Splunk Cloud Platform

Use Edge Processors

View data flow information about an Edge Processor

Each Edge Processor measures data flow metrics as it processes data. These metrics are sent to and read from the _metrics index of the Splunk Cloud Platform deployment that's connected to the Edge Processor tenant. You can access a detailed view of a specific Edge Processor to get an overview of how that Edge Processor is configured and how data is flowing through it. Use this detailed view to review the inbound and outbound data metrics of your Edge Processor and confirm whether data is flowing through as expected.

To access a detailed view of a specific Edge Processor, do the following:

  1. Navigate to the Edge Processors page.
  2. In the row that lists the Edge Processor that you want to inspect, select the Actions icon (Image of the Actions icon) and select Open.

The detailed view of an Edge Processor displays the following data flow information. By default, these are metrics from the last 30 minutes, but you can modify the time range. These metrics are not shown in real-time, so refresh the page to see the latest.

Historical metrics only include connected data sources and currently applied pipelines. If you delete a pipeline or configure a data source to no longer point to an Edge Processor, then metrics associated with them are not included in this view.

Component Information displayed
Received data
  • The source types that the connected data sources are sending to this Edge Processor.
  • The amount of data, per source type, that is being sent to this Edge Processor.
Pipelines
  • The number of pipelines that are applied to this Edge Processor.
  • The amount of outbound data that each pipeline is sending to a destination. By comparing this metric to the metric about the amount of inbound data that an Edge Processor is receiving, you can see how much data is being filtered out by each pipeline.
Edge Processor overview
  • The number of pipelines that are connected to this Edge Processor.
  • The default destination that the Edge Processor routes unprocessed data to. Edge Processors without a default destination will drop unprocessed data.
  • The number of source types that are being sent through this Edge Processor.
  • The amount of inbound data that this Edge Processor is receiving from data sources.

This number includes internal events, or events with the splunkd and fwdinfo source types, and it might be higher than expected.

  • The amount of outbound data that this Edge Processor is sending to its destinations.

This data flow information provides an overview of how an Edge Processor is handling data. If you identify a problem, you can view logs to gain further insights and troubleshoot the problem. See View logs for the Edge Processor solution.

Last modified on 30 April, 2024
Verify your Edge Processor and pipeline configurations   View logs for the Edge Processor solution

This documentation applies to the following versions of Splunk Cloud Platform: 9.0.2209, 9.0.2303, 9.0.2305, 9.1.2308, 9.1.2312, 9.2.2403, 9.2.2406 (latest FedRAMP release), 9.3.2408


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters