Splunk Search

Ingest processor problem

acs12
Engager

Hello,

How can I use the ingest processor to obtain the actual ingest without that information reaching the cloud?

My data is sent as follows:
UF - HF -Cloud

With this, once it has passed through the ingest, I don't want it to be ingested into the cloud.

 

regards

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

Ingest Processor is in Splunk Cloud.

You can use it to filter events and discard part of them, but the action are applied on Splunk Cloud, so logs must arrive to Splunk Cloud and eventually be deleted before indexing.

It's different using Edge Processor that works also on-premise, but I don't know it very well.

Ciao.

Giuseppe

0 Karma

acs12
Engager

Hello,

So I can indicate that all events from that source (it is the only data source) should be deleted and thus nothing will be ingested, is that correct?

Best regards

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.

Ciao.

Giuseppe

0 Karma

acs12
Engager

Thank you for everything, it has been very helpful.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...