Getting Data In

Parsing phase versus parsing pipeline

ddrillic
Ultra Champion

Based on the documentation I read, it appears to me that the Parsing phase is comprised of the parsing pipeline, merging pipeline and the typing pipeline. Is this right? I also wonder at which stage the event is defined. Since the merging pipeline aggregates the lines, I assume that by the end of this merging pipeline, the event is defined. Is this right?

0 Karma

ddrillic
Ultra Champion

The second image keeps disappearing ; -)

alt text

0 Karma

somesoni2
Revered Legend
0 Karma

ddrillic
Ultra Champion

Interesting thing. These pages are a bit different. The second is How Splunk processes data through pipelines and processes

alt text

versus -

alt text

0 Karma
Get Updates on the Splunk Community!

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...

Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting

For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...

Automatic Discovery Part 3: Practical Use Cases

If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...