We are excited to announce several exciting updates for Edge Processor aimed at hardening overall product resiliency and directly addressing some of the top feedback we’ve received from our customers, including support for additional data sources!
You can always check out your Data Management home page for the latest Edge Processor release notes. Here’s what’s new:
Data export queuing resiliency (learn more)
Filled exporter queues can now back pressure data to upstream clients to prevent data loss, which closely mimics the behavior of splunkd’s ingestion pipelines. Along with this change, we’ve also removed the single-threading bottleneck which previously limited overall throughput.
Edge Processor receiver acknowledgement from HEC sources (learn more)
You can now use the new Edge Processor receiver ACK feature to confirm if the Edge Processor successfully received data sent by HEC data sources, thereby bolstering reliability and reducing the risk of overall data loss. This also unlocks data sources that require a form of acknowledgement such as Data Firehose (see below).
AWS Data Firehose support (release notes)
Users can now directly ingest logs from AWS Data Firehose into Edge Processor. With Data Firehose’s integration across 20+ AWS services, you now can easily stream data from sources like Amazon CloudWatch, SNS, AWS WAF, Network Firewall, IoT, and more. See this Lantern article for a step-by-step guide!
Customize timezone in event for syslog data (release notes)
Admins now have the ability to flexibly denote specific time zones on RFC 3164 syslog data that does not have a time zone set. This applies to pipelines bound for the destinations ‘AWS S3’ and ‘Splunk platform using the services/collector/event HEC endpoint’.
Optimized Edge Processor restart behavior (release notes)
This feature reduces the number of restart loops for misconfiguration or error states in Edge Processor. Previously, these types of restart loops could impact other services and result in degraded resource performance - but no more!
Feedback is always welcome in ideas.splunk.com or in the Data Management Slack channel (request access here). Head to the Data Management resource hub for more resources.
Enjoy!
Splunk Data Management Team
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.