Skip to main content
App for Cilium app icon

App for Cilium

# Cilium Hubble AppBuilt by Mathieu Hanotaux
splunk product badge

Default Version 0.5.0

October 2, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.6, 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4

Rating
0
(0)

Log in to rate this app

Support
Not Supported

# Cilium Hubble App Dashboards for Kubernetes network flows exported by [Cilium](https://cilium.io/) Hubble, built with Dashboard Studio. ## Requirements * Splunk Enterprise or Splunk Cloud 9.4+ (tested on 10.6). * The [Add-on for Cilium](https://splunkbase.splunk.com/app/7349) 1.0.0+, installed on search heads and indexers. * Hubble exporter configured as described in the add-on documentation (Cilium 1.15+, tested with 1.20). ## Dashboard **Cilium Hubble Flows**, filtered by node and namespace: * *Overview*: flows, dropped flows and drop rate, endpoints, Hubble lost events, flows by verdict, top conversations (Sankey), drop reasons, top dropped connections. * *Drops & Policies*: drops by reason and namespace, network policies matched, latest dropped flows with L7 details. * *DNS*: queries, NXDOMAIN rate, SERVFAIL, return codes over time, top external domains and DNS clients, NXDOMAIN domains, resolved external domains. * *HTTP*: responses by status class, slowest destinations, top requests, requests denied by L7 policies. * *Egress*: traffic leaving the cluster by namespace, external destinations and connections. * *Hubble Health*: flows per node, lost events, agent events, Hubble versions. DNS and HTTP panels require L7 visibility (an L7 network policy or Cilium L7 visibility on the workloads) and the `l7` field in the exporter field mask. With aggregated exporters, only the Overview, Drops and Hubble Health panels are populated. ## Configuration The dashboard searches `index=*` by default. To restrict it to your Cilium indexes, update the `cilium_index` macro (Settings > Advanced search > Search macros), for example `index=cilium`. | Macro | Definition | |--|--| | `cilium_index` | `index=*` | | `cilium_hubble` | all Hubble exporter events (`sourcetype=cilium:hubble:flow`) | | `cilium_flows` | Hubble flows (`eventtype=cilium_flow`) | ## Release notes ### 1.0.0 * First release. In case of any problem with the app, please open an issue at [gitlab.com/mathieuHa/splunk_cilium_app](https://gitlab.com/mathieuHa/splunk_cilium_app) Mathieu HANOTAUX