Docs » Metrics pipeline management in Splunk Infrastructure Monitoring » Use data routing to keep, archive, or discard your metrics

Use data routing to keep, archive, or discard your metrics 🔗


Available in Enterprise Edition. For more information, see Subscription types, expansions, renewals, and terminations.


Use data routing to choose how to ingest and store all the metric time series (MTS) that have the same metric. Routing options include to keep metrics in real-time, archive them, or drop them altogether.

Routing exception rules let you modify the behavior of data routing. See Use routing exception rules to route a specific MTS or restore archived data.

Use data routing rules to define how to store your metrics 🔗

Note

All roles can view data routing. You must have the admin user role to edit default routing. For more information, see About roles in Splunk Observability Cloud.

Routing rule options 🔗

You have the following options to route your MTS:

  • Ingest and keep metrics real-time (default). Metrics stored in the real-time tier are available in charts and detectors.

  • Send your data to archived metrics. Archived metrics are not available in charts and detectors. You can change routing to real time or filter a subset of data to real time to make those metrics available in charts and detectors again. You can restore archived data from up to 8 days ago in case you need it.

  • Drop your metrics. If you select this option, metrics are dropped and aren’t available for monitoring. You can still keep aggregated MTS derived from those metrics.

Note

You cannot archive histogram metrics.

Edit the routing rule for a metric 🔗

To edit the routing rules for a metric and its MTS, follow these steps:

  1. Access your Splunk Observability Cloud account.

  2. In the left navigation menu, select Settings > Metrics Pipeline Management to access the landing screen with a list of all your metrics and a summary of their rulesets.

  3. Select or search for a metric to access the metric’s summary page.

  4. From a metric’s summary screen, select Edit next to the Ingestion tile.

  5. In the Update data routing dialog, select the radio button next to the new routing option you want to set.

  6. The system returns to the summary page for the metric. At the top of the page, the system displays a notification about the update:

  • If the update is successful, the notification is highlighted in green. The text confirms that the routing for the metric is updated.

  • If the update isn’t applied, the notification is highlighted in red. The text displays the reason that the update wasn’t applied.

Use routing exception rules to route a specific MTS or restore archived data 🔗

Note

You must have the admin or power user role to create or edit an exception rule. For more information, see About roles in Splunk Observability Cloud.

Use routing exception rules to override archiving selected metrics and their associated MTS.

Routing exception rules allow you to:

  • Change the destination for an MTS.

  • Restore historical archived MTS to real-time storage. You can restore up to 8 days of archived data.

Note that if you create different routing exception rules with the same filters, MPM will not duplicate any MTS. If you decide to send those MTS to real time monitoring, MPM only restores the data points for those MTS once.

Routing exception rule options 🔗

Routing exception rules have the following options:

Field

Description

Required?

Rule name and description

Custom name for the new routing exception rule.

Yes

Filter MTS population for real-time monitoring

Metrics pipeline management routes the population of MTS that match these dimensions to real time instead of archiving them.

Yes

Restore archived MTS from filtered population

The time period before the current time where you want to restore historical archived MTS to real-time storage. When you add or reactivate a rule, if you make any changes to the dimensions, you can set a new restoration window.

No

Add a routing exception rule 🔗

Add a routing exception rule to override the default routing for MTS associated with a metric.

To add the rule, follow these steps:

  1. Access your Splunk Observability Cloud account.

  2. In the left navigation menu, select Settings > Metrics Pipeline Management to access the landing screen with a list of all your metrics and a summary of their rulesets.

  3. Select or search for a metric to access the metric’s summary page.

  4. From a metric’s summary screen, select Add (+) icon in the Routing exceptions tile.

  5. In the Create routing exception rule dialog, complete the options. See Routing exception rule options.

  6. The system returns to the summary page for the metric. Check the status column to verify the routing exception has been added successfully.

Edit a routing exception rule 🔗

Note

To change the restoration time period, deactivate the routing exception rule, and then reactivate it and choose a new time window.

To edit an existing routing exception rule, perform the following steps:

  1. Access your Splunk Observability Cloud account.

  2. In the left navigation menu, select Settings > Metrics Pipeline Management to access the landing screen with a list of all your metrics and a summary of their rulesets.

  3. Select or search for a metric to access the metric’s summary page.

  4. From the list of rules, find the one you want to change, then select Edit in the More actions (â‹®) menu.

  5. In the dialog, update the routing exception settings you want to change, and select Update. See Routing exception rule options.

Activate or deactivate a routing exception rule 🔗

Caution

Activating a routing exception rule might move archived MTS to real-time storage and your usage will most likely increase.

Deactivating a routing exception rule makes real-time data for those MTS unavailable. Historical data already routed to real-time metrics is not modified and stays in charts.

To activate or deactivate a routing exception rule, follow these steps:

  1. Access your Splunk Observability Cloud account.

  2. In the left navigation menu, select Settings > Metrics Pipeline Management to access the landing screen with a list of all your metrics and a summary of their rulesets.

  3. Select or search for a metric to access the metric’s summary page.

  4. In the list of rules, find the rule. If it was deactivated, its status is Inactive.

  5. In the More actions (â‹®) menu, select Activate or Deactivate, and confirm.

  • If activating the exception rule moves MTS from archived to real-time storage, metrics

  • The dialog also lets you choose the amount of historical archived MTS to restore.

Delete a routing exception rule 🔗

Caution

When you delete a routing exception rule, the related MTS are no longer routed to real-time metrics. As a result, charts and detectors that depend on the MTS stop working.

To delete a routing exception rule, follow these steps:

  1. Access your Splunk Observability Cloud account.

  2. In the left navigation menu, select Settings > Metrics Pipeline Management to access the landing screen with a list of all your metrics and a summary of their rulesets.

  3. Select or search for a metric to access the metric’s summary page.

  4. In the list of rules, find the rule you want to delete.

  5. In the More actions (â‹®) menu, select Delete and confirm.

Extrapolate data in charts and dashboards 🔗

During and after restoring data, you might see horizontal lines going across the empty part of the chart and connecting data points. The straight lines on the chart are an extrapolation that connects 2 existing data points. They correspond to the archived data that was not restored because they were not included in the exception rule.

You can set the extrapolation policy in the Configure Plot setting to either Last Value or Zero, which changes the straight lines into a horizontal 1 or 0.