We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization (Auto-schema) a new AI-powered experience in Splunk Data Management that helps administrators plan, parse, structure, and prepare data for Splunk faster.
For many teams, onboarding a new data source can mean inspecting raw events, identifying patterns, writing field extractions, mapping data to the Splunk Common Information Model (CIM), validating outputs, and packaging everything for deployment. Important work? Absolutely. Work everyone wants to do by hand every time? Not so much.
Guided Onboarding with Auto-schema significantly reduces that manual lift from weeks to minutes while keeping admins in control.
Guided Onboarding with Auto-schema brings assistant-guided workflows to common data onboarding tasks. The assistant gathers details through chat and structured prompts, then recommends onboarding strategies, generates task lists, or creates schema output based on the scenario you choose. Guided Onboarding with Auto-schema is part of Cisco Data Fabric powered by the Splunk Platform, transforming raw machine data into structured, high-quality, AI-ready intelligence through faster, simpler, and more precise data onboarding.
With this release, you can use guided workflows to:
In short: bring representative data, answer guided questions, review the recommendations, and move from raw events toward search-ready data with less friction.
Guided Onboarding with Auto-schema includes two primary workflows: Plan data onboarding and Schematize custom data.
|
Scenario |
Use this scenario to |
Information to provide |
Main output |
|
Plan data onboarding |
Create an onboarding plan for a data source. |
Data source, platform, ingestion preference, volume, latency, and deployment model. |
A task list, selected ingestion strategy, and topology information when available. |
|
Schematize custom data |
Generate CIM mappings and deployment files for a custom data source. |
Destination, source type or source name, and representative sample events. |
An add-on package, SPL2 output, or both output types depending on the selected destination. |
The planning workflow is useful when you know the source you want to bring into Splunk but need a recommended path to get there. It helps clarify ingestion choices, deployment considerations, and the work required to make the data available.
The schematization workflow is useful when you have representative custom data and want help creating search-ready structure. Auto-schema can identify patterns in sample events, recommend mappings, and help generate outputs that fit the selected destination.
To get started, open the Data Management app in Splunk Cloud Platform. In the left navigation pane, select Scenarios.
Want to see the full flow in action? The walkthrough demos show how Guided Onboarding with Auto-schema helps move from onboarding questions and representative events to recommended schema outputs and deployment artifacts.
Guided Onboarding with Auto-schema is part of Splunk's AI-powered Data Management capabilities. On first use, users see an AI consent prompt explaining that the feature uses Large Language Models.
The prompt also explains that Splunk may process data directly relevant to the workflow, such as sample log data provided by the user and onboarding responses. Before continuing, users acknowledge the AI use and agree to Splunk's General Terms and Data Security & Privacy Commitment.
For more information, see Responsible AI for AI-powered Data Management.
Guided Onboarding with Auto-schema is available for Splunk Cloud Platform customers in selected regions and requires Splunk version 10.4 or higher.
For the latest supported region list, see the Splunk documentation here.
Data onboarding is where so much Splunk value begins. Better structure means better searches, better detections, better dashboards, and better operational visibility.
Guided Onboarding with Auto-schema helps admins get there faster, with AI-assisted guidance, generated recommendations, and reviewable outputs that fit into real Splunk workflows.
Less time wrestling with raw data. More time getting value from it.
If you’re not subscribed, you’re probably missing something good. Fix that!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.