Getting Data In

Splunk Cloud - How do data configurations get specified with UF's and Splunk SaaS indexers + Search Heads

IAskALotOfQs
Explorer

Hi all,

 

I am coming from Splunk on-prem so this is a bit confusing to me. I have looked at architectures regarding Splunk Cloud and can't understand how data configs are done when using Splunk Cloud. For example, let's say:

 

- You have a UF on a machine that forwards data to Splunk Indexers (cloud), you are to make a custom sourcetype for this specific piece of data. Where would you define the parsing rules for this if you don't manage the Indexers. Furthermore if the data can be on-boarded with a TA, how would you install this TA onto the indexers to assist with onboarding (assuming no need for HF)

 

 

Any help would be appreciated, thanks!

Labels (4)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

The cloud is managed by clever automation on Splunk's side so the apps you upload to Cloud land on indexers as well. So the proper way to define index-time props and transforms is to just make an app with those settings and install it on your Cloud instance.

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...