Prepare to onboard data

Prepare access, permissions, source information, and sample data before you start an onboarding scenario.

Confirm access requirements

To use the Scenarios, you need access to a Splunk Cloud Platform environment version 10.4 or later where your organization makes the Scenarios available. Your organization might manage access through single sign-on, gateway authentication, or Splunk platform capabilities.

User action Required identity and access control scope Required Splunk capability
View catalog data, scenarios, questionnaire answers, and strategies gx.gob.read gx_gob_read
Create, update, reset, or delete scenarios and update task status gx.gob.execute gx_gob_execute

If you can view the Scenarios page but cannot create scenarios or update tasks, ask a Splunk administrator for permission to start scenarios and update tasks.

Gather details to plan data onboarding

Gather the following details before you start the Plan data onboarding scenario:

  • Your onboarding goal, such as security monitoring, compliance reporting, operational monitoring, or incident investigation.
  • The data source that you want to onboard, if you already know it.
  • Your Splunk platform type, such as Splunk Cloud Platform or Splunk Enterprise.
  • Your expected daily data volume.
  • The data arrival latency you need, such as real-time, near real-time, or batch delivery.
  • Your filtering preference, such as bringing in all data or reducing data before or while you send it to Splunk software.
  • The destination Splunk index and source type requirements for the data.

Gather details to create a schema for data

Gather the following details before you start the Schematize custom data scenario:

  • Where you want to send the data, such as a Splunk index or External Data Lake.
  • The source type or source name for incoming data, if you already know it.
  • Representative sample events from the custom source that include typical activity, errors, and edge cases.
Note: Remove personally identifiable information, credentials, secrets, and other sensitive values from sample data before you add it to the scenario.

Review Responsible AI information

Before you use scenarios, review Responsible AI for AI-powered Data Management to learn how Splunk uses AI-powered features, protects data, and supports human review.