Start a Schematize custom data scenario

Start the Schematize custom data scenario and answer general questions about where to send the data.

You need permission to start Guided Onboarding scenarios. You also need representative sample data for the custom source.

Start this scenario when you need to create field extractions, normalization, and the Common Information Model (CIM) mappings for custom data.

  1. Log in to Splunk Cloud Platform. In the Data Management area, select Scenarios.
  2. On the Scenarios page, select Onboard data.
  3. On the Schematize custom data tile, select Get started.
  4. On the General questions page, select a destination from the Where will the data land? list.
    • Select Splunk index to generate an add-on package for search-time field extractions and CIM mappings.
    • Select External Data Lake to generate SPL2 output for the schema on-write on ingest path.
  5. (Optional) In the field, enter a Splunk source type, such as cisco:asa:syslog, or a source value that starts with source:, such as source:/var/log/app.log. This value is used exactly as the root routing stanza in the generated add-on. If you aren't sure, leave this field blank.
  6. In the Scenario name field, enter a name that identifies the source, destination, or schema goal.
  7. (Optional) Enter additional context in the Description field.
  8. Select Next.

Guided Onboarding records your destination and source information and opens the sample data step.