On the 18th of September 2024 I gave a talk on this topic at the London Splunk User Group meetup.
Ingest Actions are a simple feature of Splunk core that allow you to quickly add index-time masking or routing configuration. It's nothing new compared to SEDCMD or props & transforms, but it's much more user-friendly and it offers a preview mode where you can see the impact of your ingest action BEFORE you impact anything.
Here is the recording:
Passcode: =iJ447JC
(Note: the = is part of the passcode!)
You can download the slides here:
Comments