Splunk Cloud Platform

Use Ingest Processors

View data flow information about an Ingest Processor pipeline

Each Ingest Processor pipeline measures data flow metrics as it processes data. These metrics are sent to and read from the _metrics index of the Splunk Cloud Platform deployment that's connected to the Ingest Processor tenant. You can access a detailed view of a specific Ingest Processor to get an overview of how that Ingest Processor is configured and how data is flowing through it. Use this detailed view to review the inbound and outbound data metrics of your Ingest Processor and confirm whether data is flowing through as expected.

To access a detailed view of a specific Ingest Processor pipeline, do the following:

  1. Navigate to the Ingest Processors page.
  2. In the row that lists the Ingest Processor pipeline that you want to inspect, select the Actions icon (Image of the Actions icon), and select Open.

The detailed view of a Ingest Processor pipeline displays the following data flow information. By default, these are metrics from the last 30 minutes, but you can modify the time range. These metrics are not shown in real-time, so refresh the page to see the latest.

Historical metrics only include connected data sources and currently applied pipelines. If you delete a pipeline, then metrics associated with them are not included in this view.

Component Information displayed
Data sources
  • The source types that the connected data sources are sending to this Ingest Processor.
  • The amount of data, per source type, that is being sent to this Ingest Processor.
Pipelines
  • The number of pipelines that are applied to this Ingest Processor.
  • The amount of outbound data that each pipeline is sending to a destination. By comparing this metric to the metric about the amount of inbound data that a Ingest Processor is receiving, you can see how much data is being filtered out by each pipeline.
Ingest Processor overview
  • The number of pipelines that are connected to this Ingest Processor.
  • The default destination that the Ingest Processor routes unprocessed data to. Ingest Processors without a default destination will drop unprocessed data.
  • The number of source types that are being sent through this Ingest Processor.
  • The amount of inbound data that this Ingest Processor is receiving from data sources.

This number includes internal events, or events with the splunkd and fwdinfo source types, and it might be higher than expected.

  • The amount of outbound data that this Ingest Processor is sending to its destinations.

This data flow information provides an overview of how the Ingest Processor handles data.

Last modified on 17 July, 2024
Verify your Ingest Processor and pipeline configurations   View logs for the Ingest Processor solution

This documentation applies to the following versions of Splunk Cloud Platform: 9.1.2308, 9.1.2312, 9.2.2403, 9.2.2406 (latest FedRAMP release)


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters