Cisco Cloud Control Canvas

 
Updated August 25, 2026
PDF
Is this helpful? Feedback

AI Canvas and AI Assistant

What is AI Canvas?

AI Canvas is a shared operational workspace where people and AI agents work together to investigate and resolve IT issues.

An investigation in AI Canvas can bring together information from Cisco products and integrated third-party systems—such as monitoring, incident-management, security, automation, and knowledge-management tools—along with uploaded files, organizational knowledge, and specialized AI agents.

AI Canvas organizes this information into a single, continuing investigation. It can develop an investigation plan, assign work to the appropriate agents, correlate their findings, generate relevant visualizations, and present proposed next steps for review.

The workspace preserves the questions asked, evidence collected, findings reached, decisions made, and actions taken. This allows another operator to join the investigation or continue it later without rebuilding the context.

AI Canvas is more than a conversational interface. It is the place where a multi-step investigation is planned, performed, reviewed, shared, and carried through to resolution.

What is AI Assistant?

AI Assistant is a natural-language experience that helps users understand information and complete tasks within supported Cisco products, third-party products and workflows.

A user can ask AI Assistant a question or give it an instruction in everyday language. Depending on the product and task, AI Assistant can retrieve relevant information, explain what the data means, summarize documentation, recommend troubleshooting steps, help configure settings, or guide an operational action.

AI Assistant generally works with the context available in the product or workflow where the user invokes it. Its purpose is to make a specific interaction faster and easier—for example, understanding the status of a device, finding the likely reason for an error, summarizing an alert, or obtaining guidance for a configuration task.

AI Assistant is also different from an AI agent. AI Assistant is the experience through which a user asks for help. An agent is a specialized capability that can perform part of an investigation or workflow. Within AI Canvas, multiple agents may work together on behalf of the user.

When to use AI Canvas

Use AI Canvas when the work needs to be treated as an investigation rather than as an individual question or task.

For example, use AI Canvas when:

  • The issue may involve more than one product, system, or technology domain.

  • The cause is not yet known and evidence must be gathered and correlated.

  • Several diagnostic or analytical steps must be completed in a coordinated sequence.

  • Multiple specialized agents may be needed to examine different parts of the issue.

  • The team needs a visible investigation plan and a traceable record of findings.

  • Charts, topology maps, screenshots, files, or organizational knowledge are important to the investigation.

  • More than one operator needs to participate, review the findings, or approve proposed actions.

  • The investigation may continue across a handoff, escalation, or shift change.

Example: Users report that an application is slow. Determining the cause requires examining application performance, network paths, infrastructure health, recent changes, and security events. Use AI Canvas to coordinate the investigation, correlate the evidence, and preserve the complete record of work.

When to use AI Assistant

Use AI Assistant when you have a focused question or task and the relevant context is available within a supported Cisco product or workflow.

For example, use AI Assistant when:

  • You want to check the status or health of a specific device, site, application, or service.

  • You need a quick explanation or summary of product data.

  • You want help understanding an alert, event, error, or configuration.

  • You need recommended troubleshooting or resolution steps.

  • You want to find and summarize relevant documentation.

  • You need assistance completing a routine operational task.

  • You already know the scope of the problem and do not need a broader investigation.

Example: You want to know why a specific client failed to connect to a wireless network. Use AI Assistant to examine the available product data, explain the likely cause, and provide recommended next steps.

Learn more

Use these resources to explore Cisco Cloud Control, learn about AI Canvas, access Cloud Control Studio, and watch a shareable product overview:

Getting started with AI Assistant

AI Assistant is the conversational entry point in Cisco Cloud Control. Use it to ask questions about your environment, retrieve operational information, understand issues, and get guidance using natural language.

AI Assistant organizes each conversation as a thread. A thread preserves the prompts and responses for that conversation, allowing you to ask follow-up questions or return to the conversation later.

If the work develops into an investigation that requires a shared workspace, visual content, or collaboration with other operators, you can continue the work in AI Canvas.

Accessing AI Assistant

To access AI Assistant:

  1. From Cisco Cloud Control, select Home.

  2. Select Assistant tab.

The AI Assistant has:

  • Threads panel, where you can start, find, and reopen conversations

  • Prompt field, where you enter questions and instructions

  • Suggested prompts for common operational questions

  • A mode selector for choosing how AI Assistant processes the request

  • A link to actions that require your review, when applicable

Starting or continuing a thread

Use the Threads panel to start or manage your conversations.

  • Select Create new to start a new thread.

  • Select a thread under Previous to continue an earlier conversation.

  • Use Search history to find a thread.

  • Select Canvas overview to view your canvases.

note.svg

Starting a new thread creates a separate conversation. When you reopen an existing thread, AI Assistant uses the prompts and responses already available in that thread.


Submitting a request

To submit a request:

  1. Select one of the suggested prompts, or enter a question or instruction in the Ask anything field.

  2. Optionally, select the plus icon to add information or capabilities to the request.

  3. Select a response mode.

  4. Select the arrow icon to submit the request.

You can also select the microphone icon to enter a request using your voice.

Suggested prompts provide starting points for common operational questions, such as:

  • What are the most critical issues across my environment right now?

  • Identify configuration drift between sites.

  • Compare client connection quality across sites.

  • What security events happened in the past day?

  • Show me device inventory with status for this network.

You can select a suggested prompt and modify it to match your environment or objective.

Adding context to a request

Select the plus icon in the prompt field to open the context menu.

The menu provides the following options:

  • Prompts (/) — Browse and use predefined prompts.

  • Knowledge bases (#) — Add relevant organizational knowledge to the request.

  • Agents (@) — Select an agent with capabilities relevant to the task.

  • Workflows — Select an available workflow for a defined operational procedure.

  • Add image or file — Upload supporting material for AI Assistant to examine.

note.svg

You can also enter /, #, or @ in the prompt field to open the corresponding selection.


When attaching a document, AI Assistant supports PDF, TXT, MD, and DOCX files. Each file can be up to 5 MB, and a conversation can contain up to four uploaded files or images.

Only attach information that is relevant to the question. For example, you might attach an error screenshot, topology diagram, report, runbook, or configuration document when that material provides context that is not already available in Cisco Cloud Control.

Displaying preferences: Set how the Assistant window appears:

  • Full screen

  • Docked

  • Floating

  • New tab

Selecting a response mode

Use the mode selector in the prompt field to control how AI Assistant approaches your request.

  • Default mode: Use Default mode for focused operational questions and tasks that can usually be answered directly. Default mode is appropriate for requests such as:

    • Listing networks, devices, clients, alerts, or inventory

    • Checking the health or status of an entity

    • Summarizing recent events or changes

    • Explaining an alert or error

    • Finding configuration guidance

    • Retrieving a specific operational detail

  • Reasoning mode: Use Reasoning mode when the request requires deeper analysis or several investigative steps. Reasoning mode can:

    • Break a complex request into investigative steps

    • Gather and correlate information from relevant sources

    • Apply product knowledge and operational guidance

    • Identify patterns and supporting evidence

    • Evaluate possible causes

    • Present findings and recommended next steps

Use AI Canvas when the investigation also requires a shared visual workspace, persistent investigation artifacts, or collaboration with other operators.

Continuing the work in AI Canvas

Move the work to AI Canvas when a focused Assistant conversation develops into a broader investigation that requires:

  • Information from multiple products or operational domains

  • Several coordinated investigative steps

  • Generated cards, charts, topology maps, or other visual content

  • A persistent record of evidence, findings, and decisions

  • Participation from other operators

When an Assistant conversation is associated with a canvas, its context remains connected to that canvas. This allows you to continue the investigation without restating the information already gathered.

Handling an unsuccessful request

If AI Assistant cannot complete a request, it displays an error message in the thread.

Review the message and then try one or more of the following:

  • Retry the request.

  • Make the request more specific.

  • Reduce the number of tasks included in one prompt.

  • Confirm that referenced entities and time ranges are valid.

  • Confirm that uploaded files meet the supported format and size requirements.

  • Start a new thread if the existing conversation context is no longer relevant.

note.svg

Each canvas includes an integrated AI Assistant. The Assistant provides the conversational interface for the investigation, while the Canvas provides the visual, persistent, and collaborative workspace around that conversation.


Getting started with AI Canvas

AI Canvas combines a conversational investigation panel with a flexible visual workspace. Use the conversation panel to ask questions, invoke agents, add organizational knowledge, run workflows, and provide files or images. AI Canvas can display relevant results on the workspace as interactive cards that you can arrange, annotate, review, and share with other operators.

AI Canvas includes an integrated AI Assistant that appears in the conversation panel. Use the Assistant to ask questions, invoke agents, reference knowledge bases, run workflows, and attach supporting files or images. Responses appear in the conversation, and relevant results can be added to the Canvas workspace as interactive cards.

note.svg

AI Canvas follows the access permissions assigned to your Cisco Cloud Control account. You can access only the products, data, and environments for which you have permission. An investigation that spans multiple products requires access to each relevant product and environment.


Accessing AI Canvas

To access AI Canvas:

  1. From Cisco Cloud Control, select Home.

  2. Select the Canvas tab.

The Canvas overview displays quick-start categories and recently used canvases.

From the Canvas overview, you can:

  • Select a category under Quick start to begin with prompts for a particular operational category.

  • Select New to create an empty canvas.

  • Select a title under Recent to reopen an existing canvas.

  • Use the canvas filter to limit the canvases displayed.

  • Switch between the grid and list views.

  • Use the actions next to a recent canvas to share, rename, or duplicate it.

Quick-start categories can include areas such as health and availability, wireless, WAN health and performance, data center and compute, security policy and access, and discovery and inventory.

Understanding the Canvas workspace

A canvas contains two primary working areas:

  • Conversation panel — Enter requests, review responses, add context, and monitor queued requests.

  • Canvas workspace — Review and organize generated cards, images, annotations, summaries, and other investigation content.

The canvas header displays the canvas name, participants, sharing controls, and additional canvas options. Use Canvas overview in the breadcrumb to return to the list of canvases.

The canvas toolbar provides controls for organizing and reviewing the workspace. Use the zoom controls in the lower corner to increase or decrease the workspace magnification.

Starting an investigation

To start an investigation:

  1. Enter a question or instruction in the prompt field.

  2. Optionally, select the plus icon to add a prompt, knowledge base, agent, workflow, image, or file.

  3. Select the response mode.

  4. Select the arrow icon to submit the request.

You can also use the microphone icon to enter the request using your voice.

For example:

Compare wireless performance across the Bangalore and Pune sites during the past 24 hours. Identify access points with high channel utilization and show the results by site.

AI Canvas displays the response in the conversation panel. When a response contains information that can be visualized or explored, AI Canvas can add one or more cards to the workspace.

If you submit additional requests while processing is in progress, the Queue displays the requests waiting to be processed. Expand the queue to review the pending requests.

note.svg

AI Canvas provides Default and Reasoning response modes.


Adding information and capabilities to an investigation

Select the plus icon in the prompt field to open the context menu.

The context menu provides the following options:

  • Prompts (/) — Select a predefined prompt for a common operational task.

  • Knowledge bases (#) — Ground the request in approved organizational information, such as runbooks, procedures, policies, or other reference material.

  • Agents (@) — Invoke an available agent with capabilities relevant to the investigation.

  • Workflows — Start an available workflow for a defined operational process.

  • Add image or file — Provide supporting material for AI Canvas to analyze with the request.

You can also enter /, #, or @ directly in the prompt field to open the corresponding selection.

These options can be combined in the same investigation. For example, you can select a troubleshooting prompt, reference a runbook from a knowledge base, invoke an agent, and attach an error screenshot before submitting the request.

Using predefined prompts

Predefined prompts provide structured starting points for common tasks in less than 10 seconds. Select Prompts or enter /, browse the available prompts, and select one.

Review and modify the selected prompt before submitting it. Add relevant information such as the affected site, product, device, time range, or operational objective.

A predefined prompt starts the investigation; it does not limit the investigation to a fixed sequence. You can ask follow-up questions and add other context as the work progresses.

Using knowledge base

Select Knowledge bases or enter # to add approved organizational knowledge to the request.

Knowledge bases can help AI Canvas apply information that is specific to your organization, such as:

  • Standard operating procedures

  • Troubleshooting runbooks

  • Configuration standards

  • Security policies

  • Escalation procedures

  • Operational reference material

Specify how AI Canvas should use the selected knowledge. For example:

#Wireless Operations Runbook Investigate the client onboarding failures and compare the findings with the escalation criteria in this runbook.

Invoking an agent

Select Agents or enter @ to choose an available agent.

Agents provide specialized capabilities for particular products, domains, or operational tasks. Invoking an agent explicitly is useful when you know which capability should participate in the investigation.

For example:

@Wireless Agent Identify access points with high channel utilization at the Bangalore campus during the past four hours.

An investigation can involve more than one agent when the question spans multiple products or operational domains. AI Canvas preserves the agents' findings within the canvas so that they can be reviewed with the other investigation content.

Running a workflow

Select Workflows to choose an available workflow.

A workflow provides a defined sequence for a repeatable operational process, such as a health check, audit, investigation, or remediation procedure. Review the workflow and provide any required inputs before starting it.

Workflow progress and pending work can appear in the conversation panel or queue. Review results and any proposed actions before proceeding.

Adding multimodal input

AI Canvas can analyze a text prompt together with attached documents and images. Select the plus icon in the prompt field, and then select Add image or file.

Supported attachments include:

  • PDF, TXT, MD, and DOCX documents

  • JPG and PNG images

Each attachment can be up to 5 MB. You can attach a maximum of four files or images to a single request.

In your prompt, identify the attachment and explain what AI Canvas should examine. For example, after attaching a vendor maintenance notice as a PDF, enter:

Review the attached maintenance notice. Identify which networks may be affected during the maintenance window and determine whether those locations have backup circuits.

note.svg

Use Add image or file in the prompt field when you want AI Canvas to analyze an attachment. Use Add image on the Canvas toolbar when you want to place an image on the visual workspace.


Working with interactive cards

AI Canvas can represent investigation results as interactive cards on the workspace. A card can contain information such as a chart, table, topology, summary, inventory view, or other generated result.

Cards remain associated with the investigation that produced them. Selecting card-related content in the conversation panel highlights the corresponding card on the workspace.

Depending on the card type, you can:

  • Select data in the card to examine additional details.

  • Move the card by dragging it to another location.

  • Resize the card.

  • Open the card in a larger view.

  • Export the card.

  • Remove the card from the workspace.

note.svg

You can restore a removed card only until you refresh the page.


Organizing workspace

Use the canvas toolbar to manage content on the workspace.

The toolbar provides the following options:

  • Auto layout — Arrange workspace content automatically.

  • Stack cards — Group cards to reduce workspace clutter.

  • Add image — Place an image directly on the workspace.

  • Add text annotation — Add a note, label, or explanation to the workspace.

  • Lock cards — Prevent cards and other placed content from being moved accidentally.

  • Generate summary — Create a summary of the current canvas.

  • View activity — Review changes and actions recorded for the canvas.

  • Show minimap — Display an overview for navigating a large workspace.

  • Collapse — Hide the toolbar to provide more workspace area.

Use Add image on the toolbar when you want to place an image on the visual workspace. Use Add image or file in the prompt field when you want AI Canvas to analyze an attachment as part of a request.

Images placed directly on the workspace support JPG and PNG formats and can be up to 500 KB.

Collaborating in canvas

Select Share to give other authorized operators access to the canvas.

Participants work from the same persistent workspace and can review the investigation content, generated cards, annotations, and summaries. Access to underlying product data remains governed by each participant’s Cisco Cloud Control permissions.

To prepare the canvas for another operator or team:

  1. Organize the relevant cards.

  2. Add annotations to explain important findings or decisions.

  3. Select Generate summary to capture the current state of the investigation.

  4. Select Share and add the appropriate participants.

Use View activity to review the recorded changes and actions associated with the canvas.

Continuing from an action

Select the Actions tab to review operational items that require attention.

You can access Action from:

  • Actions tab

  • your Canvas

  • Notifications

When an action is associated with a canvas, open the canvas to review its investigation context and continue the work. Review the available evidence and any proposed action before proceeding.

Working with the prompt library

The prompt library contains predefined prompts for common operational questions and tasks. Use these prompts as starting points for exploring data, reviewing conditions, and investigating issues across the Cisco products connected to your Cisco Cloud Control environment.

The prompt library organizes prompts into the following categories:

  • Health & Availability — Review health, uptime, availability, and operational readiness.

  • Performance — Examine latency, throughput, quality metrics, utilization, and performance trends.

  • Incidents, Anomalies & Alerts — Review active incidents, detected anomalies, alerts, and related diagnostic information.

  • Topology — Explore network topology, paths, connections, and relationships between resources.

  • Security, Policy & Access — Review security events, policies, access, and compliance.

  • Discovery & Inventory — Review devices, software, firmware, and inventory information.

The category names are consistent for all users. The prompts displayed within each category can vary based on the products connected to Cisco Cloud Control.

Using a prompt from the library

You can open the prompt library from the prompt field in AI Assistant or AI Canvas.

To use a predefined prompt:

  1. Select the plus icon in the prompt field, and then select Prompts. Alternatively, enter / in the prompt field.

  2. Select a category.

  3. Select a prompt.

  4. Review the prompt and add relevant details, such as a site, network, device, product, or time range.

  5. Submit the request.

For example, you can modify a general performance prompt to provide a specific scope:

Compare wireless performance across the Bangalore and Pune sites during the past 24 hours. Highlight access points with high channel utilization.

A predefined prompt provides a starting point. You can modify it before submitting it and ask follow-up questions as the investigation develops.

Working with Reasoning mode

Reasoning mode is designed for complex troubleshooting and investigations that require a structured, evidence-based approach. It creates an investigation plan, allows you to review the proposed scope and steps, and then performs the approved investigation before presenting its findings.

Default mode and Reasoning mode can both access product data, invoke relevant agents, correlate information, and generate results. The distinguishing feature of Reasoning mode is its explicit investigation plan and the additional visibility it provides into the investigation steps, evidence, and limitations.

Use Reasoning mode when:

  • The cause of an issue is unclear.

  • The investigation spans multiple products or operational domains.

  • Several diagnostic or analytical steps must be coordinated.

  • You need to review the investigation approach before analysis begins.

  • Findings must be supported by evidence and suitable for review or handoff.

  • Missing data or other investigation limitations must be clearly identified.

Use Default mode when a request can be addressed without first developing and reviewing a detailed investigation plan.

How Reasoning mode works

A Reasoning mode investigation includes the following stages:

  • Plan creation — AI Canvas interprets the request and creates a proposed investigation plan. The plan identifies the questions to examine and the steps required to address them.

  • Plan review — You review the proposed plan before the investigation begins. Confirm that its scope, products, domains, entities, and time range match your objective. Modify the plan when necessary, and then approve it to continue.

  • Investigation — AI Canvas performs the approved steps using the products, agents, data, and knowledge available within your access permissions.

  • Progress visibility — While the investigation is running, AI Canvas displays information about its current phase, agent activity, completed work, and elapsed time.

  • Evidence-backed results — AI Canvas combines the findings and presents the evidence supporting its conclusions. The response can also include recommended next steps and limitations that affected the investigation.

  • Investigation record — Processing details identify the phases, agents, and completed steps that contributed to the response. You can review these details to understand how the investigation was performed.

AI Canvas can also generate visual cards for relevant findings. Card generation and follow-up questions are general Canvas capabilities and are not limited to Reasoning mode.

Running a Reasoning mode investigation

  1. Create a canvas or open an existing canvas.

  2. In the mode selector, select Reasoning.

  3. Enter a request that describes the issue, desired outcome, scope, and time range.

Reviewing the results

A Reasoning mode response can include:

  • Summary — The primary findings and conclusions from the investigation.

  • Supporting evidence — The information used to support each finding.

  • Recommended next steps — Suggested actions or additional areas to investigate.

  • Investigation limitations — Missing data, unavailable products, access restrictions, or other conditions that may affect the conclusions.

  • Visual cards — Charts, tables, topologies, summaries, or other generated views relevant to the investigation.

  • Processing details — The phases, agents, and steps that contributed to the response.

Review the supporting evidence and limitations before acting on a conclusion or recommended next step.

note.svg

A Reasoning mode request can take longer to complete because AI Canvas develops and performs a structured investigation. The products, data, knowledge, agents, and environments available to the investigation depend on your Cisco Cloud Control access permissions.


Working with multimodal input

Multimodal input allows AI Canvas to analyze a text prompt together with attached documents or images. Use attachments when relevant information is not already available from your Cisco Cloud Control environment, selected knowledge bases, or invoked agents.

You can attach:

  • Documents in PDF, TXT, MD, or DOCX format

  • Images in JPG or PNG format

Each attachment can be up to 5 MB. You can attach a maximum of four files or images to a single request.

Common attachments include:

  • Screenshots of alerts, errors, dashboards, or device status

  • Network diagrams and topology images

  • Vendor maintenance notices

  • Troubleshooting documents and support case records

  • Exported reports

  • Runbooks and operational procedures

To add an attachment:

  1. Select the plus icon in the AI Assistant prompt field.

  2. Select Add image or file.

  3. Select up to four supported files or images.

  4. Enter a prompt that identifies the attachment and explains what AI Canvas should analyze.

  5. Submit the request.

The attachment and its related conversation remain associated with the current canvas.

note.svg

Use Add image or file in the prompt field when you want AI Canvas to analyze an attachment. Use Add image on the Canvas toolbar when you want to place an image directly on the visual workspace.


Multimodal input example prompts

Maintenance notice

  1. Attach the vendor maintenance notice containing the affected circuit IDs, service locations, maintenance window, and expected impact.

  2. Enter a prompt such as:

Review the attached Comcast maintenance notice. Match the listed circuits and service locations to my networks, identify the affected sites, and show whether each site has a backup circuit or failover path.

AI Canvas can extract information such as the maintenance window and affected locations from the attachment, and then compare that information with data available from your operational environment.

Troubleshooting document

  1. Attach the relevant troubleshooting document or support case as a PDF, TXT, MD, DOCX, or image.

  2. Enter a prompt such as:

Review the attached TAC case. Summarize the reported symptoms and resolution steps, compare them with the issue in my current investigation, and identify which steps are applicable.

AI Canvas can examine the attached case information and relate it to the symptoms, evidence, and operational context available in the current canvas.

Screenshot and report

  1. Attach an error screenshot and an exported report.

  2. Enter a prompt such as:

Examine the attached error screenshot and performance report. Determine whether they describe the same issue, identify the affected devices, and recommend the next troubleshooting steps.

AI Canvas can analyze information from multiple attachment types together with the text request and the current investigation context.

Working with knowledge bases

A knowledge base is a reusable collection of organizational information that AI Assistant and AI Canvas can reference when responding to a request. Knowledge bases can provide context that is not available from live product data, such as internal procedures, operational standards, ownership information, and historical records.

A knowledge base can contain information such as:

  • Troubleshooting runbooks

  • Standard operating procedures

  • Network and configuration standards

  • Security and compliance policies

  • Maintenance schedules and change procedures

  • Site and service ownership information

  • Vendor guidance

  • Incident reports and post-incident reviews

Knowledge bases remain available for use across conversations and canvases. Users can access only the knowledge bases shared with them in the current environment.

The quality and relevance of the response depend on the information contained in the selected knowledge base. For example, AI Canvas can identify an escalation contact only if the selected knowledge base contains current ownership or contact information.

Selecting a knowledge base

To use a knowledge base in a request:

  1. Select the plus icon in the prompt field.

  2. Select Knowledge bases. Alternatively, enter # in the prompt field.

  3. Select the relevant knowledge base.

  4. Enter a request that explains what information you want AI Canvas to retrieve or apply.

  5. Submit the request.

note.svg

Review knowledge-base content regularly to ensure that procedures, standards, schedules, and contact information remain accurate.


Invoking Agents

Agents provide product-specific expertise. In both Assistant and Canvas, you can allow the Assistant to choose an agent automatically based on your request, or you can select one or more product agents for a prompt.

Select agents directly when you want to specify which product domains should handle your request—for example, Meraki, Nexus, or SD-WAN—without relying only on automatic routing.

The agents available to you depend on your product entitlements and configured integrations. You cannot select individual skills or the underlying services used by an agent.

Selecting agents for a prompt

You can open the agent picker in either of the following ways:

  • In the prompt field, type @ at a supported text boundary.

  • Select the plus (+) icon, and then select Agents.

The agent picker remains open while you select multiple agents and indicates which agents are selected. Selected agents are added to the prompt field as @ mentions. For example, @Meraki Agent and @ThousandEyes Agent.

Browsing and Filtering Agents

To browse and filter the Cisco agents you are entitled to use, open the agent picker and use its built-in search functionality. This allows you to quickly locate agents associated with Cisco products in the alphabetical catalog.

  1. Open the agent picker to view the initial list of Cisco agents.

  2. Click Show more to expand the alphabetically sorted catalog and view additional agents.

  3. Enter text in the search field to filter for specific agents. Agents you have already selected remain discoverable while filtering.

Routing and direct selection

The Assistant can determine which agent should handle a request from the prompt. Selecting an agent with @ or from the plus (+) menu gives you direct control when you already know which product expertise is required.

Direct selection supplements automatic routing; it does not replace it. If you do not select an agent, the Assistant uses its standard routing behavior.

Agent availability and errors

The picker displays Cisco agents based on your entitlements. Cisco agents that you are not entitled to use are not displayed.

An entitled agent can still be temporarily unavailable. If a selected agent or its backing service cannot complete the request, the Assistant displays the failure in the conversation.

The picker also provides appropriate loading, empty, no-results, error, and retry states when retrieving or filtering the Cisco agent catalog.

Understanding limitations

  • The Workflows agent is in beta, and it supports Default only.

  • Direct selection applies to product agents, not individual skills, task-specific agents, people, or underlying MCP server registrations.

  • Filtering begins after you explicitly open the agent picker. Proactively suggesting an agent from ordinary prompt text is not part of the current scope.

  • Assigning different portions of the same prompt to different selected agents is not documented as supported behavior.

Working with AI Canvas workflows

AI Canvas supports discovering, creating, configuring, and running workflows available in your workspace. Available workflows can include Cisco-managed and user-defined workflows. The workflows displayed depend on your environment, permissions, and configured integrations.

Workflows can perform write actions that change your operational environment. Review the target resources, input values, and expected effect before selecting Run.

AI Canvas workflows are available in Default mode. They are not supported in Reasoning mode.

Discovering and selecting a workflow

You can find or request a workflow in the following ways:

  • Browsing available workflows: Select the plus icon in the AI Canvas composer, select Workflows, and browse the available Cisco-managed and user-defined workflows.

  • Requesting an existing workflow: Describe the workflow you want to run in natural language. For example:

    • Run a workflow to quarantine a rogue client.

    • Disable the guest SSID on my network.

    • Run ping from my MX device to 8.8.8.8.

  • Requesting a new workflow: Describe the outcome you want when an available workflow does not meet your requirements. For example:

    • Create a workflow to tag all offline switches as needs-attention.

    • Create a workflow that checks access point health and reboots access points with an uptime greater than 90 days.

  • Invoking the Workflows agent: Enter @ in the composer, select the Workflows agent, and describe the workflow you want to find, create, configure, or run.

  • Selecting a recommended workflow: During troubleshooting, AI Assistant can recommend a relevant workflow as a possible next step. Answer any follow-up questions, review the recommended workflows, and select the workflow you want to configure.

note.svg

The available workflows depend on the Cisco-managed and user-defined workflows configured in your workspace.


timesave.svg

Selecting a workflow opens its configuration form. It does not start the workflow.


Configuring and running a workflow

After selecting a workflow:

  1. Review the configuration form.

  2. Verify any values populated from the conversation.

  3. Edit the populated values when necessary.

  4. Complete all remaining required fields.

  5. Select Continue.

  6. On the review screen, verify the workflow, target resources, and input values.

  7. Select Run to confirm and start the workflow.

  8. View the workflow status in the originating conversation or Canvas card.

caut.svg

Confirm that the workflow conditions and target scope cannot affect unintended devices, networks, or users.


Running a workflow

In a shared demonstration environment, use only the approved workflow and target values. Do not substitute another device or network unless the environment owner authorizes the change.

  1. Enter the prompt:

    Run the workflow to quarantine a rogue device.

  2. When the configuration form opens, enter:

    • MAC address: 96:9c:7f:70:43:49

    • Network name: Buenos Aires

  3. Select Continue.

  4. On the review screen, verify the workflow, MAC address, and network name.

  5. Confirm that all values match the approved demonstration scenario.

  6. Select Run to start the workflow.

Monitoring a workflow

The workflow card displays the latest available status and result.

  • In progress: Expand the card to review the current status and available progress details. You can leave or close the conversation without cancelling the workflow.

  • Completed: Expand the card and review the workflow result or output. To run the workflow again, select the available new-run action, review the configuration, and confirm the new run. A completed workflow does not run again automatically.

  • Failed: Expand the card and review the available failure details. To try again, select the available new-run or setup action, review or re-enter the configuration, and confirm the new run. A failed workflow is not retried automatically.

  • Status unavailable: If AI Canvas cannot retrieve the current status, this does not necessarily mean that the workflow failed. Reload AI Canvas or reopen the originating conversation to retrieve the latest available status.

  • Reopening a workflow: When you reopen the originating conversation, locate the workflow card and review its latest state. If the workflow is still running, expand the card to view its progress. If it has completed or failed, review the persisted result.

Collaborating on Canvas

Roles

There are two primary roles for collaborators in Canvas.

  • Owner: User who created the canvas is the default owner. Owner has full control over the canvas, including settings, permissions, and collaborator management.

  • Editor: Anyone who joins a canvas through a shared link becomes an editor. Editors can view and modify the canvas content, such as adding, editing, and rearranging cards, but they do not have the same level of control over settings and access.

Sharing a canvas

You can get a link that enables collaborators to edit a canvas. Anyone with this link is automatically granted editor rights.

Follow these steps to share a canvas.

  1. Click Share in the top-right corner of your canvas and then select Invite collaborators.

  2. Click copy invite link. This generates a unique shareable link.

  3. Share this link with your collaborators.

Owner controls

The owner retains advanced permissions and can:

  • Transfer Ownership:

    • Owners can assign ownership of the canvas to another collaborator if needed (e.g., handing over a project to a different lead).

    • Once ownership is transferred, the new Owner gains full rights, and the previous Owner becomes an Editor.

  • Remove Collaborators:

    • Owners can revoke access for specific users.

    • This immediately removes the collaborator’s ability to view or edit the canvas, even if they previously had the shared link.

  • Collaboration Behavior: These Canvas behaviors apply when users collaborate.

    • Collaborators see board-level changes instantly, such as when someone adds a text card, moves a card, or when someone else’s Canvas Assistant chat outputs a new card on to the canvas. Collaborators do not see each other’s chat assistants but can ask questions about cards other assistants generated by highlighting the card (clicking it) and asking in their own assistant panel

    • Canvas saves edits automatically, which maintains context and history across sessions.

    • The activity timeline captures changes, such as renames, additions, and deletions, so that teams can track updates over time.

Clarifying ambiguous prompts and queries in AI Canvas

If a prompt or query could refer to more than one device, account group, or other available match, AI Canvas asks you to clarify what you intended. This prevents the Assistant from choosing arbitrarily and helps it use the correct context in subsequent steps.

Clarifying before analysis begins

AI Canvas can use inventory information to interpret device references in your query. It searches for devices that match identifiers such as a device name, serial number, model, site-related name, or MAC address pattern.

  • If the query identifies an appropriate inventory match, AI Canvas adds the relevant device information to the query context and continues.

  • If several devices match, AI Canvas displays a selection prompt so that you can choose the intended device.

  • If a broad reference matches devices from different product categories, AI Canvas can group the results so that you can narrow the selection by category.

  • If no inventory match is found, AI Canvas continues without inventory enrichment.

Clarifying during a Reasoning mode query

Some ambiguity becomes visible only after a Reasoning mode query has started and an agent retrieves data. If the query produces multiple possible matches for a specifically named device, account group, or other value, AI Canvas stops that step and asks you to clarify the query instead of choosing automatically.

After you make a selection, AI Canvas applies your answer to the remaining steps and continues the query. This can occur when an agent returns multiple account groups or other possible matches.

Responding to a clarification prompt

  1. Review the devices, categories, or other options displayed in the clarification prompt.

  2. Select the option that best matches your query.

  3. Allow AI Canvas to continue the query using the selected context.

tip.svg

If none of the available options matches your intent, refine the original query by providing a more specific name, identifier, product, or location.


Reviewing clarification examples

Selecting from devices with similar names

Query

Check bronco health

AI Canvas can find several devices whose names contain bronco. It displays the matching devices so that you can select the intended device before analysis continues.

Selecting a product category for a site reference

Query

What is the health of CAMPUS-SFO devices?

If the reference matches devices from multiple product categories, AI Canvas can first ask you to select a category. It then continues with the devices in the selected category.

Continuing with a specific device match

Query

What is the status of MX90-NEDC-GTW?

When the device reference is sufficiently specific, AI Canvas uses the matching inventory details and continues without displaying a selection prompt.

Understanding limitations

  • Inventory-based enrichment currently supports devices. Site and client inventory are not currently supported by this process.

  • Inventory matching depends on the identifiers extracted from the query. Uncommon naming conventions or generic queries might not produce a match.

  • Very broad searches might consider only a limited set of inventory results.

  • When inventory enrichment is unavailable or does not find a match, AI Canvas continues the query without the additional inventory context.

Managing AI data preferences for model training

Use the AI model training preference in Cisco Cloud Control to manage whether Cisco can use eligible AI Canvas and AI Assistant data to train and improve AI models for your tenant.

The preference applies to the entire tenant, rather than to individual users.

Default: Enabled

A Tenant Full Admin can modify this preference at any time in the Admin Console settings.

note.svg

A preference change applies to data generated from the time of the change forward. It does not reclassify data generated before the change.


When the preference is on: Eligible data generated while the preference is on is marked as available for permitted Cisco AI model training and improvement.

When the preference is off: Eligible data generated while the preference is off is marked Do not use and is excluded from Cisco AI model training and improvement.

If the preference is turned on again later, only eligible data generated after it is turned on becomes available. Data generated while the preference was off remains unavailable for training and improvement.

Data covered by the preference

For AI Canvas and AI Assistant, the preference applies to interaction data generated from user activity, including:

  • User prompts

  • AI-generated responses

  • Canvas widgets and boards

  • Equivalent interaction data generated from Cisco Cloud Control native pages or x-launch experiences

  • Uploaded files and data retrieved from applicable Cisco offers

Select the information icon next to the preference to review a summary of the covered data. From the tooltip, select Learn how Cisco uses data for more information.

Change the AI model training preference

  1. In Cisco Cloud Control, open Admin Console.

  2. Select Settings from the navigation menu.

  3. Open the Data Preferences tab.

  4. Locate AI model training.

  5. Set Allow Cisco to use AI Canvas and AI Assistant data to train and improve AI models to the required state:

    • Turn the preference on to allow eligible data generated from that point forward to be used for AI model training and improvement.

    • Turn the preference off to prevent eligible data generated from that point forward from being used for AI model training and improvement.

  6. Verify that the setting displays the latest change date and the account that made the change.

note.svg

The change takes effect prospectively. Switching the preference does not change the status assigned to data from an earlier opted-in or opted-out period.


Review preference changes

The AI model training setting displays the date of the most recent change and the account that made it. Select View change history to review changes to the organization’s preference.

Using multiple tenants and organizations

Cisco AI Assistant supports users who have access to more than one product tenant or organization. When a request could apply to multiple tenants or organizations, AI Assistant asks you to select the environment to use.

Cisco products can use different terms for an administrative environment. For example, one product might use tenant, while another uses organization. This section uses tenant or organization to refer to either type.

How AI Assistant determines the tenant or organization

AI Assistant determines the scope of a request as follows:

  • If you have access to only one applicable tenant or organization, AI Assistant uses it without asking you to make a selection.

  • If you have access to multiple applicable tenants or organizations and the intended scope is unclear, AI Assistant asks you to select one.

  • If you submit the request from a product or page that already provides tenant or organization context, AI Assistant can use that context without asking you to select it again.

  • After you make a selection, the request and its related follow-up questions remain scoped to the selected tenant or organization.

Selecting a tenant or organization does not provide additional access. AI Assistant displays and uses only the environments that your Cisco Cloud Control account is authorized to access.

Understanding tenant and organization scope

For each product involved in a request, AI Assistant uses one selected tenant or organization. It does not combine or compare data from multiple tenants or organizations for the same product in a single request.

For example, a request cannot combine device information from two Meraki organizations into one result. Submit separate requests for each organization when you need to investigate both.

If a general request can use information from more than one product, AI Assistant might ask you to select the applicable tenant or organization for each relevant product. Each product query remains scoped to the selection you make.

If each product connected to your environment has only one tenant or organization, AI Assistant uses the available context automatically and does not display a selection step.

Select a tenant or organization

To submit a request when you have access to multiple environments:

  1. Enter and submit your request.

  2. When prompted, review the available tenants or organizations.

  3. Select the tenant or organization that contains the data you want to examine.

  4. Continue with the request.

  5. Ask related follow-up questions in the same conversation.

Before acting on a response, confirm that it applies to the intended tenant or organization.

Example requests

Review alerts in a Meraki organization

Prompt:

Show me the devices with the highest number of alerts.

If you have access to multiple Meraki organizations and the organization cannot be determined from the current context, AI Assistant asks you to select one. The resulting device and alert information is limited to the selected organization.

Review issues in an Intersight tenant

Prompt:

Are there any critical issues in my environment?

If you have access to multiple Intersight tenants and the intended tenant is unclear, AI Assistant asks you to select one. It then reviews critical issues within the selected tenant.

Find offline devices across applicable products

Prompt:

Show me offline devices.

This request does not identify a product or environment. AI Assistant determines which products can provide the requested device information. If an applicable product has multiple accessible tenants or organizations, AI Assistant asks you to select the tenant or organization to use for that product.

The response is based on the product environments you select; it does not aggregate data from multiple tenants or organizations for the same product.

Best practices for writing prompts

Prompt structure plays an important role in the quality of AI Canvas responses.

Specific and well-scoped prompts help:

  • improve response precision

  • reduce unnecessary results

  • provide faster and more actionable insights

Core prompting principles

Be specific about scope. Always define:

  • what you are investigating

  • where (site, device, client)

  • when (time range)

Example

  • Bad: "Why is the network slow?"

  • Better: "Investigate latency issues for my network in the last 24 hours."

Include context explicitly

The assistant relies on available context, but adding detail improves accuracy. Include:

  • site / network name

  • device or client identifiers

  • timeframe

  • issue type

Ask for actionable outputs

Instead of general questions, ask for:

  • root cause

  • recommendations

  • next steps

Example

  • Confusing: "What is happening here?"

  • Better: "Identify the root cause of packet loss and recommend next steps to resolve it."

Break complex queries into steps

For multi-layer investigations, use multiple prompts instead of one large query.

Example flow

  1. Identify affected clients

  2. Analyze device health

  3. Correlate with WAN metrics

Structured prompt framework (RT-CCO)

Use this framework for high-quality prompts:

  1. Role - Who the AI should act as

  2. Task - What you want it to do

  3. Context - Relevant background or data

  4. Constraints - Limits or instructions

  5. Output Format - Desired structure of response

Example "Act as a Senior Network Engineer. Analyze the interface errors on Switch-01 (Context) for the last 2 hours (Timeframe). Provide a summary of the root cause and a list of remediation steps (Output Format)."

Prompt structure template

Use [Action] + [Object] + [Scope] + [Timeframe] + [Expected Output] prompt structure.

Example

"Compare [CPU utilization] + [on Core-Router-A] + [across the last 24 hours] + [and list any anomalies found]."

Writing effective prompts

Do Don’t

Use clear, concise language

Use vague terms like “issue” or “problem”

Specify scope and timeframe

Ask multiple unrelated questions in one prompt

Ask for actionable insights

Assume missing context

Use consistent naming (sites, devices)

Overload the prompt with unnecessary detail

Context and limitations

  • The assistant uses available canvas context (cards, data sources, prior prompts).

  • Responses depend on:

    • selected network/site

    • available telemetry

    • time range

    If results seem incorrect:

    • refine the scope

    • add missing context

    • break the query into smaller steps

  • When a prompt for a subjective task (for example, "Allow smith access to jira") triggers an authentication failure, the session can become locked. Even after the authentication issue is resolved, the assistant continues to display the error, preventing further task execution.

    Workaround: To resolve this, open a duplicate session in a new tab to re-initiate the request. This clears the previous error state and allows the system to process the task successfully.

  • When querying for server inventory (for example, "Summarize rack vs blade counts"), the AI Canvas may generate widgets with empty tables, despite successfully retrieving the total count.

    Workaround: Try rephrasing the prompt to request specific attributes (for example, "List the names and models of blade servers") or ask the query again to trigger a fresh retrieval.

Optimized prompts for integrated products

To obtain the best results from the AI Canvas, tailor your prompts to the telemetry and data models of your integrated platforms. While general questions provide broad information, platform-specific scenarios allow the AI Canvas to:

  • Leverage domain expertise: Apply platform-specific logic (for example, Meraki’s RF metrics or ThousandEyes' path analysis) to your query.

  • Reduce noise: Use platform-specific filters to narrow down thousands of events to the most relevant, actionable insights.

  • Bridge data gaps: Correlate identity, security, and network telemetry by explicitly referencing the relationships between components (for example, linking a server profile to a storage drive failure).

The following sections provide proven prompt structures. Use these templates to transform vague requests into precise, diagnostic-grade queries.

Meraki prompts

Cisco Meraki provides cloud-managed networking for distributed wireless, switching, security, WAN, and endpoint environments.

Use cases:

  • Access Manager

  • Wireless health

  • Switching

  • Firewall and security

  • VPN and routing

  • Client visibility

  • Performance monitoring

  • Device inventory and health

  • Alerts and events

  • Organization configuration

Try these prompts:

  • Network overview

    • Prompt: "How is my organization doing?"

    • Why it works:

      • Provides a high-level operational summary across the environment

    • Insights provided:

      • Highlights overall network health

      • Helps quickly identify whether immediate investigation is required

  • Critical alerts

    • Prompt: "Are there any critical alerts?"

    • Why it works:

      • Focuses attention on high-priority operational issues

    • Insights provided:

      • Surfaces active alerts requiring immediate action

      • Helps prioritize troubleshooting efforts

  • WAN port utilization

    • Prompt: "Show my WAN port utilization."

    • Why it works:

      • Helps identify bandwidth saturation and traffic spikes

    • Insights provided:

      • Highlights heavily utilized WAN interfaces

      • Helps detect congestion or abnormal traffic patterns

  • WAN port status

    • Prompt: "Show my WAN port status."

    • Why it works:

      • Provides visibility into WAN connectivity health

    • Insights provided:

      • Identifies disconnected or degraded WAN links

      • Helps verify circuit availability

  • Security Events

    • Prompt: "What security events happened in my network in the past day?"

    • Why it works:

      • Focuses on recent security-related activity

    • Insights provided:

      • Surfaces suspicious or high-priority security events

      • Helps identify emerging threats

  • Top Utilized Clients

    • Prompt: "Show me the top utilized clients."

    • Why it works:

      • Helps identify devices consuming excessive bandwidth

    • Insights provided:

      • Highlights heavy network consumers

      • Helps investigate performance degradation caused by client activity

  • Client VPN Visibility

    • Prompt: "Who is connected to the client VPN?"

    • Why it works:

      • Provides visibility into remote access activity

    • Insights provided:

      • Identifies active VPN users

      • Helps monitor remote connectivity usage

Catalyst Center prompts

Cisco Catalyst Center simplifies campus and branch network operations through automation, assurance, analytics, and AI-assisted troubleshooting.

Use cases:

  • Switching

  • Routing

  • Configuration analysis

  • Device replacement

  • AI analytics

  • Network assurance

  • Wireless health

  • Compliance

  • Performance and monitoring

  • Software-image management

  • Network topology

  • Documentation search

Try these prompts:

  • Network overview

    • Prompt: "How is my organization doing?"

    • Why it works:

      • Provides a high-level operational summary across the Catalyst Center environment

    • Insights provided:

      • Highlights overall network health and availability

      • Surfaces the areas most likely to need attention

      • Helps determine whether immediate investigation is required

  • Recent activity review

    • Prompt: "What did I miss over the last 12 hours?"

    • Why it works:

      • Creates a time-bounded recap for users returning after a shift, handoff, or period away from the environment

    • Insights provided:

      • Summarizes meaningful health changes and recent events

      • Calls attention to critical alerts or newly affected areas

      • Provides a practical starting point for follow-up questions

  • Site health comparison

    • Prompt: "Which of my sites have the lowest health scores right now?"

    • Why it works:

      • Ranks sites by current health so users can prioritize investigation instead of reviewing sites one by one

    • Insights provided:

      • Identifies the least healthy sites

      • Makes site-to-site differences easier to compare

      • Helps focus troubleshooting on the highest-priority locations

  • Wireless health check

    • Prompt: "Run a Wi-Fi health check on my Catalyst Center."

    • Why it works:

      • Brings wireless health signals together in one request and supports a broad first pass before deeper troubleshooting

    • Insights provided:

      • Highlights wireless health concerns across sites and access points

      • Surfaces client connection or performance symptoms when relevant

      • Suggests where to narrow the next investigation

  • Device and site performance

    • Prompt: "Which Catalyst Center sites have degraded performance right now?"

    • Why it works:

      • Focuses the response on active performance degradation and the locations experiencing it

    • Insights provided:

      • Identifies currently degraded sites

      • Provides available performance context and the data time range

      • Supports follow-up analysis of the devices, clients, or metrics behind the degradation

  • Client experience

    • Prompt: "How are the clients associated with AP X doing?"

    • Why it works:

      • Scopes the analysis to a specific access point, making it useful for investigating a known area or user-impact report

    • Insights provided:

      • Summarizes the experience of clients associated with the selected access point

      • Highlights connection failures or other client issues when available

      • Helps distinguish a localized access-point problem from a broader wireless issue

  • Critical issue triage

    • Prompt: "Show me a summary of critical alerts for my Catalyst Center."

    • Why it works:

      • Consolidates the most urgent alerts into a single triage view for faster prioritization

    • Insights provided:

      • Summarizes active critical alerts

      • Shows affected devices, clients, or sites when relevant

      • Helps users decide which issue to investigate first

  • Issue impact analysis

    • Prompt: "Show me the impacted Catalyst Center sites and devices for issue X."

    • Why it works:

      • Connects a known issue to its operational scope, reducing the effort needed to assess the blast radius

    • Insights provided:

      • Lists the sites and devices associated with the specified issue

      • Clarifies whether the impact is localized or widespread

      • Provides context for escalation, communication, and remediation planning

  • Discovery and inventory

    • Prompt: "Show my Catalyst Center device inventory."

    • Why it works:

      • Provides a direct natural-language entry point into the device estate without requiring users to navigate inventory views

    • Insights provided:

      • Returns the devices known to Catalyst Center

      • Provides available device details in a structured view

      • Supports follow-up questions about health, reachability, software, or location

  • Security exposure

    • Prompt: "Which security advisories are affecting my devices?"

    • Why it works:

      • Frames advisory information around the organization’s actual device exposure instead of a generic advisory list

    • Insights provided:

      • Identifies security advisories relevant to managed devices

      • Shows affected devices when the information is available

      • Helps users prioritize validation and remediation follow-up

Identity prompts

Cisco Identity Services provides identity-based network access control, contextual visibility, segmentation, and policy enforcement across connected users and devices.

Use cases:

  • Network-outage root-cause analysis

  • Security-incident containment

  • Segmentation and security-group-tag troubleshooting

  • Active Directory connectivity

  • Single-user authentication-failure isolation

  • Authentication troubleshooting

  • Identity-related incident response

  • Identity-posture assessment

Try these prompts:

  • Supported identifiers

    • Name or email address: For example, "Jane Doe" or "jane.doe@company.com"

    • Application name: For example, "Salesforce" or "Workday"

    • Device or endpoint identifier: For example, a MAC address or hostname

    • Time range: For example, "last 7 days" or "since March 1"

  • *Identity health summary

    • Prompt: "Show a risk summary for John Doe."

    • Why it works:

      • Identifies risks related to a user across multiple accounts and data sources

    • Insights provided:

      • Provides the user’s posture score, trust level, and MFA status

      • Summarizes sign-in activity

      • Prioritizes risks and anomalies by criticality

  • Investigate trends

    • Prompt: "Show authentication trends over the past 30 days."

    • Why it works:

      • Identifies trends across identity data from multiple sources

    • Insights provided:

      • Breaks down the authentication methods used

      • Shows MFA adoption

      • Identifies and prioritizes risks by criticality

  • Troubleshooting

    • Prompt: "Why is John Doe having trouble logging in?"

    • Why it works:

      • Correlates identity lifecycle status with network data

    • Insights provided:

      • Identifies likely root causes

      • Prioritizes potential issues by criticality

      • Recommends next steps for remediation

ThousandEyes prompts

Cisco ThousandEyes provides end-to-end visibility into application and service delivery across enterprise networks, the internet, cloud providers, and SaaS services.

Use cases:

  • Endpoint-agent troubleshooting

  • Internet Insights troubleshooting

  • Alert suppression

  • Maintenance-window monitoring

  • Agent, label, and role inventory

  • Test and target root-cause analysis

  • Network-health monitoring

  • Outage monitoring

  • Agent and test discovery

Try these prompts:

  • Outage detection and service disruptions

    • Prompt: "Are there any outages affecting my monitored services right now?"

    • Why it works:

      • Outages can be localized, regional, or global in scope

      • Geographic context helps distinguish backbone internet issues from local site problems

    • Insights provided:

      • Identifies impacted services and affected locations

      • Helps determine whether the issue originates within the enterprise, ISP, or external provider network

  • Network path analysis

    • Prompt: "Show me the network path visualization for my monitored tests."

    • Why it works:

      • Network path analysis requires visibility into multiple providers and transit points

      • Isolating problematic ISP hops or AS paths accelerates root cause analysis

    • Insights provided:

      • Displays traffic flow and network path behavior

      • Helps identify packet loss, latency, or failures across provider hops

  • Anomaly detection

    • Prompt: "Are there any anomalies in my ThousandEyes tests?"

    • Why it works:

      • Anomalies are meaningful only when compared against historical baselines

      • Historical comparison helps identify true operational deviations

    • Insights provided:

      • Highlights abnormal latency, packet loss, or performance degradation

      • Helps identify emerging operational problems before outages occur

  • Test management and status

    • Prompt: "What ThousandEyes tests are currently running?"

    • Why it works:

      • Test execution alone does not confirm test health or successful telemetry collection

      • Focusing on failing or degraded tests provides more actionable operational insight

    • Insights provided:

      • Displays active test status and operational health

      • Helps identify silent failures or telemetry collection problems

  • Performance metrics and trends

    • Prompt: "What are the current latency and packet loss metrics for my critical tests?"

    • Why it works:

      • Raw metrics can be difficult to interpret at scale

      • Comparative analysis and prioritization improve operational visibility

    • Insights provided:

      • Highlights regions, providers, or services with poor performance

      • Helps prioritize optimization and troubleshooting efforts

Nexus Dashboard prompts

Cisco Nexus Dashboard provides a centralized platform for operating, monitoring, and troubleshooting data-center fabrics across multiple sites.

Use cases:

  • Connectivity analysis

  • Security-contract analysis

  • Interface monitoring

  • Congestion analysis

  • Fabric software management

  • Anomaly investigation

  • AI and machine-learning workload monitoring

  • Fabric health

  • Network analytics

  • Topology visualization

Try these prompts:

  • Fabric health overview

    • Prompt: "Is my data center fabric healthy right now?"

    • Why it works:

      • Provides an immediate operational health assessment of the data center fabric

    • Insights provided:

      • Highlights active issues impacting the fabric

      • Helps determine whether immediate investigation is required

  • Fabric health summary

    • Prompt: "Give me an overall health summary of my data center fabrics."

    • Why it works:

      • Consolidates multiple health indicators into a single high-level summary

    • Insights provided:

      • Provides visibility into overall fabric stability and operational status

  • Critical fabric issues

    • Prompt: "Are there any critical issues across my data center fabrics?"

    • Why it works:

      • Focuses attention on high-priority operational risks

    • Insights provided:

      • Identifies critical failures or degraded components requiring immediate remediation

  • Components requiring attention

    • Prompt: "Which fabric components need attention today?"

    • Why it works:

      • Helps prioritize operational tasks and remediation efforts

    • Insights provided:

      • Highlights switches, links, or services showing degraded health or alerts

  • Multi-fabric overview

    • Prompt: "Show me a health overview of all fabrics managed by Nexus Dashboard."

    • Why it works:

      • Simplifies visibility across multiple managed environments

    • Insights provided:

      • Provides centralized operational awareness across fabrics

Nexus Hyperfabric prompts

Cisco Nexus Hyperfabric simplifies the design, deployment, and operation of cloud-managed data-center and AI network fabrics.

Use cases:

  • Resource visibility

  • Live network diagnostics

  • Endpoint mobility tracking

  • Resource discovery

  • Connectivity diagnostics

  • Endpoint search

Try these prompts:

  • Fabric discovery and inventory

    • Prompt: "Show me all devices discovered in my Nexus Hyperfabric organization."

    • Why it works:

      • Broad inventory requests can generate large and difficult-to-read results

      • Narrowing the request helps AI focus on the most relevant operational data

    • Insights provided:

      • Displays discovered devices in a more structured and actionable format

      • Helps simplify inventory visibility and operational review

  • Connectivity diagnostics

    • Prompt: "Are any devices in my fabric unable to communicate?"

    • Why it works:

      • Focuses the analysis on endpoints experiencing connectivity problems

      • Enables AI to perform targeted connectivity and path validation checks

    • Insights provided:

      • Identifies communication failures between devices

      • Helps isolate routing, forwarding, or connectivity issues

  • End-to-end reachability and toubleshooting

    • Prompt: "Are there any reachability issues between endpoints in my fabric?"

    • Why it works:

      • Reachability issues often require deeper analysis than simple connectivity checks

      • Encourages AI to evaluate routing paths, VRFs, and forwarding behavior

    • Insights provided:

      • Helps identify routing or segmentation issues impacting endpoint communication

      • Improves troubleshooting accuracy across the fabric

  • Endpoint search

    • Prompt: "Show me all endpoints currently connected to my fabric and their locations."

    • Why it works:

      • Endpoint visibility is essential for operational and physical troubleshooting

      • Location-aware endpoint information makes results more actionable

    • Insights provided:

      • Displays connected endpoints and their attachment locations

      • Helps identify endpoint placement and physical connectivity relationships

  • Fabric topology and device status

    • Prompt: "Show me the topology of my Nexus Hyperfabric deployment."

    • Why it works:

      • Topology visibility improves infrastructure understanding and troubleshooting efficiency

    • Insights provided:

      • Displays device relationships and fabric structure

      • Helps validate deployment architecture and operational health

  • Fabric capacity planning

    • Prompt: "Can I add any connections to my fabrics?"

    • Why it works:

      • Capacity planning requires understanding available resources and topology constraints

      • Detailed prompts allow AI to evaluate switch and port availability more accurately

    • Insights provided:

      • Identifies available connectivity capacity across the fabric

      • Helps validate whether additional connections can be supported

      • Highlights switchports or infrastructure limitations impacting expansion

Intersight prompts

Cisco Intersight provides centralized visibility, automation, and lifecycle management for Cisco compute infrastructure across data centers and edge locations.

Use cases:

  • Account and domain context

  • Compute inventory

  • Profiles, templates, and policies

  • Pools and identities

  • Network and fabric visibility

  • Storage visibility

  • Health and fault monitoring

  • Jobs, events, and audit history

  • Topology and relationship analysis

  • Troubleshooting context

  • Risk analysis

  • Search, filtering, and report export

  • Server compute management

  • Managed-object queries

  • Configuration audit and change tracking

Try these prompts:

  • Compute inventory

    • Prompt: "Which servers are running the oldest firmware version?"

    • Why it works:

      • Firmware consistency is important for maintaining security and performance

    • Insights provided:

      • Identifies potential vulnerabilities and compatibility risks

      • Helps prioritize firmware and hardware updates

  • Storage health

    • Prompt: "Are there any storage drives in a degraded or failed state?"

    • Why it works:

      • Storage failures can result in data loss or application downtime

    • Insights provided:

      • Identifies degraded or failed storage components

      • Helps prioritize remediation before failures impact workloads

  • Network adapter status

    • Prompt: "List all servers with inactive or disconnected network adapters."

    • Why it works:

      • Network adapter issues can lead to connectivity and service disruptions

    • Insights provided:

      • Highlights configuration or connectivity issues requiring immediate attention

  • Audit and change tracking

    • Prompt: "Who made changes to my server profiles in the last 24 hours?"

    • Why it works:

      • Understanding what changed and who made the change is critical for troubleshooting and remediation

    • Insights provided:

      • Provides an accountability trail

      • Helps correlate recent configuration changes with operational issues

  • Hardware health overview

    • Prompt: "Give me an overall health summary of my compute infrastructure."

    • Why it works:

      • Provides you with an at-a-glance operational summary

    • Insights provided:

      • Delivers a high-level view of infrastructure health

      • Helps identify systemic issues requiring immediate attention

Secure Access prompts

Cisco Secure Access provides cloud-delivered, zero-trust security for users and devices accessing private applications, SaaS services, and the internet.

Use cases:

  • Activity search

  • Rules activity

  • Unique-resource monitoring

  • Network-tunnel-group monitoring

  • Roaming-computer monitoring

  • Internal-network monitoring

  • Domain intelligence

  • Security summaries

  • Total-request reporting

  • Top-N reports

  • Time-series reports

  • Identity distribution

  • Bandwidth reports

  • Reporting and analytics

  • Access-rule configuration

  • Destination-list configuration

  • Application-access troubleshooting

Try these prompts:

  • Recent security activity

    • Prompt: "Show security summary for the last <N> days."

    • Prompt: "Show top threats this week."

    • Why it works:

      • Provides a broad operational snapshot across all traffic types, helping quickly surface anomalies without requiring a specific category

    • Insights provided:

      • Provides aggregated event counts across traffic types

      • Highlights recent security trends and patterns

      • Identifies categories that may require deeper investigation

  • ZTNA access activity

    • Prompt: "Show recent ZTNA access activity."

    • Why it works:

      • Filters for zero-trust network access events, isolating private application access patterns from general internet traffic

    • Insights provided:

      • Shows private application access attempts

      • Provides ZTNA policy enforcement results

      • Highlights user-to-resource access patterns

  • Firewall activity

    • Prompt: "Show recent firewall activity from Secure Access."

    • Why it works:

      • Focuses on firewall enforcement, surfacing blocked connections and rule matches that may indicate policy enforcement or attack attempts

    • Insights provided:

      • Shows blocked and allowed connections

      • Highlights firewall rule-match patterns

      • Identifies potential intrusion or exfiltration attempts

  • Intrusion prevention events

    • Prompt: "Show recent intrusion prevention events from Secure Access."

    • Why it works:

      • Isolates IPS and IDS detections to identify active exploitation attempts or signature-matched threats

    • Insights provided:

      • Shows signature-matched threat detections

      • Identifies attack vectors

      • Provides the severity distribution of detected threats

  • SSL/TLS decryption activity

    • Prompt: "Show recent SSL/TLS decryption activity from Secure Access."

    • Why it works:

      • Provides visibility into encrypted traffic inspection, helping validate that decryption policies are working and not creating blind spots

    • Insights provided:

      • Shows decryption success and failure rates

      • Indicates encrypted traffic inspection coverage

      • Identifies certificate-related issues

  • Security summary

    • Prompt: "Show the security summary for total, blocked, and allowed requests from Secure Access."

    • Why it works:

      • Provides a high-level request disposition breakdown, showing how traffic is divided among allowed, blocked, and monitored requests

    • Insights provided:

      • Provides the total request volume

      • Shows block and allowed rates

      • Breaks down traffic by enforcement action

  • Top accessed destinations

    • Prompt: "What are the top accessed destinations from Secure Access?"

    • Why it works:

      • Identifies the most visited domains and IP addresses, helping spot shadow IT, high-bandwidth consumers, or frequently targeted resources

    • Insights provided:

      • Identifies the most popular destinations by request count

      • Highlights potential shadow IT or unauthorized services

      • Identifies bandwidth-heavy destinations

  • Top threats

    • Prompt: "What are the top threats from Secure Access?"

    • Why it works:

      • Surfaces the most frequently detected threats, enabling prioritization of security response and policy tuning

    • Insights provided:

      • Identifies the most common threat categories and signatures

      • Shows threat-volume trends

      • Highlights priority targets for remediation

  • Hourly request trends

    • Prompt: "Show request counts aggregated by hour from Secure Access."

    • Why it works:

      • Reveals traffic patterns over time, helping identify anomalous spikes, off-hours activity, or gradual traffic growth

    • Insights provided:

      • Shows hourly traffic-volume trends

      • Identifies anomalous traffic spikes

      • Establishes baseline traffic patterns for comparison

  • Bandwidth usage

    • Prompt: "Show bandwidth usage by hour from Secure Access."

    • Why it works:

      • Tracks data-transfer volumes over time, identifying bandwidth-heavy periods and potential data-exfiltration patterns

    • Insights provided:

      • Shows hourly bandwidth consumption

      • Identifies peak usage periods

      • Highlights unusual data-transfer volumes

  • Access rule hit counts

    • Prompt: "Show access rule hit counts from Secure Access."

    • Why it works:

      • Shows which policy rules are actively matching traffic and which are unused, supporting policy optimization and cleanup

    • Insights provided:

      • Identifies active and unused rules

      • Shows the distribution of rule matches

      • Highlights policy-optimization opportunities

  • Top identities by request count

    • Prompt: "Who are the top identities by request count from Secure Access?"

    • Why it works:

      • Identifies the highest-volume users, helping detect compromised accounts, policy violations, or bandwidth abuse

    • Insights provided:

      • Identifies the most active users by request volume

      • Highlights potential account-misuse indicators

      • Shows the distribution of user activity

  • Network tunnel status

    • Prompt: "Show the status of all network tunnels from Secure Access."

    • Why it works:

      • Surfaces tunnel health across the deployment, identifying disconnected or degraded tunnels that could affect site-to-site connectivity

    • Insights provided:

      • Shows active and inactive tunnel counts

      • Provides tunnel health and uptime

      • Highlights site-connectivity status

  • Roaming computer inventory

    • Prompt: "List roaming computers and their status from Secure Access."

    • Why it works:

      • Provides visibility into remote endpoints enrolled through the roaming client, helping track device coverage and enrollment health

    • Insights provided:

      • Provides enrolled-device counts and status

      • Shows last-seen timestamps for offline detection

      • Identifies the distribution of client versions

  • Internal network configuration

    • Prompt: "List configured internal networks from Secure Access."

    • Why it works:

      • Enumerates internal network ranges and tunnel associations, helping validate that branch and campus networks are properly registered

    • Insights provided:

      • Lists configured network ranges

      • Shows tunnel-to-network associations

      • Identifies gaps in network coverage

  • Deployment health overview

    • Prompt: "What is the health status of my network deployments from Secure Access?"

    • Why it works:

      • Combines tunnel, appliance, and site status into a single operational health view

    • Insights provided:

      • Provides overall deployment-health indicators

      • Identifies sites or appliances requiring attention

      • Highlights degraded components across the deployment

  • Tunnel group status

    • Prompt: "Show me all network tunnel groups and their status from Secure Access."

    • Why it works:

      • Provides tunnel-group-level visibility by aggregating individual tunnel states into logical groups

    • Insights provided:

      • Provides a tunnel-group health summary

      • Shows peer-tunnel states within each group

      • Identifies groups with degraded tunnels

  • Tunnel groups by region

    • Prompt: "List all tunnel groups by region from Secure Access."

    • Why it works:

      • Organizes tunnel infrastructure by geographic region, supporting regional capacity planning and outage correlation

    • Insights provided:

      • Shows the regional distribution of tunnel groups

      • Provides region-specific health indicators

      • Highlights geographic redundancy coverage

  • Access policy rules

    • Prompt: "List all access policy rules from Secure Access."

    • Why it works:

      • Provides a complete view of the access-policy ruleset, including rule ordering, actions, and scope

    • Insights provided:

      • Provides the complete rule inventory in its configured order

      • Shows rule actions such as allow, block, and warn

      • Identifies the scope and targeting of each rule

  • Rule detail inspection

    • Prompt: "Show full details for rule <name> from Secure Access."

    • Why it works:

      • Drills into a specific rule to inspect its conditions, identities, destinations, and schedule

    • Insights provided:

      • Provides the complete rule configuration

      • Shows identity and destination targeting

      • Provides schedule and exception details

  • Destination list inventory

    • Prompt: "List all destination lists in the Secure Access organization."

    • Why it works:

      • Provides a complete view of destination lists and their entry counts, helping clarify the scope of custom allow and block lists

    • Insights provided:

      • Provides the complete list inventory with entry counts

      • Shows list creation and modification dates

      • Identifies list types such as allow, block, and custom

  • Domain search across lists

    • Prompt: "Which destination lists contain cisco.com?"

    • Why it works:

      • Searches every destination list for a specific domain, helping determine whether the domain is correctly categorized or duplicated

    • Insights provided:

      • Identifies lists containing the target domain

      • Highlights duplicate entries across lists

      • Identifies potentially conflicting allow and block entries

  • Stale list audit

    • Prompt: "Which destination lists are stale or empty?"

    • Why it works:

      • Identifies lists that have not been updated recently or contain no entries, supporting policy hygiene and cleanup

    • Insights provided:

      • Identifies lists with no entries

      • Identifies lists with outdated modification dates

      • Highlights cleanup candidates

  • Destination limit usage

    • Prompt: "How close are we to the 250,000 destination limit in Secure Access?"

    • Why it works:

      • Tracks destination consumption against the organizational limit, providing an early warning before capacity is reached

    • Insights provided:

      • Shows the current destination count against the limit

      • Shows each list’s contribution to the total

      • Supports capacity-planning decisions

  • Domain risk assessment

    • Prompt: "What is the security risk information for cisco.com?"

    • Why it works:

      • Queries Cisco Talos threat intelligence for a domain’s risk score, associated threats, and reputation data

    • Insights provided:

      • Provides the domain risk score and confidence

      • Identifies associated threat indicators

      • Shows historical reputation data

  • Domain categorization

    • Prompt: "What is the content category for facebook.com?"

    • Why it works:

      • Retrieves the content classification assigned to a domain, helping explain how policies will apply to traffic destined for it

    • Insights provided:

      • Provides the content-category assignment

      • Shows the category confidence level

      • Highlights policy implications associated with the categorization

  • Private application troubleshooting

    • Prompt: "Why can’t <End User Name> access <Private Resource>?"

    • Why it works:

      • Triggers a multi-step diagnostic covering user identity, device posture, network connectivity, DNS resolution, and policy enforcement across the access path

    • Insights provided:

      • Validates resource reachability

      • Provides policy-evaluation and enforcement results

      • Checks device enrollment and posture

      • Shows DNS-resolution status

      • Analyzes network connectivity

  • Public application troubleshooting

    • Prompt: "Why can’t <End User Name> access <Public App>?"

    • Why it works:

      • Investigates public application access failures by correlating user identity, web-proxy logs, content categorization, and policy evaluation

    • Insights provided:

      • Provides web-proxy enforcement results

      • Shows the impact of content categories and URL filtering

      • Validates user identity and access method

      • Checks DNS resolution and connectivity

Secure Firewall prompts

Cisco Secure Firewall provides centralized threat protection, policy enforcement, routing, VPN connectivity, and health monitoring across distributed environments.

Use cases:

  • Firewall inventory

  • Routing and VPN monitoring

  • Management and search

  • Audit and policy analysis

  • Health monitoring

  • VPN troubleshooting

Try these prompts:

  • VPN tunnel status

    • Prompt: "What is the current status of all my site-to-site VPN tunnels?"

    • Why it works:

      • Provides an immediate, high-level health check of the VPN environment

    • Insights provided:

      • Identifies which tunnels are active versus inactive

      • Helps enable rapid triage before users report connectivity issues

  • VPN diagnostics and investigation

    • Prompt: "Are there any IKE negotiation failures on my VPN tunnels?"

    • Why it works:

      • IKE (Internet Key Exchange) negotiation failures are a common VPN issue

    • Insights provided:

      • Helps isolate authentication or parameter mismatch problems

      • Reduces time spent troubleshooting unrelated physical or routing issues

  • VPN tunnel stability

    • Prompt: "Which tunnels have had the most disruptions this month?"

    • Why it works:

      • Shifts focus from current status to recurring operational issues

    • Insights provided:

      • Helps identify unstable or flapping tunnels

      • Can reveal ISP instability, hardware degradation, or persistent configuration issues

  • VPN knowledge and best practices

    • Prompt: "What are the best practices for site-to-site VPN configuration?"

    • Why it works:

      • Encourages proactive optimization instead of reactive troubleshooting

    • Insights provided:

      • Helps ensure configurations align with security best practices

      • Can reduce future vulnerabilities and performance bottlenecks

Catalyst SD-WAN prompts

Cisco Catalyst SD-WAN provides centralized, policy-driven connectivity across branches, data centers, cloud environments, and SaaS applications.

Use cases:

  • Operational insights

  • Security insights

  • Network and application health

  • Circuit and bandwidth monitoring

  • VPN and tunnel health

  • Security-event investigation

  • Client and endpoint visibility

  • Events and diagnostics

  • Application quality of experience

Try these prompts:

  • Network and application health overview

    • Prompt: "Give me a summary of my network and application health."

    • Why it works:

      • High-level prompts provide a quick operational snapshot of overall network conditions

      • Helps quickly determine whether issues exist before investigating specific areas

    • Insights provided:

      • Overall health indicators across sites and WAN links

      • Summary of application performance across the SD-WAN network

      • Identification of degraded links, sites, or applications requiring further investigation

  • WAN bandwidth and utilization analysis

    • Prompt: "Can you show the Rx/Tx bandwidth rates, utilization, and peak usage for all my WAN links?"

    • Why it works:

      • Monitoring utilization helps identify congestion and capacity limitations impacting application performance and user experience

      • Rx/Tx bandwidth visibility helps identify asymmetric traffic patterns

      • Peak usage provides historical context beyond point-in-time metrics

    • Insights provided:

      • Current Rx and Tx bandwidth rates across WAN links

      • Utilization levels for each WAN circuit

      • Peak bandwidth usage and traffic spikes

      • Identification of congested or underutilized circuits

  • Application performance and SLA monitoring

    • Prompt: "How are my applications performing, and are there any SLA violations in my SD-WAN network?"

    • Why it works:

      • Application experience is a key indicator of overall network health

      • SLA violations highlight when network conditions impact application performance

      • Helps identify business-critical applications experiencing degraded performance

    • Insights provided:

      • Application latency, packet loss, and performance metrics

      • Applications experiencing SLA violations

      • Prioritization of remediation efforts for business-critical applications

  • Application usage visibility

    • Prompt: "What is the usage of applications in my SD-WAN network?"

    • Why it works:

      • Understanding application traffic distribution helps with capacity planning and policy optimization

      • Identifies applications consuming the most bandwidth across the network

    • Insights provided:

      • Application traffic distribution across the SD-WAN network

      • Top bandwidth-consuming applications

      • Application usage trends and traffic patterns

Collaboration Control Hub prompts

Cisco Collaboration Control Hub provides centralized administration, monitoring, analytics, and troubleshooting for meetings, calling, video devices, and collaboration services.

Use cases:

  • Cloud-meeting and call troubleshooting

  • On-premises calling troubleshooting

  • Video-endpoint monitoring

  • Meeting and call search

  • Audio- and video-quality analysis

  • Join-failure and service-health analysis

  • Participant and endpoint visibility

Try these prompts:

Webex Meetings prompts

The following prompts are examples of supported queries and supported identifiers for Meetings workflows.

  • Supported identifiers

    • Name or email address

    • Conference ID

      • Example: "710387709096844458"

    • Time range

      • Example: "last 7 days" or "26 March 2026"

    • Device name

      • Example: "john doe desk pro"

    • Workspace name

      • Example: "tokyo24-11-quiet room 6"

  • Poor quality meeting analysis

    • Prompt: "Show me poor quality meetings for user@company.com"

    • Why it works: Narrowing the query to a specific user helps isolate meeting quality issues and reduces unnecessary results.

    • Insights provided:

      • Identifies meetings with degraded audio or video quality

      • Highlights recurring user experience issues

      • Helps prioritize troubleshooting for affected users

  • Meeting attendance analysis

    • Prompt: "How many meetings did user@company.com attend in the last 7 days?"

    • Why it works: Combining a user identifier with a time range provides targeted participation analysis.

    • Insights provided:

      • Meeting participation trends

      • Usage activity over time

      • User engagement visibility

  • Meeting quality troubleshooting

    • Prompt: "Check user@company.com quality status for the last 3 days"

    • Why it works: Focusing on a recent timeframe helps identify ongoing or recurring quality problems.

    • Insights provided:

      • Audio and video quality trends

      • Recent degradation patterns

      • Potential recurring connectivity issues

  • Packet loss isolation

    • Prompt: "Was the packet loss on my side or the other participants in meeting 70826389765?"

    • Why it works: Isolating packet loss sources helps determine whether the issue originated locally or remotely.

    • Insights provided:

      • Source of packet loss

      • Participant-side versus local network issues

      • Faster root cause identification

  • Network troubleshooting

    • Prompt: "Troubleshoot network issue for John Doe in meeting 70826389765"

    • Why it works: Combining user and meeting identifiers enables deeper session-level analysis.

    • Insights provided:

      • Network quality indicators

      • Session-specific troubleshooting details

      • Potential connectivity bottlenecks

  • Meeting join analysis

    • Prompt: "Did any participants have issues joining meeting 70826389765 on time?"

    • Why it works: Join behavior analysis helps identify authentication, connectivity, or performance issues affecting meeting access.

    • Insights provided:

      • Delayed or failed joins

      • User onboarding problems

      • Meeting access patterns

  • Device-based meeting analysis

    • Prompt: "Analyze meetings in the last 7 days for device 'john doe desk pro'"

    • Why it works: Device-focused analysis helps determine whether quality issues are tied to a specific endpoint.

    • Insights provided:

      • Device-specific quality trends

      • Endpoint performance visibility

      • Hardware-related issue detection

  • Workspace meeting analysis

    • Prompt: "Tell me about the last meeting in the Tokyo-21 workspace"

    • Why it works: Workspace-focused queries provide operational visibility into shared meeting environments.

    • Insights provided:

      • Recent meeting activity

      • Workspace utilization details

      • Room-specific quality insights

Webex Calling prompts

The following prompts are examples of supported queries and supported identifiers for Calling workflows.

  • Supported identifiers

    • Name or email address

    • Phone number

      • Example: "+12345678900"

    • Correlation ID

      • Example: "4505c58b-e183-9e0d-9d16-587455d97487"

    • Call ID (case-sensitive)

      • Example: "sse0134213360303261757062387@10.192.72.201"

    • WXC Session ID

      • Example: "wxcsid_v7_4519447e-9505-4bkc-ad2l"

    • Time range

      • Example: "last 7 days" or "26 March 2026"

  • Poor quality call analysis

    • Prompt: "Show me calls with poor quality for John Doe"

    • Why it works: Filtering by user helps isolate calling issues to a specific endpoint or user experience.

    • Insights provided:

      • Calls with degraded quality

      • User-specific call performance

      • Trends in call reliability

  • Calling history analysis

    • Prompt: "Analyze user@company.com Webex Calling calls in the last 7 days"

    • Why it works: Combining a user identifier with a defined timeframe enables focused usage and quality analysis.

    • Insights provided:

      • Historical calling activity

      • Call quality trends

      • Usage visibility over time

  • Phone number search

    • Prompt: "Show me all calls from phone number +16693084178 in past 14 days"

    • Why it works: Phone-number-based searches simplify tracing communication activity across time periods.

    • Insights provided:

      • Call history visibility

      • Activity tracking

      • Communication pattern analysis

  • Correlation ID search

    • Prompt: "Search for calls with correlation id '4505c58b-e183-9e0d-9d16-587455d97487' going back 30 days"

    • Why it works: Correlation IDs allow precise investigation of specific call sessions and backend events.

    • Insights provided:

      • Detailed session-level troubleshooting

      • Event correlation visibility

      • Faster root cause investigation

  • Device-based call analysis

    • Prompt: "Analyze calls in the last 7 days for device 'john doe desk pro'"

    • Why it works: Device-focused analysis helps determine whether quality issues are linked to a specific endpoint.

    • Insights provided:

      • Device-specific call quality trends

      • Endpoint health visibility

      • Hardware or connectivity issue identification

Webex Workspace and Device prompts

The following prompts are examples of supported queries and supported identifiers for Workspace and Device workflows.

  • Supported identifiers

    • Device name

      • Example: "john doe desk pro"

    • Workspace name

      • Example: "tokyo24-11-quiet room 6"

    • Time range

      • Example: "last 7 days" or "26 March 2026"

  • Supported query areas

    • Device inventory and status

    • Device search and error visibility

    • Device configuration and event history

    • Workspace utilization and occupancy trends

    • Environmental metrics and analytics

    • Location search and capacity planning

  • Device status visibility

    • Prompt: "How many devices are online?"

    • Why it works: High-level inventory prompts provide immediate operational awareness across deployed devices.

    • Insights provided:

      • Online versus offline device counts

      • Device availability visibility

      • Operational status overview

  • Workspace utilization analysis

    • Prompt: "Which of my workspaces had the most use in the last 7 days?"

    • Why it works: Workspace usage trends help identify heavily utilized collaboration spaces.

    • Insights provided:

      • Workspace utilization patterns

      • High-demand locations

      • Capacity planning insights

  • Workspace inventory analysis

    • Prompt: "How many devices does workspace 'Tokyo-21' have?"

    • Why it works: Workspace-specific inventory queries provide focused operational visibility.

    • Insights provided:

      • Device counts per workspace

      • Workspace equipment visibility

      • Deployment planning support

  • Calling configuration visibility

    • Prompt: "How many devices have calling configured?"

    • Why it works: Configuration-focused prompts help validate deployment readiness and feature adoption.

    • Insights provided:

      • Calling-enabled device counts

      • Deployment coverage visibility

      • Configuration tracking

  • Issue pattern detection

    • Prompt: "List all the devices with issues and find any common patterns among the issues"

    • Why it works: Pattern analysis helps identify recurring operational problems affecting multiple devices.

    • Insights provided:

      • Shared failure indicators

      • Recurring device issues

      • Faster troubleshooting prioritization

  • Workspace issue analysis

    • Prompt: "How many workspaces have issues and what is the common pattern among the issues?"

    • Why it works: Correlating workspace issues helps identify systemic environmental or deployment problems.

    • Insights provided:

      • Workspace issue trends

      • Common operational patterns

      • Potential root cause indicators

Splunk prompts

Splunk prompts provide operational, service, and observability data across integrated Splunk products.

Splunk Cloud prompts

Splunk Cloud Platform provides an environment for collecting, searching, analyzing, and acting on operational and security data. Splunk IT Service Intelligence helps correlate events and understand service impact, while Splunk Observability Cloud provides real-time visibility into applications, infrastructure, and user experiences.

Use cases:

  • Splunk index discovery

  • Natural-language questions over Splunk data

  • SPL query generation

  • SPL query explanation

  • SPL query execution

Try these prompts:

  • Splunk deployment health

    • Prompt: "How is the health of my Splunk deployment?"

    • Why it works:

      • Provides a high-level overview of system status, allowing for proactive monitoring of the entire environment.

      • Essential for identifying resource bottlenecks before they impact end-user performance.

    • Insights provided:

      • Overall system health such as indexer health, errors, or licence usage.

      • Identification of potential performance system-wide issues.

  • Performance monitoring

    • Prompt: "What is the p95 latency per Splunk service for the last 24 hours?"

    • Why it works:

      • Focuses on user experience by tracking the 95th percentile latency, which is more representative of real-world performance than averages.

      • Helps establish performance baselines for individual services.

    • Insights provided:

      • Latency trends across different Splunk services.

      • Identification of specific services experiencing performance degradation.

  • Error tracking & diagnostics

    • Prompt: "Show me HTTP 5xx errors by endpoint in Splunk in the past 24 hours"

    • Why it works:

      • Directly targets server-side failures that prevent successful data ingestion or user requests.

      • Allows for rapid debugging of specific API endpoints.

    • Insights provided:

      • Overall error posture.

      • Identification of problematic endpoints causing service failures.

    • Prompt: "Which Splunk services have an error rate above 2 percent in the last hour?"

    • Why it works:

      • Enables real-time incident response by filtering out noise and highlighting critical service degradation.

      • Helps prioritize troubleshooting efforts based on impact thresholds.

    • Insights provided:

      • Immediate identification of services performing below acceptable quality standards.

      • Critical failure points requiring urgent attention.

  • Alert & data integrity

    • Prompt: "Summarize any alerts from our Splunk system"

    • Why it works:

      • Consolidates disparate alerts into a single, actionable summary, reducing "alert fatigue."

      • Facilitates faster incident management and triage.

    • Insights provided:

      • Summary of cconfigured alerts.

      • Overview of triggered alert patterns.

    • Prompt: "Are any hosts not reporting to Splunk?"

    • Why it works:

      • Ensures data integrity and visibility across the entire infrastructure.

      • Detects potential gaps in data ingestion.

    • Insights provided:

      • Duration and list of hosts not reporting to Splunk.

      • Possible root causes to investigate.

  • Security & access management

    • Prompt: "Show any failed Splunk login attempts in the last 24 hours grouped by user"

    • Why it works:

      • Crucial for maintaining strong security posture.

      • Helps distinguish between simple errors and potential unauthorized access attempts.

    • Insights provided:

      • Audit trail of failed authentication attempts.

      • Identification of users or accounts experiencing recurring access issues.

Splunk IT Service Intelligence (ITSI) prompts

Splunk IT Service Intelligence correlates operational events into service-aware episodes, helping teams reduce alert noise and understand service impact.

Use cases:

  • Episode discovery

  • Episode-detail retrieval

  • Episode summarization

  • Impacted-object analysis

  • Similar-episode discovery

  • External ticket and runbook retrieval

note.svg

Replace <episode-id> with the complete UUID of an ITSI episode. Episode-specific prompts require a valid UUID.


  • Critical episode monitoring

    • Prompt: "Show me all active critical episodes from the last 24 hours."

    • Why it works:

      • Combines an explicit lookback period with active state and critical severity to produce a focused worklist instead of every open episode

    • Insights provided:

      • Provides active critical episodes with their episode IDs, severity, status, owner, and event count

      • Provides an immediate view of what needs attention first

  • Recurrence analysis

    • Prompt: "Has episode <episode-id> happened before?"

    • Why it works:

      • Clearly requests recurrence analysis while supplying the episode ID required for similarity scoring

    • Insights provided:

      • Indicates whether similar historical episodes were found

      • Identifies historically similar episodes and the fields that drove each match

  • Unassigned episode triage

    • Prompt: "Show up to 100 active Medium-severity episodes from the last 24 hours and identify which are unassigned."

    • Why it works:

      • Pairs a supported lookback and severity filter with an ownership check, turning episode volume into an actionable staffing view

    • Insights provided:

      • Identifies active Medium-severity episodes with no current owner

      • Highlights triage and coverage gaps in the on-call rotation

  • Episode detail inspection

    • Prompt: "Get details for episode <episode-id>."

    • Why it works:

      • Supplies the required episode ID and retrieves the authoritative record that anchors follow-up investigation

    • Insights provided:

      • Provides the title, description, severity, status, owner, event count, and timestamps

      • Provides the episode policy, activity state, and handling instructions when available

  • Complete incident briefing

    • Prompt: "Give me a full picture of episode <episode-id>: details, summary, impacted objects, and existing tickets."

    • Why it works:

      • Names every required artifact and keeps the full multi-skill investigation anchored to one episode ID

    • Insights provided:

      • Provides a combined briefing covering metadata, AI narrative, impact, and existing tickets

      • Provides the context needed to open or update an incident record in one response

  • Blast radius analysis

    • Prompt: "What is the blast radius of episode <episode-id>?"

    • Why it works:

      • Uses impact language that maps to affected services, entities, and KPIs, producing a stakeholder-ready scope assessment

    • Insights provided:

      • Identifies the services, entities, and KPIs affected by the episode

      • Indicates whether the incident is contained to one component or spreading

  • Latest AI-generated summary

    • Prompt: "Give me the latest AI-generated summary for episode <episode-id>."

    • Why it works:

      • Explicitly requests the most recent narrative, which matters because the analysis changes as new events enter the episode

    • Insights provided:

      • Summarizes what happened, which services were affected, and the current status

      • Indicates whether the latest summarization is complete or still pending

  • Suspected root causes

    • Prompt: "What are the suspected root causes of episode <episode-id>?"

    • Why it works:

      • Targets the suspected-root-cause results directly so the response leads with hypotheses to validate instead of symptoms

    • Insights provided:

      • Provides ranked suspected root causes extracted from the episode events

      • Provides a starting hypothesis to confirm or rule out during remediation

  • Tickets and runbook references

    • Prompt: "What external tickets and runbook URLs are linked to episode <episode-id>?"

    • Why it works:

      • Checks for existing work and documented procedures before responders create duplicate tickets or improvise remediation steps

    • Insights provided:

      • Provides linked Jira or ServiceNow tickets with direct URLs

      • Provides runbook and documentation references attached to the episode

  • Prioritized service-impact view

    • Prompt: "Show the top 5 critical ITSI episodes from the last 24 hours and list the impacted services for each."

    • Why it works:

      • Bounds the episode list before expanding impact details, creating a prioritized view of current business-service risk

    • Insights provided:

      • Ranks critical episodes alongside the services each episode affects

      • Identifies which business services carry the greatest current risk

Splunk Observability Cloud prompts

Splunk Observability Cloud provides full-stack visibility across infrastructure, applications, services, and user experiences to support real-time troubleshooting.

Use cases:

  • Network-versus-application analysis

  • Application-impact assessment

  • Root-cause analysis

Try these prompts:

  • Open-ended root cause analysis

    • Prompt: "Run a root cause analysis for ThousandEyes alert <alert-id>."

    • Why it works:

      • Names the analysis, alert source, and alert ID while leaving the conclusion open so the evidence drives the result

    • Insights provided:

      • Provides a network-or-application verdict with an explicit confidence score

      • Identifies endpoint request-duration changes and the ThousandEyes test that detected the problem

      • Provides an evidence chain explaining which side was ruled out and why

  • Branch alert root cause analysis

    • Prompt: "Create an RCA for Meraki alert <alert-id>."

    • Why it works:

      • Identifies the Meraki source and alert ID, enabling correlation with application evidence and branch-network context

    • Insights provided:

      • Provides a verdict and confidence, including the metric family that drove the conclusion

      • Shows the blast radius across Meraki networks and the timing of correlated alerts

      • Provides a customer WAN assessment, including locations where telemetry is unavailable

  • Network-versus-application classification

    • Prompt: "Is ThousandEyes alert <alert-id> caused by the network or the application? Provide an RCA."

    • Why it works:

      • Poses the core binary directly and requests the evidence behind the classification, making the answer clear and auditable

    • Insights provided:

      • Provides a direct classification with a confidence score

      • Explains why the alternative explanation is less likely

      • Provides endpoint-level or network-metric evidence supporting the verdict

  • Comparative hypothesis analysis

    • Prompt: "Determine whether Meraki alert <alert-id> is explained better by network issues or application latency."

    • Why it works:

      • Frames both hypotheses in measurable terms and supports a confidence-weighted comparison when the signals are mixed

    • Insights provided:

      • Identifies the better-supported hypothesis and the strength of support

      • Shows the specific network and application degradations found, including their magnitudes

      • Explains why the weaker hypothesis was ruled out

  • Two-sentence RCA summary

    • Prompt: "Summarize the RCA for Meraki alert <alert-id> in two sentences."

    • Why it works:

      • Sets an explicit length, producing a concise update suited to ticket comments, chat messages, and status reports

    • Insights provided:

      • Summarizes the verdict and confidence

      • Provides the strongest piece of supporting evidence

  • Concise evidence-backed summary

    • Prompt: "For ThousandEyes alert <alert-id>, provide a concise RCA summary with supporting evidence for the leading hypothesis."

    • Why it works:

      • Balances brevity with auditability and acknowledges that the result is a ranked hypothesis rather than absolute certainty

    • Insights provided:

      • Provides the leading hypothesis and confidence score

      • Highlights only the strongest supporting signals instead of the full evidence set

      • Recommends the next investigation step