Splunk Cloud Platform

Use Ingest Processors

Add or manage destinations

As an administrator, you can use the Destinations page to add, edit or delete your destinations. The destination is where your Ingest Processor pipelines send data to. You can set a default destination to route unprocessed data by configuring the settings for a given Ingest Processor pipeline.

Add a destination

You add destinations by navigating to the Destinations page, selecting New destination, and then selecting the destination type.
Splunk best practice is to specify a destination as your default destination in addition to other destinations to prevent data loss.

Edit a destination

You can change destination properties by completing the following steps.

  1. Navigate to the Destinations page.
  2. On the Destinations page, in the row that lists the Ingest Processor pipeline that you want to modify, select the Actions icon (Image of the Actions icon) and then select Edit Pipeline.
  3. Update the configuration settings as desired, and then select Save.

It can take a few minutes for these processes to be completed. During this time, the affected Ingest Processor pipelines enter the Pending status.

To confirm that the process completed successfully, do the following:

  • Navigate to the Ingest Processor page. Then, verify that the Instance health column for the affected Ingest Processor pipelines show that all instances are back in the Healthy status.
  • Navigate to the Pipelines page. Then, verify that the Applied column for the affected pipelines contains a The pipeline is applied icon (Image of the "applied pipeline" icon).

You might need to refresh your browser to see the latest updates.

Delete a destination

You can delete a destination by completing the following steps.

  1. Navigate to the Destinations page.
  2. In the row that lists the destination that you want to delete, select the Actions icon (Image of the Actions icon) and then select Delete Pipeline.
  3. Select Delete to confirm your choice.
Last modified on 17 July, 2024
How the destination for Ingest Processor works   Sending data from Ingest Processor to Splunk Cloud Platform

This documentation applies to the following versions of Splunk Cloud Platform: 9.1.2308, 9.1.2312, 9.2.2403, 9.2.2406 (latest FedRAMP release), 9.3.2408


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters