Use templates to create pipelines for Edge Processors
To help you get started on creating and using pipelines, the Edge Processor solution includes sample pipelines called templates. Templates are Splunk-built pipelines that are designed to work with specific data sources and use cases. Templates include sample data and preconfigured SPL2, so you can use them as a starting point in order to build custom pipelines to solve specific use cases or as a reference to learn how to write SPL2 to build pipelines.
To create a pipeline using a template, complete the following steps.
Before starting to create a pipeline, make sure that the destination that you want the pipeline to send data to is listed on the Destinations page of your tenant. If your destination is not listed on that page, then you must add that destination to your tenant. See Add or manage destinations for more information.
- Navigate to the Pipelines page and select New Pipeline. You can filter the selections to display only the templates you specify.
- Select the pipeline template that you want to use, and then select Next.
- Select or enter a sourcetype to define the subset of data you want this pipeline to process.
- Select Next to confirm your partition.
- Templates include sample data, so you can review and select Next.
- Select the name of the destination that you want to send data to, and then select Done.
- To save this template as a pipeline that you can apply to Edge Processors, do the following:
- Select Save pipeline.
- In the Name field, enter a descriptive name for your pipeline.
- Select Save.
- To apply this pipeline to an Edge Processor, do the following:
- Navigate to the Pipelines page.
- In the row that lists your pipeline, select the Actions icon () and then select Apply/remove.
- Select the Edge Processors that you want to apply the pipeline to, and then select Save.
You can only apply pipelines to Edge Processors that are in the Healthy status.
You can review the comments in the pipeline editor to learn more about what the pipeline will do to the sample data.
It can take a few minutes for the Edge Processor service to finish applying your pipeline to an Edge Processor. During this time, all Edge Processors that the pipeline is applied to enter the Pending status. To confirm that the process completed successfully, do the following:
- Navigate to the Edge Processors page. Then, verify that the Instance health column for the affected Edge Processors shows that all instances are back in the Healthy status.
- Navigate to the Pipelines page. Then, verify that the Applied column for the pipeline contains a The pipeline is applied icon ().
You might need to refresh your browser to see the latest updates.
The Edge Processor that you applied this pipeline to can now process the data it receives based on the processing instructions defined in the template.
Remove pipelines from Edge Processors
Getting sample data for previewing data transformations
This documentation applies to the following versions of Splunk Cloud Platform™: 9.0.2209, 9.0.2303, 9.0.2305 (latest FedRAMP release)