Splunk Edge Processor Enhancements Offer Greater Data Access and Improve Data Management

Platform Abbas Saboowala

On the heels of an exciting GA in March and the April announcement of its regional expansion, we are excited to share the latest updates to Splunk Edge Processor that will make it even easier for customers to have more flexibility and control over just the data you want, nothing more nothing less.

Support Data Ingestion and Export Using HTTP Event Collector (HEC)

Users can now experience increased ingestion support from a wide range of applications and products that can send data to Splunk using HEC, and can take advantage of stream processing for third-party sources like VMWare Tanzu, Kubernetes, Kafka, among others. Plus there’s better support for other Splunk-supported apps like Splunk Nozzle for VMware Tanzu, Splunk Connect for Kafka, Splunk Connect for Kubernetes, etc. that send data over HEC. What’s more, in addition to extended ingest support, Edge Processor now also supports exporting to Splunk using HEC.

Want to see it in action? Check out this short video on setting up Edge Processor to receive data from Kubernetes pods over HEC, and creating a pipeline to filter noisy events.

YouTube video player

Assign a Default Destination per Edge Processor

To complement use cases involving data sovereignty, Splunk Admins can now configure a default destination for each Edge Processor node, where previously, only one global destination was available. So, if desired, users can direct unhandled data for each Edge Processor to a destination of their choosing, giving them the control and flexibility to choose how to access data and where to store it. This feature can also support the improvement of your organization's data compliance posture.

Expanded Regional Availability in Four New Markets

Splunk Edge Processor expands its availability to Splunk Cloud stacks in EMEA with the addition of Frankfurt, Germany and London, England; and APAC which now includes Tokyo, Japan and Singapore. To get started using Splunk Edge Processor today, contact your Splunk Account Team to request activation, or send an email directly to EdgeProcessor@splunk.com with your company name, Splunk cloud stack name, and preferred Splunk Cloud region.

For more about Splunk Edge Processor, including plans to support additional sources, destinations, and new functionality, see release notes and documentation.

Related Articles

Removing Python® 2 from New Splunk Cloud and Splunk Enterprise Releases Starting Fall 2021
Platform
3 Minute Read

Removing Python® 2 from New Splunk Cloud and Splunk Enterprise Releases Starting Fall 2021

Python 2 will be removed from all new Splunk Cloud and Splunk Enterprise releases starting Fall 2021. Learn how to confirm full Python 3 app readiness for confidence in migrations.
Introducing SPL2: The Next-Generation Search & Data Preparation Language for Splunk
Platform
5 Minute Read

Introducing SPL2: The Next-Generation Search & Data Preparation Language for Splunk

Announcing the worldwide availability of Search Processing Language version 2 (SPL2), the next evolution of our powerful SPL language for data search and preparation, now in Splunk Enterprise and Splunk Cloud Platform.
Custom Anomaly Detection with Splunk IT Service Intelligence and Machine Learning Toolkit v3.2 - Part 2
Platform
5 Minute Read

Custom Anomaly Detection with Splunk IT Service Intelligence and Machine Learning Toolkit v3.2 - Part 2

Part 2 of a two-part series providing a detailed and technical walkthrough around customizing a custom Splunk ITSI Machine Learning workflow