Splunk Cloud Platform

Use Edge Processors

Quick start: Process and route data using Edge Processors

This quick start is for users who are learning how to use the Edge Processor solution. Complete the following steps to create a basic Edge Processor and pipeline setup that receives data from a forwarder, processes the data as needed, and then sends the processed data to an index or an Amazon S3 bucket.

This diagram shows an overview of the steps required to set up and use an Edge Processor.

Number Task Documentation
1 Verify that your host meets the system and network requirements. Installation requirements for Edge Processors
2 Set up Edge Processors. Set up an Edge Processor
3 (Optional) Configure event breaking and merging for the incoming data that you want your pipelines to process.


You can skip this step if the Edge Processor service already provides event breaking and merging configurations for the source type of the data that you want to work with. Check the Source types page to confirm whether a configuration for your source type already exists.

Add source types for Edge Processors
4 (Optional) Add a destination.

You can skip this step if you want to send data to the Splunk Cloud Platform deployment that's connected to your cloud tenant.
Add or manage destinations
5 Create pipelines to process data. Create pipelines for Edge Processors
6 Get data in to an Edge Processor using forwarders. Get data from a forwarder into an Edge Processor
Last modified on 13 February, 2023
Manage users for the Edge Processor solution   Installation requirements for Edge Processors

This documentation applies to the following versions of Splunk Cloud Platform: 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308, 9.1.2312, 9.2.2403 (latest FedRAMP release), 9.2.2406


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters