Splunk Search

Ingest processor problem

acs12
Engager

Hello,

How can I use the ingest processor to obtain the actual ingest without that information reaching the cloud?

My data is sent as follows:
UF - HF -Cloud

With this, once it has passed through the ingest, I don't want it to be ingested into the cloud.

 

regards

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

Ingest Processor is in Splunk Cloud.

You can use it to filter events and discard part of them, but the action are applied on Splunk Cloud, so logs must arrive to Splunk Cloud and eventually be deleted before indexing.

It's different using Edge Processor that works also on-premise, but I don't know it very well.

Ciao.

Giuseppe

0 Karma

acs12
Engager

Hello,

So I can indicate that all events from that source (it is the only data source) should be deleted and thus nothing will be ingested, is that correct?

Best regards

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.

Ciao.

Giuseppe

0 Karma

acs12
Engager

Thank you for everything, it has been very helpful.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...