Splunk Search

Ingest processor problem

acs12
Engager

Hello,

How can I use the ingest processor to obtain the actual ingest without that information reaching the cloud?

My data is sent as follows:
UF - HF -Cloud

With this, once it has passed through the ingest, I don't want it to be ingested into the cloud.

 

regards

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.

Ciao.

Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

Ingest Processor is in Splunk Cloud.

You can use it to filter events and discard part of them, but the action are applied on Splunk Cloud, so logs must arrive to Splunk Cloud and eventually be deleted before indexing.

It's different using Edge Processor that works also on-premise, but I don't know it very well.

Ciao.

Giuseppe

0 Karma

acs12
Engager

Hello,

So I can indicate that all events from that source (it is the only data source) should be deleted and thus nothing will be ingested, is that correct?

Best regards

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.

Ciao.

Giuseppe

0 Karma

acs12
Engager

Thank you for everything, it has been very helpful.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @acs12 ,

good for you, see next time!

Ciao and happy splunking

Giuseppe

P.S.: Karma Points are appreciated 😉

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...