Docs » Metrics pipeline management in Splunk Infrastructure Monitoring » Control your metric ingestion volume with rules

Control your metric ingestion volume with rules 🔗


Available in Enterprise Edition


For each metric you send to Splunk Observability Cloud, you can create various aggregation and data dropping rules to control ingestion and storage volume.

Create rules for a metric 🔗

Follow these steps to create rules for a metric.

  1. From the landing page of Splunk Observability Cloud, go to Settings > Metrics pipeline management.

  2. Select Create new rules.

  3. In the search bar, enter the name of the metric for which you want to create rules.

    Note

    Metrics ingested through the https://ingest.signalfx.com/v1/collectd endpoint might appear in your search, but metrics pipeline management is not available for those metrics.

  4. Select OK.

  5. Add aggregation rules:

    1. Select Add aggregation rule.

    2. Enter the following fields to create an aggregation rule.

      Field name

      Description

      Required?

      Filter population

      Search for dimension keys or values to narrow down the associated metric time series (MTS).

      No

      Specify dimensions: Keep/Drop

      Search for dimensions and select either Keep or Drop. Splunk Observability Cloud saves the dimensions you keep in the new aggregated MTS, and removes the dropped dimensions.

      Yes

      New aggregated metric name

      Select Generate name to use a metric name set by the system, or enter a custom name for your aggregated metric.

      Yes

    3. (Optional) If you want to disable your rule, switch Rule status to Inactive. By default, a new aggregation rule is active.

    4. (Optional) Select Add new aggregation rule and repeat steps 6b-6c to add another aggregation rule.

  6. (Optional) Add dropping rule:

    Note: You need to be an admin to drop data.

    In the Drop unaggregated raw metrics data section, select Drop data to discard the raw unaggregated metric that matches your search in step 3. If you drop raw data, Splunk Observability Cloud retains only the new aggregated metric. By default, Splunk Observability Cloud keeps raw unaggregated data.

    To learn more, see Impact and benefits of dropping data.

  7. Select Save.

  8. Review the resulting volume of MTS.

  9. Select Confirm.