We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization (Auto-schema) a new AI-powered experience in Splunk Data Management that helps administrators plan, parse, structure, and prepare data for Splunk faster.
For many teams, onboarding a new data source can mean inspecting raw events, identifying patterns, writing field extractions, mapping data to the Splunk Common Information Model (CIM), validating outputs, and packaging everything for deployment. Important work? Absolutely. Work everyone wants to do by hand every time? Not so much.
Guided Onboarding with Auto-schema significantly reduces that manual lift from weeks to minutes while keeping admins in control.
What Is Guided Onboarding with Auto-schema?
Guided Onboarding with Auto-schema brings assistant-guided workflows to common data onboarding tasks. The assistant gathers details through chat and structured prompts, then recommends onboarding strategies, generates task lists, or creates schema output based on the scenario you choose. Guided Onboarding with Auto-schema is part of Cisco Data Fabric powered by the Splunk Platform, transforming raw machine data into structured, high-quality, AI-ready intelligence through faster, simpler, and more precise data onboarding.
With this release, you can use guided workflows to:
Plan how to onboard a new data source
Schematize representative custom data
Generate CIM mapping recommendations
Create field extraction logic
Produce deployment-ready outputs such as add-on packages or SPL2 pipeline
Review and edit AI-assisted recommendations before using them
In short: bring representative data, answer guided questions, review the recommendations, and move from raw events toward search-ready data with less friction.
Two Workflows to Help You Get Data In
Guided Onboarding with Auto-schema includes two primary workflows: Plan data onboarding and Schematize custom data.
Scenario
Use this scenario to
Information to provide
Main output
Plan data onboarding
Create an onboarding plan for a data source.
Data source, platform, ingestion preference, volume, latency, and deployment model.
A task list, selected ingestion strategy, and topology information when available.
Schematize custom data
Generate CIM mappings and deployment files for a custom data source.
Destination, source type or source name, and representative sample events.
An add-on package, SPL2 output, or both output types depending on the selected destination.
The planning workflow is useful when you know the source you want to bring into Splunk but need a recommended path to get there. It helps clarify ingestion choices, deployment considerations, and the work required to make the data available.
The schematization workflow is useful when you have representative custom data and want help creating search-ready structure. Auto-schema can identify patterns in sample events, recommend mappings, and help generate outputs that fit the selected destination.
How to Access It
To get started, open the Data Management app in Splunk Cloud Platform. In the left navigation pane, select Scenarios.
OskarPatnaik_0-1785417677813.png
Watch the Walkthrough
Want to see the full flow in action? The walkthrough demos show how Guided Onboarding with Auto-schema helps move from onboarding questions and representative events to recommended schema outputs and deployment artifacts.
See it in Action:
Plan Data Onboarding Demo → Schematize Custom Data Demo →
Responsible AI and User Control
Guided Onboarding with Auto-schema is part of Splunk's AI-powered Data Management capabilities. On first use, users see an AI consent prompt explaining that the feature uses Large Language Models.
The prompt also explains that Splunk may process data directly relevant to the workflow, such as sample log data provided by the user and onboarding responses. Before continuing, users acknowledge the AI use and agree to Splunk's General Terms and Data Security & Privacy Commitment.
OskarPatnaik_1-1785417677814.png
For more information, see Responsible AI for AI-powered Data Management.
Availability
Guided Onboarding with Auto-schema is available for Splunk Cloud Platform customers in selected regions and requires Splunk version 10.4 or higher.
For the latest supported region list, see the Splunk documentation here.
Start Onboarding Faster
Data onboarding is where so much Splunk value begins. Better structure means better searches, better detections, better dashboards, and better operational visibility.
Guided Onboarding with Auto-schema helps admins get there faster, with AI-assisted guidance, generated recommendations, and reviewable outputs that fit into real Splunk workflows.
Less time wrestling with raw data. More time getting value from it. If you’re not subscribed, you’re probably missing something good. Fix that!
... View more