I am looking for network visibility into things such as IDS, firewalls, emails, ldap etc.
I'd just select the proper data, craft a corresponding search after reading all the Splunk docs and then modify it according to my needs.
If you find that answer very generic and not very helpful: Your question is the same. 😉
I've no idea what you want/need, what you already have, where you see the challenges, etc etc.
Please add a lot more details to your question to allow for a good answer.