Hello,
How can I use the ingest processor to obtain the actual ingest without that information reaching the cloud?
My data is sent as follows:
UF - HF -Cloud
With this, once it has passed through the ingest, I don't want it to be ingested into the cloud.
regards
Hi @acs12 ,
yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.
Ciao.
Giuseppe
Hi @acs12 ,
Ingest Processor is in Splunk Cloud.
You can use it to filter events and discard part of them, but the action are applied on Splunk Cloud, so logs must arrive to Splunk Cloud and eventually be deleted before indexing.
It's different using Edge Processor that works also on-premise, but I don't know it very well.
Ciao.
Giuseppe
Hello,
So I can indicate that all events from that source (it is the only data source) should be deleted and thus nothing will be ingested, is that correct?
Best regards
Hi @acs12 ,
yes, but this selection, using Ingest Processor, must be done on Splunk Cloud before Indexing.
Ciao.
Giuseppe
Thank you for everything, it has been very helpful.
Hi @acs12 ,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉