top of page

Use Ingest Actions to shrink your ingest and make the most of your license!

Writer's picture: Gabriel VasseurGabriel Vasseur

Updated: Sep 24, 2024

On the 18th of September 2024 I gave a talk on this topic at the London Splunk User Group meetup.


Ingest Actions are a simple feature of Splunk core that allow you to quickly add index-time masking or routing configuration. It's nothing new compared to SEDCMD or props & transforms, but it's much more user-friendly and it offers a preview mode where you can see the impact of your ingest action BEFORE you impact anything.


 Here is the recording:


 Passcode: =iJ447JC 

 (Note: the = is part of the passcode!)


You can download the slides here:



43 views0 comments

Recent Posts

See All

Comments


©2021 by Gabriel Vasseur. Proudly created with Wix.com

bottom of page