Getting Data In

Can you suggest a best approach for Splunk Data On boarding and data segregation?

rohitvjoshi
Path Finder

Let us say we are getting data from 2 different sources called A and B. The data is coming under the index called "Example". A user wants to segregate the data for both A an B sources and data is forwarded from multiple servers. Is there a different approach we can follow or that you can recommend?

Tags (1)
0 Karma
1 Solution

DalJeanis
Legend

Your options are (1) override the sourcetype and/or index based on source (2) filter the searches based on source.

The approach to recommend depends on what you mean by "segregate". If your client wants certain people to only be able to see certain parts of the data, and needs to be absolutely certain of that fact -- certain enough to satisfy a savvy auditor -- then the ONLY method to recommend is to split them into different indexes.

On the other hand, if it's more of a convenience thing, then a search macro filtering based on source may be sufficient for the need.

View solution in original post

0 Karma

DalJeanis
Legend

Your options are (1) override the sourcetype and/or index based on source (2) filter the searches based on source.

The approach to recommend depends on what you mean by "segregate". If your client wants certain people to only be able to see certain parts of the data, and needs to be absolutely certain of that fact -- certain enough to satisfy a savvy auditor -- then the ONLY method to recommend is to split them into different indexes.

On the other hand, if it's more of a convenience thing, then a search macro filtering based on source may be sufficient for the need.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...