Introducing Ingest Processor: An Evolution in Splunk Data Management

Splunk is pleased to announce the general availability of Ingest Processor, a Splunk-hosted offering within Splunk Cloud Platform designed to help customers achieve greater efficiencies in data transformation and improved visibility into data in motion. Ingest Processor joins Edge Processor, launched last year, to formalize Splunk’s Data Management portfolio, where we continue to invest in a multi-tenant cloud-based architecture to autoscale in response to increased workloads, and SPL2, our next-gen data search and preparation language that offers increased flexibility to shape data - all with an eye on cost-effectiveness.

With Ingest Processor, customers can easily filter, mask, enrich and otherwise transform data at the point of ingest, before routing it to supported destinations Splunk Cloud Platform, Amazon S3 and newly, Splunk Observability Cloud. Unique to Ingest Processor is that it enables a new capability – the conversion of logs to metrics in an effort to further optimize monitoring. Plus, given that this is a Splunk-hosted service, Ingest Processor is offered at two tiers — Essentials and Premier — depending on data processed volumes per day.

Customers now have a choice of deployment model – Edge Processor for those who require more control over data before it leaves their network boundaries and therefore need to host their own infrastructure, or Ingest Processor for customers all in on cloud, and distinctly, who want Splunk to manage the infrastructure for you. Furthermore, both pipeline processors can receive data from Splunk Universal and Heavyweight Forwarders, HEC and syslog.

Check out this video to see it in action.

Availability

At launch, Ingest Processor is available on Splunk Cloud AWS Victoria stacks upgraded 9.1.2312.202. It’s also CCF compliant, but don’t fret – PCI and HIPAA compliance are roadmap items coming soon.

It’s also available in a market near you, with plans for further regional expansion on the roadmap:

Get Started Today!

Managing data volumes is an integral part of a strong data strategy, and Splunk is here to help! To request activation in your environment, please contact your Splunk Account Team or complete this form. Include your company name, Splunk Cloud stack name, and Splunk Cloud region.

For more about Data Management and Ingest Processor, including release plans to support additional sources, destinations, and new functionality, see Splunk Docs for Ingest Processor and Splunk Docs for Splunk Cloud Platform.

Related Articles

What's New in Splunk Cloud Platform
Platform
1 Minute Read

What's New in Splunk Cloud Platform

Splunk Cloud Platform is dedicated to bringing our customers the latest Splunk platform innovations first. This blog series highlights the newest capabilities as they become available. Read on to learn about our latest release, 8.1.2013.
Introducing the Splunk App for Data Science and Deep Learning 5.0
Platform
4 Minute Read

Introducing the Splunk App for Data Science and Deep Learning 5.0

Exciting news: The Deep Learning Toolkit App for Splunk (DLTK) will be renamed the Splunk App for Data Science and Deep Learning (DSDL). It’s slightly lengthy, but a better-suited name because the app is useful for both deep learning and data science operations.
Threat Hunting With ML: Another Reason to SMLE
Platform
4 Minute Read

Threat Hunting With ML: Another Reason to SMLE

This blog is the first in a mini-series of blogs where we aim to explore and share various aspects of our security team’s mindset and learnings. In this post, we will introduce you to how our own security and threat research team develops the latest security detections using ML.