<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Ingest Actions in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749857#M119130</link>
    <description>What you are meaning with “ that our deployment and indexer are on the same server”?&lt;BR /&gt;What is this deployment, is it deployment server or something else? Have you one indexer or several and/or cluster? When you are deploying with IA are targets only HFs or are you managing also UFs or other HFs without IA rulesets?</description>
    <pubDate>Tue, 15 Jul 2025 21:04:48 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2025-07-15T21:04:48Z</dc:date>
    <item>
      <title>Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749590#M119085</link>
      <description>&lt;P&gt;Trying to filter out all perfmon data using ingest actions. so, i try and see the samples and i get this error&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tbarn005_0-1752181708177.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39631i1A9AE14BC3600750/image-size/large?v=v2&amp;amp;px=999" role="button" title="tbarn005_0-1752181708177.png" alt="tbarn005_0-1752181708177.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I checked to see if my forwarders have the same&amp;nbsp;pass4SymmKey and they did. I am not sure what to do im checking now to ensure the FW isnt blocking communication but i think that is unlikely. I can see the servers in forwarder management picking up the deployment apps from the indexer. anyone have any ideas??&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 21:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749590#M119085</guid>
      <dc:creator>tbarn005</dc:creator>
      <dc:date>2025-07-10T21:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749607#M119091</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/274539"&gt;@tbarn005&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you confirm which pass4SymmKey you have verified is the same across the SH and HFs?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The pass4SymmKey&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;under&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;deployment&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;stanza in&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;server.conf&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;matches between deployment server and heavy forwarder is used for the Ingest Action preview and I believe this cannot be a default value.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;For more info and diagnostic/troubleshooting check out&amp;nbsp;&lt;A href="https://splunk.my.site.com/customer/s/article/Ingest-Actions-are-not-working" target="_blank"&gt;https://splunk.my.site.com/customer/s/article/Ingest-Actions-are-not-working&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jul 2025 07:47:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749607#M119091</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-07-11T07:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749781#M119114</link>
      <description>What is your architecture and how you have configured IA?</description>
      <pubDate>Mon, 14 Jul 2025 21:28:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749781#M119114</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-07-14T21:28:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749843#M119121</link>
      <description>&lt;P&gt;So we have a single search head here. I should mention that our deployment and indexer are on the same server. I am aware that best practices is to separate them. Do you think this could be it?&amp;nbsp; As far as how i've configured Ingest actions I only have one rule now to drop all PerfmonMk:CPU &amp;gt; filter using regex &amp;gt;&amp;nbsp; "^PerfmonMk:CPU$" it does not seem to be dropping the data&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 18:36:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749843#M119121</guid>
      <dc:creator>tbarn005</dc:creator>
      <dc:date>2025-07-15T18:36:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749846#M119124</link>
      <description>&lt;P&gt;Yes, this is one of the first things i've found when searching and i reset that password on both the indexer and my forwarders and still nothing&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 18:49:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749846#M119124</guid>
      <dc:creator>tbarn005</dc:creator>
      <dc:date>2025-07-15T18:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749857#M119130</link>
      <description>What you are meaning with “ that our deployment and indexer are on the same server”?&lt;BR /&gt;What is this deployment, is it deployment server or something else? Have you one indexer or several and/or cluster? When you are deploying with IA are targets only HFs or are you managing also UFs or other HFs without IA rulesets?</description>
      <pubDate>Tue, 15 Jul 2025 21:04:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749857#M119130</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-07-15T21:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749905#M119142</link>
      <description>&lt;P&gt;To clarify, we’re running a single Splunk instance where the Deployment Server, Indexer, and Search head all reside on the same server so it’s a non-distributed architecture. When I mentioned “deployment,” I was referring both to our overall Splunk setup and the fact that our Deployment Server shares the same host as the Indexer. We have only one indexer, no clustering, and no heavy forwarders (HFs) in use. However, we do have universal forwarders (UFs) installed on various servers, and they’re configured to send data directly to the indexer. Regarding Ingest Actions (IA), I’ve configured one rule locally on the indexer to drop data from the source type PerfmonMK:CPU. The rule uses a regex filter (^PerfmonMk:CPU$) with a drop action. IA rules are applied only on the indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jul 2025 15:49:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749905#M119142</guid>
      <dc:creator>tbarn005</dc:creator>
      <dc:date>2025-07-16T15:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Ingest Actions</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749908#M119143</link>
      <description>Ok. It’s better to use terminology from Splunk SVA documentation &lt;A href="https://docs.splunk.com/Documentation/SVA/current/Architectures/TopologyGuidance" target="_blank"&gt;https://docs.splunk.com/Documentation/SVA/current/Architectures/TopologyGuidance&lt;/A&gt;. In that way we all understand better and clearly what others have. In this case you have single server installation (S1).&lt;BR /&gt;When you have S1 and also DS role configured into it and you want to use IA, I’m not sure if that is valid architecture or not with IA? You cannot configure server itself with DS and when you are using IA in server with DS I’m not sure if IA part is always use DS or not in that case? Also UFs is not supported platform for IA and it could try to install also IA part to those?&lt;BR /&gt;Can you find anything else from internal logs which can explain what has happened?</description>
      <pubDate>Wed, 16 Jul 2025 17:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Ingest-Actions/m-p/749908#M119143</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-07-16T17:02:25Z</dc:date>
    </item>
  </channel>
</rss>

