Prepare to onboard data
Prepare access, permissions, source information, and sample data before you start an onboarding scenario.
Confirm access requirements
To use the Scenarios, you need access to a Splunk Cloud Platform environment version 10.4 or later where your organization makes the Scenarios available. Your organization might manage access through single sign-on, gateway authentication, or Splunk platform capabilities.
| User action | Required identity and access control scope | Required Splunk capability |
|---|---|---|
| View catalog data, scenarios, questionnaire answers, and strategies | gx.gob.read |
gx_gob_read |
| Create, update, reset, or delete scenarios and update task status | gx.gob.execute |
gx_gob_execute |
If you can view the Scenarios page but cannot create scenarios or update tasks, ask a Splunk administrator for permission to start scenarios and update tasks.
Gather details to plan data onboarding
Gather the following details before you start the Plan data onboarding scenario:
- Your onboarding goal, such as security monitoring, compliance reporting, operational monitoring, or incident investigation.
- The data source that you want to onboard, if you already know it.
- Your Splunk platform type, such as Splunk Cloud Platform or Splunk Enterprise.
- Your expected daily data volume.
- The data arrival latency you need, such as real-time, near real-time, or batch delivery.
- Your filtering preference, such as bringing in all data or reducing data before or while you send it to Splunk software.
- The destination Splunk index and source type requirements for the data.
Gather details to create a schema for data
Gather the following details before you start the Schematize custom data scenario:
- Where you want to send the data, such as a Splunk index or External Data Lake.
- The source type or source name for incoming data, if you already know it.
- Representative sample events from the custom source that include typical activity, errors, and edge cases.
Review Responsible AI information
Before you use scenarios, review Responsible AI for AI-powered Data Management to learn how Splunk uses AI-powered features, protects data, and supports human review.