Use Ingest Actions to shrink your ingest and make the most of your license!
- Gabriel Vasseur
- Sep 20, 2024
- 1 min read
Updated: Sep 24, 2024
On the 18th of September 2024 I gave a talk on this topic at the London Splunk User Group meetup.
Ingest Actions are a simple feature of Splunk core that allow you to quickly add index-time masking or routing configuration. It's nothing new compared to SEDCMD or props & transforms, but it's much more user-friendly and it offers a preview mode where you can see the impact of your ingest action BEFORE you impact anything.
Here is the recording:
Passcode: =iJ447JC
(Note: the = is part of the passcode!)
You can download the slides here:
Comments