detected anomalies, and diagnostics

  • Connectivity, Paths & Topology — Network paths, tunnel status, and topology visualization

  • Security, Policy & Access — Security events, access policies, and compliance posture

  • Configuration, Change & Inventory — Config changes, software versions, and device inventory

note.svg

The prompts displayed change dynamically based on the products you have access to.


AI Canvas capabilities

AI Canvas is designed for complex, multi-step operational workflows. Powered by the Cisco Deep Network Model, it helps teams collaborate, orchestrate cross-product tasks, and resolve incidents efficiently. With runbooks, product intents, and interactive generative cards, teams can troubleshoot incidents, drive actionable results, and move from insights to actions in a shared workspace.

Key capabilities include:

  • Cross-Domain Incident Investigation:: Rapidly correlate telemetry across infrastructure silos. Example: "Show me everything affecting performance at Site A today."

  • Multi-Hop Troubleshooting:: Identify bottlenecks across complex network paths. Example: "Why is voice quality poor between our Los Angeles and New York City offices?"

  • Root Cause Analysis:: Perform forensic diagnostics on past events with persistent context. Example: "Investigate the security incident from last Tuesday."

  • SLA Compliance Validation:: Automate reporting and verification of service level agreements. Example: "How did we perform against our 99.9% uptime commitment this quarter?"

  • Configuration Baseline Audits:: Ensure consistency and compliance across distributed device fleets. Example: "Compare firewall configurations across all branch offices."

  • Collaborative Case Handoffs:: Seamlessly transition investigations between team members using shared, persistent task states.

AI Canvas use cases

  • Investigating issues across multiple systems: Requires correlation across disparate data sources and visual analysis.

  • Finding the root cause of problems: Needs timeline correlation, multiple data views, and hypothesis testing.

  • Analyzing performance over time: Relies on historical analysis and visual comparisons.

  • Working with team members on the same issue: Facilitated by shared workspaces and seamless context handoffs.

  • Troubleshooting complex multi-step problems: Supports multi-step processes with branching investigation paths.

  • Creating compliance and audit reports: Leverages data aggregation, visualization, and automated report generation.

AI Canvas use case examples

Here are examples of common AI Canvas use case prompts and their expected results. These use cases start as simple Assistant queries and evolve into multi-step, highly visual tasks requiring persistent workspace, multi-modal input/output, and collaboration.

Cross-domain incident investigation

  • Intent

    • Cross-domain incident investigation

  • Query

    • "Show me everything affecting Site A performance today"

  • AI Canvas response

    • AI Canvas opens with a multi-panel investigative workspace

    • Network topology widget highlights affected links in red

    • Timeline chart shows performance degradation starting from 2 p.m.

    • Correlation matrix links:

      • ThousandEyes path data

      • Meraki device health

    • Alert timeline indicates cascading failures across systems

  • Next steps

    • Drill down into specific time windows

    • Compare current performance with historical baselines

    • Invite network and security teams to collaborate

    • Continue investigation with shared context

Multi-hop troubleshooting

  • Intent

    • Multi-hop network troubleshooting

  • Query

    • "Why is voice quality poor between our Los Angeles and New York City offices?"

  • Canvas response

    • Interactive path visualization showing all network hops

    • Mean Opinion Score (MOS) displayed per hop

    • Latency heat map across time periods

    • Jitter and packet loss graphs for each segment

    • Side-by-side comparison:

      • Current performance

      • Baseline performance

    • Automated runbook suggests next diagnostic steps

  • Next steps

    • Execute suggested diagnostics

    • Identify problematic hops

    • Adjust Quality of Service (QoS) policies

    • Document findings for future reference

Collaborative case handoffs

  • Intent

    • Collaborative troubleshooting and case continuity

  • Query

    • Engineer leaves Canvas with investigation context saved

  • Canvas response

    • Next user sees:

      • Previous investigation steps

      • AI-generated summaries

      • Current case status

    • Case summary widget includes full investigation context

    • Annotated network diagrams with troubleshooting notes

    • Action items tracker with pending tasks

  • Next steps

    • Field team continues investigation seamlessly

    • Work resumes from last known state

    • Case status is updated as progress is made

    • Collaboration continues across teams without loss of context

Use AI Canvas

To get started, create your first canvas, connect your data sources, and experiment with canvases and cards.

  • Log in to the Cisco Cloud Control UI

  • Open AI Canvas:

    • On the Cisco Cloud Control Home page, click the Canvas

    • Outside the Cisco Cloud Control Home page, click Canvas in the top navigation bar to open the AI Canvas overview

  • From the AI Canvas overview, you can:

    • Select a prompt category

    • Create a workspace from the board library

    • Click Create canvas to create a new canvas

    • Open an existing canvas

  • Select a conversation mode:

    • Default: Responds immediately to queries

    • Reasoning: Intended for more complex or multi-step queries

After the Canvas screen opens, you can choose from several options to interact with your workspace:

  • Canvas options

    • You can:

      • Rename the current canvas

      • Duplicate the canvas

      • Archive the canvas

      • Delete the canvas

  • Query prompt

    • Ask questions or query for information within the current canvas

  • Generate report

    • Generate a full report of activity within the current canvas

  • View activity

    • View the history of major user actions performed in the current canvas

  • Share

    • Export and share the current canvas with other collaborators

  • Auto layout

    • Automatically arranges workspace elements within the canvas

  • Stack cards

    • Groups related data cards together to optimize workspace organization

  • Add image

    • Upload images to provide visual context during troubleshooting and investigations

    • Supported image formats:

      • JPG

      • PNG

    • Image upload limits:

      • Maximum file size: 5 MB per image in chat

      • Maximum of 4 uploaded files or images per conversation

      • Images uploaded directly from the board side panel support a maximum size of 500 KB

  • Add text annotation

    • Add notes, labels, or contextual comments to the canvas

  • Lock cards

    • Prevent accidental movement or modification of cards and placed items

  • Generate summary

    • Create a concise overview of the current canvas content and activity

  • View activity log

    • Open a detailed log of changes and actions performed within the canvas

  • Show minimap

    • Toggle a navigation overview window for easier workspace navigation

    • Disabled by default to reduce visual clutter

  • Collapse

    • Hide the menu to maximize available workspace area

note.svg

Widgets in AI Canvas are interactive and support drill-down exploration. You can select items within a widget to view additional details and related data. For example, selecting a network in a widget can display connected clients, associated alerts, device health, or related telemetry.


Use prompt library

You can access the prompt library directly in the chat.

  • Type "/" in the chat input to open the prompt library.

  • Select from the available categories and prompts in the dropdown menu without leaving the conversation.

AI Assistant in Canvas

The AI Assistant preserves conversation context when you move into AI Canvas, allowing you to continue investigations and collaboration without restarting your workflow. Previous prompts, responses, and investigation details remain available within the canvas so you can continue building on earlier analysis.

The assistant in AI Canvas supports:

  • Default mode

    • Designed for quick, direct queries that require minimal analysis

    • Best for simple tasks such as listing networks, clients, devices, alerts, or inventory

    • Returns responses immediately so you can move efficiently through routine operational tasks

  • Reasoning mode

    • Designed for advanced troubleshooting and investigative workflows

    • Breaks down complex requests into multiple investigative steps

    • Uses product knowledge, documentation, and operational best practices to guide analysis

    • Can correlate telemetry and insights across multiple domains and products

    • Helps identify patterns, gather supporting evidence, and determine potential root causes

  • Add file

    • Upload supporting files to provide additional context for investigations and analysis

    • Supported file formats:

      • PDF

      • TXT

      • MD

      • DOCX

    • File upload limits:

      • Maximum file size: 5 MB per file

      • Maximum of 4 uploaded files or images per conversation

Knowledge base

  • Upload or select reference documents the assistant can use during troubleshooting and analysis workflows.

  • Add operational resources such as runbooks, policies, network standards, maintenance procedures, vendor guidance, and reference documentation.

  • Knowledge bases persist across conversations, canvases, and investigation sessions.

  • Select relevant knowledge artifacts at the start of a conversation to provide additional organizational and operational context.

  • Helps the assistant reference internal workflows, operational guidance, historical incidents, and best practices during analysis and troubleshooting.

  • Knowledge artifacts are shared across users with access to the same environment, helping teams collaborate using a common operational knowledge set.

Multimodal input
  • Upload files or images to provide additional context during investigations and troubleshooting workflows.

  • Common examples include screenshots, vendor maintenance notices, troubleshooting documents, exported reports, and operational references.

  • Uploaded files remain associated with the current conversation thread so they are available when you return to the investigation.

  • Supported file and image uploads are limited to a maximum of 4 items per user query.

Knowledge base example prompts
  • Prompt: "Our Shanghai WAN circuit is showing high latency right now — has this happened before and who should I contact?"

    • Helps correlate current operational issues with historical incidents and operational ownership information

  • Prompt: "Which of our data center networks have had outages, and do any of them lack ISP redundancy?"

    • Helps combine operational history with infrastructure design and resiliency information

  • Prompt: "I need to plan a network change at our Chicago Post Office — when’s the maintenance window, who’s the site lead, and have there been any recent incidents I should know about?"

    • Helps correlate operational schedules, ownership details, and recent incident history for change planning

Multimodal input example prompts
  • Prompt: "This maintenance notice from Comcast says they’re doing work on Saturday — which of my networks will be affected and do they have backup circuits?"

    • Helps correlate uploaded maintenance notices with your operational environment and network topology

  • Prompt: "I’m seeing the same symptoms described in this TAC case — walk me through the resolution steps applied here and tell me which ones apply to my current situation."

    • Helps compare uploaded troubleshooting documentation against active issues and identify relevant remediation steps

Collaboration on Canvas

Roles

There are two primary roles for collaborators in Canvas.

  • Owner: User who created the canvas is the default owner. Owner has full control over the canvas, including settings, permissions, and collaborator management.

  • Editor: Anyone who joins a canvas through a shared link becomes an editor. Editors can view and modify the canvas content, such as adding, editing, and rearranging cards, but they do not have the same level of control over settings and access.

Sharing a canvas

You can get a link that enables collaborators to edit a canvas. Anyone with this link is automatically granted editor rights.

Follow these steps to share a canvas.

  1. Click Share in the top-right corner of your canvas and then select Invite collaborators.

  2. Click copy invite link. This generates a unique shareable link.

  3. Share this link with your collaborators.

Owner controls

The owner retains advanced permissions and can:

  • Transfer Ownership:

    • Owners can assign ownership of the canvas to another collaborator if needed (e.g., handing over a project to a different lead).

    • Once ownership is transferred, the new Owner gains full rights, and the previous Owner becomes an Editor.

  • Remove Collaborators:

    • Owners can revoke access for specific users.

    • This immediately removes the collaborator’s ability to view or edit the canvas, even if they previously had the shared link.

  • Collaboration Behavior: These Canvas behaviors apply when users collaborate.

    • Collaborators see board-level changes instantly, such as when someone adds a text card, moves a card, or when someone else’s Canvas Assistant chat outputs a new card on to the canvas. Collaborators do not see each other’s chat assistants but can ask questions about cards other assistants generated by highlighting the card (clicking it) and asking in their own assistant panel

    • Canvas saves edits automatically, which maintains context and history across sessions.

    • The activity timeline captures changes, such as renames, additions, and deletions, so that teams can track updates over time.

note.svg

You can gain visibility into the connected products and MCP (Model Context Protocol) servers associated with your workspace.


Actions

Use the Actions tab to review investigations, alerts, and operational issues that require attention across your Cisco Cloud Control environment.

You can access actions from:

  • Actions tab

  • your Canvas

  • Notifications

When you open your Canvas from an action, the associated investigation context is preserved automatically. This allows you to continue troubleshooting, analysis, and remediation workflows without restarting the investigation.

Actions also enable you to perform follow-up tasks directly from ongoing investigations, helping streamline operational workflows and collaboration.

Best practices for writing prompts

Prompt structure plays an important role in the quality of AI Canvas responses.

Specific and well-scoped prompts help:

  • improve response precision

  • reduce unnecessary results

  • provide faster and more actionable insights

Core prompting principles

Be specific about scope Always define:

  • what you are investigating

  • where (site, device, client)

  • when (time range)

Example

  • Bad: "Why is the network slow?"

  • Better: "Investigate latency issues for my network."

Include context explicitly

The assistant relies on available context, but adding detail improves accuracy. Include:

  • site / network name

  • device or client identifiers

  • timeframe

  • issue type

Ask for actionable outputs

Instead of general questions, ask for:

  • root cause

  • recommendations

  • next steps

Example

  • Confusing: "What is happening here?"

  • Better: "Identify the root cause of packet loss and recommend next steps to resolve it."

Break complex queries into steps

For multi-layer investigations, use multiple prompts instead of one large query.

Example flow

  1. Identify affected clients

  2. Analyze device health

  3. Correlate with WAN metrics

Structured prompt framework (RT-CCO)

Use this framework for high-quality prompts:

  1. Role - Who the AI should act as

  2. Task - What you want it to do

  3. Context - Relevant background or data

  4. Constraints - Limits or instructions

  5. Output Format - Desired structure of response

Example "Act as a Senior Network Engineer. Analyze the interface errors on Switch-01 (Context) for the last 2 hours (Timeframe). Provide a summary of the root cause and a list of remediation steps (Output Format)."

Prompt structure template

Use [Action] + [Object] + [Scope] + [Timeframe] + [Expected Output] prompt structure.

Example

"Compare [CPU utilization] + [on Core-Router-A] + [across the last 24 hours] + [and list any anomalies found]."

Common use cases and example prompts

  • Troubleshooting:

    • Prompt: "Analyze the flapping status of the uplink interface on Site-A-Gateway over the last 6 hours."

  • Capacity Planning:

    • Prompt: "Provide a trend analysis of bandwidth usage for the Guest Wi-Fi network over the past 7 days."

Writing effective prompts

Do Don’t

Use clear, concise language

Use vague terms like “issue” or “problem”

Specify scope and timeframe

Ask multiple unrelated questions in one prompt

Ask for actionable insights

Assume missing context

Use consistent naming (sites, devices)

Overload the prompt with unnecessary detail

Context and limitations

  • The assistant uses available canvas context (cards, data sources, prior prompts).

  • Responses depend on:

    • selected network/site

    • available telemetry

    • time range

    If results seem incorrect:

    • refine the scope

    • add missing context

    • break the query into smaller steps

  • When a prompt for a subjective task (for example, "Allow smith access to jira") triggers an authentication failure, the session can become locked. Even after the authentication issue is resolved, the assistant continues to display the error, preventing further task execution.

    Workaround: To resolve this, open a duplicate session in a new tab to re-initiate the request. This clears the previous error state and allows the system to process the task successfully.

  • When querying for server inventory (for example, "Summarize rack vs blade counts"), the AI Canvas may generate widgets with empty tables, despite successfully retrieving the total count.

    Workaround: Try rephrasing the prompt to request specific attributes (for example, "List the names and models of blade servers") or ask the query again to trigger a fresh retrieval.

Optimized prompts for integrated products

To obtain the best results from the AI Canvas, tailor your prompts to the telemetry and data models of your integrated platforms. While general questions provide broad information, platform-specific scenarios allow the AI Canvas to:

  • Leverage domain expertise: Apply platform-specific logic (for example, Meraki’s RF metrics or ThousandEyes' path analysis) to your query.

  • Reduce noise: Use platform-specific filters to narrow down thousands of events to the most relevant, actionable insights.

  • Bridge data gaps: Correlate identity, security, and network telemetry by explicitly referencing the relationships between components (for example, linking a server profile to a storage drive failure).

The following sections provide proven prompt structures. Use these templates to transform vague requests into precise, diagnostic-grade queries.

Meraki prompts

  • Network overview

    • Prompt: "How is my organization doing?"

    • Why it works:

      • Provides a high-level operational summary across the environment

    • Insights provided:

      • Highlights overall network health

      • Helps quickly identify whether immediate investigation is required

  • Critical alerts

    • Prompt: "Are there any critical alerts?"

    • Why it works:

      • Focuses attention on high-priority operational issues

    • Insights provided:

      • Surfaces active alerts requiring immediate action

      • Helps prioritize troubleshooting efforts

  • WAN port utilization

    • Prompt: "Show my WAN port utilization."

    • Why it works:

      • Helps identify bandwidth saturation and traffic spikes

    • Insights provided:

      • Highlights heavily utilized WAN interfaces

      • Helps detect congestion or abnormal traffic patterns

  • WAN port status

    • Prompt: "Show my WAN port status."

    • Why it works:

      • Provides visibility into WAN connectivity health

    • Insights provided:

      • Identifies disconnected or degraded WAN links

      • Helps verify circuit availability

  • Security Events

    • Prompt: "What security events happened in my network in the past day?"

    • Why it works:

      • Focuses on recent security-related activity

    • Insights provided:

      • Surfaces suspicious or high-priority security events

      • Helps identify emerging threats

  • Top Utilized Clients

    • Prompt: "Show me the top utilized clients."

    • Why it works:

      • Helps identify devices consuming excessive bandwidth

    • Insights provided:

      • Highlights heavy network consumers

      • Helps investigate performance degradation caused by client activity

  • Client VPN Visibility

    • Prompt: "Who is connected to the client VPN?"

    • Why it works:

      • Provides visibility into remote access activity

    • Insights provided:

      • Identifies active VPN users

      • Helps monitor remote connectivity usage

ThousandEyes prompts

  • Outage detection and service disruptions

    • Prompt: "Are there any outages affecting my monitored services right now?"

    • Why it works:

      • Outages can be localized, regional, or global in scope

      • Geographic context helps distinguish backbone internet issues from local site problems

    • Insights provided:

      • Identifies impacted services and affected locations

      • Helps determine whether the issue originates within the enterprise, ISP, or external provider network

  • Network path analysis

    • Prompt: "Show me the network path visualization for my monitored tests."

    • Why it works:

      • Network path analysis requires visibility into multiple providers and transit points

      • Isolating problematic ISP hops or AS paths accelerates root cause analysis

    • Insights provided:

      • Displays traffic flow and network path behavior

      • Helps identify packet loss, latency, or failures across provider hops

  • Anomaly detection

    • Prompt: "Are there any anomalies in my ThousandEyes tests?"

    • Why it works:

      • Anomalies are meaningful only when compared against historical baselines

      • Historical comparison helps identify true operational deviations

    • Insights provided:

      • Highlights abnormal latency, packet loss, or performance degradation

      • Helps identify emerging operational problems before outages occur

  • Test management and status

    • Prompt: "What ThousandEyes tests are currently running?"

    • Why it works:

      • Test execution alone does not confirm test health or successful telemetry collection

      • Focusing on failing or degraded tests provides more actionable operational insight

    • Insights provided:

      • Displays active test status and operational health

      • Helps identify silent failures or telemetry collection problems

  • Performance metrics and trends

    • Prompt: "What are the current latency and packet loss metrics for my critical tests?"

    • Why it works:

      • Raw metrics can be difficult to interpret at scale

      • Comparative analysis and prioritization improve operational visibility

    • Insights provided:

      • Highlights regions, providers, or services with poor performance

      • Helps prioritize optimization and troubleshooting efforts

Nexus Dashboard prompts

  • Fabric health overview

    • Prompt: "Is my data center fabric healthy right now?"

    • Why it works:

      • Provides an immediate operational health assessment of the data center fabric

    • Insights provided:

      • Highlights active issues impacting the fabric

      • Helps determine whether immediate investigation is required

  • Fabric health summary

    • Prompt: "Give me an overall health summary of my data center fabrics."

    • Why it works:

      • Consolidates multiple health indicators into a single high-level summary

    • Insights provided:

      • Provides visibility into overall fabric stability and operational status

  • Critical fabric issues

    • Prompt: "Are there any critical issues across my data center fabrics?"

    • Why it works:

      • Focuses attention on high-priority operational risks

    • Insights provided:

      • Identifies critical failures or degraded components requiring immediate remediation

  • Components requiring attention

    • Prompt: "Which fabric components need attention today?"

    • Why it works:

      • Helps prioritize operational tasks and remediation efforts

    • Insights provided:

      • Highlights switches, links, or services showing degraded health or alerts

  • Multi-fabric overview

    • Prompt: "Show me a health overview of all fabrics managed by Nexus Dashboard."

    • Why it works:

      • Simplifies visibility across multiple managed environments

    • Insights provided:

      • Provides centralized operational awareness across fabrics

Nexus Hyperfabric prompts

  • Fabric discovery and inventory

    • Prompt: "Show me all devices discovered in my Nexus Hyperfabric organization."

    • Why it works:

      • Broad inventory requests can generate large and difficult-to-read results

      • Narrowing the request helps AI focus on the most relevant operational data

    • Insights provided:

      • Displays discovered devices in a more structured and actionable format

      • Helps simplify inventory visibility and operational review

  • Connectivity diagnostics

    • Prompt: "Are any devices in my fabric unable to communicate?"

    • Why it works:

      • Focuses the analysis on endpoints experiencing connectivity problems

      • Enables AI to perform targeted connectivity and path validation checks

    • Insights provided:

      • Identifies communication failures between devices

      • Helps isolate routing, forwarding, or connectivity issues

  • End-to-end reachability and toubleshooting

    • Prompt: "Are there any reachability issues between endpoints in my fabric?"

    • Why it works:

      • Reachability issues often require deeper analysis than simple connectivity checks

      • Encourages AI to evaluate routing paths, VRFs, and forwarding behavior

    • Insights provided:

      • Helps identify routing or segmentation issues impacting endpoint communication

      • Improves troubleshooting accuracy across the fabric

  • Endpoint search

    • Prompt: "Show me all endpoints currently connected to my fabric and their locations."

    • Why it works:

      • Endpoint visibility is essential for operational and physical troubleshooting

      • Location-aware endpoint information makes results more actionable

    • Insights provided:

      • Displays connected endpoints and their attachment locations

      • Helps identify endpoint placement and physical connectivity relationships

  • Fabric topology and device status

    • Prompt: "Show me the topology of my Nexus Hyperfabric deployment."

    • Why it works:

      • Topology visibility improves infrastructure understanding and troubleshooting efficiency

    • Insights provided:

      • Displays device relationships and fabric structure

      • Helps validate deployment architecture and operational health

  • Fabric capacity planning

    • Prompt: "Can I add any connections to my fabrics?"

    • Why it works:

      • Capacity planning requires understanding available resources and topology constraints

      • Detailed prompts allow AI to evaluate switch and port availability more accurately

    • Insights provided:

      • Identifies available connectivity capacity across the fabric

      • Helps validate whether additional connections can be supported

      • Highlights switchports or infrastructure limitations impacting expansion

Intersight prompts

  • Compute inventory

    • Prompt: "Which servers are running the oldest firmware version?"

    • Why it works:

      • Firmware consistency is important for maintaining security and performance

    • Insights provided:

      • Identifies potential vulnerabilities and compatibility risks

      • Helps prioritize firmware and hardware updates

  • Storage health

    • Prompt: "Are there any storage drives in a degraded or failed state?"

    • Why it works:

      • Storage failures can result in data loss or application downtime

    • Insights provided:

      • Identifies degraded or failed storage components

      • Helps prioritize remediation before failures impact workloads

  • Network adapter status

    • Prompt: "List all servers with inactive or disconnected network adapters."

    • Why it works:

      • Network adapter issues can lead to connectivity and service disruptions

    • Insights provided:

      • Highlights configuration or connectivity issues requiring immediate attention

  • Audit and change tracking

    • Prompt: "Who made changes to my server profiles in the last 24 hours?"

    • Why it works:

      • Understanding what changed and who made the change is critical for troubleshooting and remediation

    • Insights provided:

      • Provides an accountability trail

      • Helps correlate recent configuration changes with operational issues

  • Hardware health overview

    • Prompt: "Give me an overall health summary of my compute infrastructure."

    • Why it works:

      • Provides you with an at-a-glance operational summary

    • Insights provided:

      • Delivers a high-level view of infrastructure health

      • Helps identify systemic issues requiring immediate attention

Secure Access prompts

  • Supported identifiers

    • Name or email address

    • Private resource

      • Example: "Finance-App"

    • Device name (optional)

      • Example: "john doe desk pro"

    • Access method (optional)

      • Example: "VPN" or "ZTNA"

  • Access troubleshooting

    • Prompt: "Why can’t John Doe access Finance-App?"

    • Why it works:

      • The assistant performs multiple validation checks across the user, device, network, and destination resource to narrow the scope of the issue.

      • Instead of checking a single policy or event, the assistant correlates data across several components involved in the access request.

    • Insights provided:

      • Resource reachability validation

      • Network connectivity checks

      • Policy evaluation and enforcement results

      • DNS resolution status

      • Device enrollment and posture validation

      • User access analysis to determine whether the user can access other applications

      • Application access analysis to determine whether other users can access the same resource

      • Network connectivity and system resource checks for environments integrated with ThousandEyes

Firewall prompts

  • VPN tunnel status

    • Prompt: "What is the current status of all my site-to-site VPN tunnels?"

    • Why it works:

      • Provides an immediate, high-level health check of the VPN environment

    • Insights provided:

      • Identifies which tunnels are active versus inactive

      • Helps enable rapid triage before users report connectivity issues

  • VPN diagnostics and investigation

    • Prompt: "Are there any IKE negotiation failures on my VPN tunnels?"

    • Why it works:

      • IKE (Internet Key Exchange) negotiation failures are a common VPN issue

    • Insights provided:

      • Helps isolate authentication or parameter mismatch problems

      • Reduces time spent troubleshooting unrelated physical or routing issues

  • VPN tunnel stability

    • Prompt: "Which tunnels have had the most disruptions this month?"

    • Why it works:

      • Shifts focus from current status to recurring operational issues

    • Insights provided:

      • Helps identify unstable or flapping tunnels

      • Can reveal ISP instability, hardware degradation, or persistent configuration issues

  • VPN knowledge and best practices

    • Prompt: "What are the best practices for site-to-site VPN configuration?"

    • Why it works:

      • Encourages proactive optimization instead of reactive troubleshooting

    • Insights provided:

      • Helps ensure configurations align with security best practices

      • Can reduce future vulnerabilities and performance bottlenecks

SD-WAN prompts

  • Network and application health overview

    • Prompt: "Give me a summary of my network and application health."

    • Why it works:

      • High-level prompts provide a quick operational snapshot of overall network conditions

      • Helps quickly determine whether issues exist before investigating specific areas

    • Insights provided:

      • Overall health indicators across sites and WAN links

      • Summary of application performance across the SD-WAN network

      • Identification of degraded links, sites, or applications requiring further investigation

  • WAN bandwidth and utilization analysis

    • Prompt: "Can you show the Rx/Tx bandwidth rates, utilization, and peak usage for all my WAN links?"

    • Why it works:

      • Monitoring utilization helps identify congestion and capacity limitations impacting application performance and user experience

      • Rx/Tx bandwidth visibility helps identify asymmetric traffic patterns

      • Peak usage provides historical context beyond point-in-time metrics

    • Insights provided:

      • Current Rx and Tx bandwidth rates across WAN links

      • Utilization levels for each WAN circuit

      • Peak bandwidth usage and traffic spikes

      • Identification of congested or underutilized circuits

  • Application performance and SLA monitoring

    • Prompt: "How are my applications performing, and are there any SLA violations in my SD-WAN network?"

    • Why it works:

      • Application experience is a key indicator of overall network health

      • SLA violations highlight when network conditions impact application performance

      • Helps identify business-critical applications experiencing degraded performance

    • Insights provided:

      • Application latency, packet loss, and performance metrics

      • Applications experiencing SLA violations

      • Prioritization of remediation efforts for business-critical applications

  • Application usage visibility

    • Prompt: "What is the usage of applications in my SD-WAN network?"

    • Why it works:

      • Understanding application traffic distribution helps with capacity planning and policy optimization

      • Identifies applications consuming the most bandwidth across the network

    • Insights provided:

      • Application traffic distribution across the SD-WAN network

      • Top bandwidth-consuming applications

      • Application usage trends and traffic patterns

Collaboration Control Hub prompts

Webex Meetings prompts

The following prompts are examples of supported queries and supported identifiers for Meetings workflows.

  • Supported identifiers

    • Name or email address

    • Conference ID

      • Example: "710387709096844458"

    • Time range

      • Example: "last 7 days" or "26 March 2026"

    • Device name

      • Example: "john doe desk pro"

    • Workspace name

      • Example: "tokyo24-11-quiet room 6"

  • Poor quality meeting analysis

    • Prompt: "Show me poor quality meetings for user@company.com"

    • Why it works: Narrowing the query to a specific user helps isolate meeting quality issues and reduces unnecessary results.

    • Insights provided:

      • Identifies meetings with degraded audio or video quality

      • Highlights recurring user experience issues

      • Helps prioritize troubleshooting for affected users

  • Meeting attendance analysis

    • Prompt: "How many meetings did user@company.com attend in the last 7 days?"

    • Why it works: Combining a user identifier with a time range provides targeted participation analysis.

    • Insights provided:

      • Meeting participation trends

      • Usage activity over time

      • User engagement visibility

  • Meeting quality troubleshooting

    • Prompt: "Check user@company.com quality status for the last 3 days"

    • Why it works: Focusing on a recent timeframe helps identify ongoing or recurring quality problems.

    • Insights provided:

      • Audio and video quality trends

      • Recent degradation patterns

      • Potential recurring connectivity issues

  • Packet loss isolation

    • Prompt: "Was the packet loss on my side or the other participants in meeting 70826389765?"

    • Why it works: Isolating packet loss sources helps determine whether the issue originated locally or remotely.

    • Insights provided:

      • Source of packet loss

      • Participant-side versus local network issues

      • Faster root cause identification

  • Network troubleshooting

    • Prompt: "Troubleshoot network issue for John Doe in meeting 70826389765"

    • Why it works: Combining user and meeting identifiers enables deeper session-level analysis.

    • Insights provided:

      • Network quality indicators

      • Session-specific troubleshooting details

      • Potential connectivity bottlenecks

  • Meeting join analysis

    • Prompt: "Did any participants have issues joining meeting 70826389765 on time?"

    • Why it works: Join behavior analysis helps identify authentication, connectivity, or performance issues affecting meeting access.

    • Insights provided:

      • Delayed or failed joins

      • User onboarding problems

      • Meeting access patterns

  • Device-based meeting analysis

    • Prompt: "Analyze meetings in the last 7 days for device 'john doe desk pro'"

    • Why it works: Device-focused analysis helps determine whether quality issues are tied to a specific endpoint.

    • Insights provided:

      • Device-specific quality trends

      • Endpoint performance visibility

      • Hardware-related issue detection

  • Workspace meeting analysis

    • Prompt: "Tell me about the last meeting in the Tokyo-21 workspace"

    • Why it works: Workspace-focused queries provide operational visibility into shared meeting environments.

    • Insights provided:

      • Recent meeting activity

      • Workspace utilization details

      • Room-specific quality insights

Webex Calling prompts

The following prompts are examples of supported queries and supported identifiers for Calling workflows.

  • Supported identifiers

    • Name or email address

    • Phone number

      • Example: "+12345678900"

    • Correlation ID

      • Example: "4505c58b-e183-9e0d-9d16-587455d97487"

    • Call ID (case-sensitive)

      • Example: "sse0134213360303261757062387@10.192.72.201"

    • WXC Session ID

      • Example: "wxcsid_v7_4519447e-9505-4bkc-ad2l"

    • Time range

      • Example: "last 7 days" or "26 March 2026"

  • Poor quality call analysis

    • Prompt: "Show me calls with poor quality for John Doe"

    • Why it works: Filtering by user helps isolate calling issues to a specific endpoint or user experience.

    • Insights provided:

      • Calls with degraded quality

      • User-specific call performance

      • Trends in call reliability

  • Calling history analysis

    • Prompt: "Analyze user@company.com Webex Calling calls in the last 7 days"

    • Why it works: Combining a user identifier with a defined timeframe enables focused usage and quality analysis.

    • Insights provided:

      • Historical calling activity

      • Call quality trends

      • Usage visibility over time

  • Phone number search

    • Prompt: "Show me all calls from phone number +16693084178 in past 14 days"

    • Why it works: Phone-number-based searches simplify tracing communication activity across time periods.

    • Insights provided:

      • Call history visibility

      • Activity tracking

      • Communication pattern analysis

  • Correlation ID search

    • Prompt: "Search for calls with correlation id '4505c58b-e183-9e0d-9d16-587455d97487' going back 30 days"

    • Why it works: Correlation IDs allow precise investigation of specific call sessions and backend events.

    • Insights provided:

      • Detailed session-level troubleshooting

      • Event correlation visibility

      • Faster root cause investigation

  • Device-based call analysis

    • Prompt: "Analyze calls in the last 7 days for device 'john doe desk pro'"

    • Why it works: Device-focused analysis helps determine whether quality issues are linked to a specific endpoint.

    • Insights provided:

      • Device-specific call quality trends

      • Endpoint health visibility

      • Hardware or connectivity issue identification

Webex Workspace and Device prompts

The following prompts are examples of supported queries and supported identifiers for Workspace and Device workflows.

  • Supported identifiers

    • Device name

      • Example: "john doe desk pro"

    • Workspace name

      • Example: "tokyo24-11-quiet room 6"

    • Time range

      • Example: "last 7 days" or "26 March 2026"

  • Supported query areas

    • Device inventory and status

    • Device search and error visibility

    • Device configuration and event history

    • Workspace utilization and occupancy trends

    • Environmental metrics and analytics

    • Location search and capacity planning

  • Device status visibility

    • Prompt: "How many devices are online?"

    • Why it works: High-level inventory prompts provide immediate operational awareness across deployed devices.

    • Insights provided:

      • Online versus offline device counts

      • Device availability visibility

      • Operational status overview

  • Workspace utilization analysis

    • Prompt: "Which of my workspaces had the most use in the last 7 days?"

    • Why it works: Workspace usage trends help identify heavily utilized collaboration spaces.

    • Insights provided:

      • Workspace utilization patterns

      • High-demand locations

      • Capacity planning insights

  • Workspace inventory analysis

    • Prompt: "How many devices does workspace 'Tokyo-21' have?"

    • Why it works: Workspace-specific inventory queries provide focused operational visibility.

    • Insights provided:

      • Device counts per workspace

      • Workspace equipment visibility

      • Deployment planning support

  • Calling configuration visibility

    • Prompt: "How many devices have calling configured?"

    • Why it works: Configuration-focused prompts help validate deployment readiness and feature adoption.

    • Insights provided:

      • Calling-enabled device counts

      • Deployment coverage visibility

      • Configuration tracking

  • Issue pattern detection

    • Prompt: "List all the devices with issues and find any common patterns among the issues"

    • Why it works: Pattern analysis helps identify recurring operational problems affecting multiple devices.

    • Insights provided:

      • Shared failure indicators

      • Recurring device issues

      • Faster troubleshooting prioritization

  • Workspace issue analysis

    • Prompt: "How many workspaces have issues and what is the common pattern among the issues?"

    • Why it works: Correlating workspace issues helps identify systemic environmental or deployment problems.

    • Insights provided:

      • Workspace issue trends

      • Common operational patterns

      • Potential root cause indicators

Splunk Prompts

  • Splunk deployment health

    • Prompt: "How is the health of my Splunk deployment?"

    • Why it works:

      • Provides a high-level overview of system status, allowing for proactive monitoring of the entire environment.

      • Essential for identifying resource bottlenecks before they impact end-user performance. ** Insights provided:

      • Overall system health such as indexer health, errors, or licence usage.

      • Identification of potential performance system-wide issues.

  • Performance monitoring

    • Prompt: "What is the p95 latency per Splunk service for the last 24 hours?"

    • Why it works:

      • Focuses on user experience by tracking the 95th percentile latency, which is more representative of real-world performance than averages.

      • Helps establish performance baselines for individual services.

    • Insights provided:

      • Latency trends across different Splunk services.

      • Identification of specific services experiencing performance degradation.

  • Error tracking & diagnostics

    • Prompt: "Show me HTTP 5xx errors by endpoint in Splunk in the past 24 hours"

    • Why it works:

      • Directly targets server-side failures that prevent successful data ingestion or user requests.

      • Allows for rapid debugging of specific API endpoints.

    • Insights provided:

      • Overall error posture.

      • Identification of problematic endpoints causing service failures.

    • Prompt: "Which Splunk services have an error rate above 2 percent in the last hour?"

    • Why it works:

      • Enables real-time incident response by filtering out noise and highlighting critical service degradation.

      • Helps prioritize troubleshooting efforts based on impact thresholds.

    • Insights provided:

      • Immediate identification of services performing below acceptable quality standards.

      • Critical failure points requiring urgent attention.

  • Alert & data integrity

    • Prompt: "Summarize any alerts from our Splunk system"

    • Why it works:

      • Consolidates disparate alerts into a single, actionable summary, reducing "alert fatigue."

      • Facilitates faster incident management and triage.

    • Insights provided:

      • Summary of cconfigured alerts.

      • Overview of triggered alert patterns.

    • Prompt: "Are any hosts not reporting to Splunk?"

    • Why it works:

      • Ensures data integrity and visibility across the entire infrastructure.

      • Detects potential gaps in data ingestion.

    • Insights provided:

      • Duration and list of hosts not reporting to Splunk.

      • Possible root causes to investigate.

  • Security & access management

    • Prompt: "Show any failed Splunk login attempts in the last 24 hours grouped by user"

    • Why it works:

      • Crucial for maintaining strong security posture.

      • Helps distinguish between simple errors and potential unauthorized access attempts.

    • Insights provided:

      • Audit trail of failed authentication attempts.

      • Identification of users or accounts experiencing recurring access issues.