Splunk Ingest Actions Setup

Use when the user asks to set up Ingest Actions, evaluate or mask data at ingest, drop noisy events before indexing, or stage an RFS S3 destination for a route handoff. Not for Ingest Processor or Edge Processor pipelines. Render, validate, and apply eval, mask, and drop rules as props.conf RULESET and transforms.conf INGEST_EVAL through target-app REST endpoints on Splunk Enterprise or a customer-managed heavy forwarder. For route-s3, apply stages only outputs.conf [rfs:] and exits 2 with an explicit Splunk Web or supported rulesets-API handoff for the route rule. Splunk Cloud is render/handoff-only.

chambear2809 Updated

File contents

chambear2809/splunk-cisco-skills/tree/main/skills/splunk-ingest-actions-setup commit 7a8880aa59

Frequently asked questions

npx skillmds@latest add chambear2809/splunk-ingest-actions-setup