Product News & Announcements
All the latest news and announcements about Splunk products. Subscribe and never miss an update!

Guided Onboarding with Auto-schema Is Now Generally Available

OskarPatnaik
Splunk Employee
Splunk Employee

 

We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization (Auto-schema) a new AI-powered experience in Splunk Data Management that helps administrators plan, parse, structure, and prepare data for Splunk faster.  

For many teams, onboarding a new data source can mean inspecting raw events, identifying patterns, writing field extractions, mapping data to the Splunk Common Information Model (CIM), validating outputs, and packaging everything for deployment. Important work? Absolutely. Work everyone wants to do by hand every time? Not so much. 

Guided Onboarding with Auto-schema significantly reduces that manual lift from weeks to minutes while keeping admins in control. 

What Is Guided Onboarding with Auto-schema? 

Guided Onboarding with Auto-schema brings assistant-guided workflows to common data onboarding tasks. The assistant gathers details through chat and structured prompts, then recommends onboarding strategies, generates task lists, or creates schema output based on the scenario you choose. Guided Onboarding with Auto-schema is part of Cisco Data Fabric powered by the Splunk Platform, transforming raw machine data into structured, high-quality, AI-ready intelligence through faster, simpler, and more precise data onboarding. 

With this release, you can use guided workflows to: 

  • Plan how to onboard a new data source 
  • Schematize representative custom data 
  • Generate CIM mapping recommendations 
  • Create field extraction logic 
  • Produce deployment-ready outputs such as add-on packages or SPL2 pipeline 
  • Review and edit AI-assisted recommendations before using them 

In short: bring representative data, answer guided questions, review the recommendations, and move from raw events toward search-ready data with less friction. 

Two Workflows to Help You Get Data In 

Guided Onboarding with Auto-schema includes two primary workflows: Plan data onboarding and Schematize custom data. 

Scenario 

Use this scenario to 

Information to provide 

Main output 

Plan data onboarding 

Create an onboarding plan for a data source. 

Data source, platform, ingestion preference, volume, latency, and deployment model. 

A task list, selected ingestion strategy, and topology information when available. 

Schematize custom data 

Generate CIM mappings and deployment files for a custom data source. 

Destination, source type or source name, and representative sample events. 

An add-on package, SPL2 output, or both output types depending on the selected destination. 

 

The planning workflow is useful when you know the source you want to bring into Splunk but need a recommended path to get there. It helps clarify ingestion choices, deployment considerations, and the work required to make the data available. 

The schematization workflow is useful when you have representative custom data and want help creating search-ready structure. Auto-schema can identify patterns in sample events, recommend mappings, and help generate outputs that fit the selected destination. 

How to Access It 

To get started, open the Data Management app in Splunk Cloud Platform. In the left navigation pane, select Scenarios. 
 

OskarPatnaik_0-1785417677813.png

Watch the Walkthrough 

Want to see the full flow in action? The walkthrough demos show how Guided Onboarding with Auto-schema helps move from onboarding questions and representative events to recommended schema outputs and deployment artifacts. 
 

See it in Action:   

 Responsible AI and User Control 

Guided Onboarding with Auto-schema is part of Splunk's AI-powered Data Management capabilities. On first use, users see an AI consent prompt explaining that the feature uses Large Language Models.

The prompt also explains that Splunk may process data directly relevant to the workflow, such as sample log data provided by the user and onboarding responses. Before continuing, users acknowledge the AI use and agree to Splunk's General Terms and Data Security & Privacy Commitment. 

OskarPatnaik_1-1785417677814.png

For more information, see Responsible AI for AI-powered Data Management.

Availability 

Guided Onboarding with Auto-schema is available for Splunk Cloud Platform customers in selected regions and requires Splunk version 10.4 or higher. 

For the latest supported region list, see the Splunk documentation here.

Start Onboarding Faster 

Data onboarding is where so much Splunk value begins. Better structure means better searches, better detections, better dashboards, and better operational visibility. 

Guided Onboarding with Auto-schema helps admins get there faster, with AI-assisted guidance, generated recommendations, and reviewable outputs that fit into real Splunk workflows. 

Less time wrestling with raw data. More time getting value from it. 

If you’re not subscribed, you’re probably missing something good. Fix that! 

Contributors
Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...