Machine Data Lake prerequisites

Verify the Splunk Cloud Platform, Data Management, Ingest Processor, search, service-account, user-permission, and routing requirements before onboarding Machine Data Lake.

Before you begin checklist

Verify each requirement before you create a raw table. Use the observable result, not only the existence of a configuration item, to decide whether the environment is ready.

  • Splunk Cloud Platform version and Machine Data Lake availability

    How to verify: Confirm that the target Splunk Cloud Platform environment runs a supported version and is enabled for Machine Data Lake. For current requirements, see Release notes.

    Expected result: The target environment supports Machine Data Lake raw table creation, data landing, raw search, promotion preview, and promotion workflows.

    If verification fails: Contact Splunk Support before onboarding.

  • Data Management connection

    How to verify: Open Data Management and confirm that the intended Splunk Cloud Platform deployment is available as the connected target. For first-time setup, see First-time setup instructions for the Ingest Processor solution.

    Expected result: Data Management can create and manage resources for raw tables, data landing, preview, and promotion in the intended deployment.

    If verification fails: Complete or repair the Data Management connection setup before you create a raw table.

  • Search head target

    How to verify: Confirm that the Data Management connection and service account use the same search head unit (SHU) or search head cluster that customers use for Machine Data Lake workflows.

    Expected result: Users create and manage raw tables, data landing, raw search, promotion preview, and promotion workflows from the SHU linked to the Data Management connection. In most environments, use the default search head.

    If verification fails: If the environment has multiple SHUs or you need a different search head, such as a search head that runs Splunk Enterprise Security, contact Splunk Support before changing the target.

  • Data Management service account

    How to verify: Confirm that the service account used by Data Management calls to Splunk Cloud Platform exists and can complete Data Management setup checks.

    Expected result: Service-account calls to the target deployment succeed.

    If verification fails: Follow the service-account setup instructions in First-time setup instructions for the Ingest Processor solution. If setup still fails, contact Splunk Support.

  • Service account role

    How to verify: Verify that the Splunk Cloud Platform role assigned to the Data Management service account includes list_search_head_clustering, edit_spl2_datasets, edit_connections, edit_datasets, read_datasets, write_datasets, read_connections, indexes_edit, and search.

    Expected result: The service account role includes every required capability and is provisioned for the same SHU or search head cluster as the Data Management connection. If the role is updated, Machine Data Lake workflows become available after propagation completes.

    If verification fails: Recheck the documented service-account role setup and verify that the role includes every required capability. If the role is still missing or incomplete, contact Splunk Support. After the role is updated, verify the workflow again after the change propagates.

  • Ingest Processor resources

    How to verify: Verify that Ingest Processor resources are available and healthy for dataset landing and promotion flows. Review applicable limits in Service limits and constraints.

    Expected result: Data landing and streaming promotion workflows have available Ingest Processor capacity and required services report healthy status.

    If verification fails: Resolve service health or capacity issues before creating raw tables or streaming promotions. If the required health or capacity status is not available to you, contact Splunk Support.

  • SPL2 and data orchestration services

    How to verify: Verify that SPL2 modules and data orchestration services are available for raw table search and analytics search.

    Expected result: Raw table search and analytics search paths are available after data lands or promotion completes.

    If verification fails: Ask an administrator to verify SPL2 modules and data orchestration service health before you retry the workflow. If the services remain unavailable, contact Splunk Support.

  • User permissions

    How to verify: Confirm that the user has the dataset access and role capabilities required for the intended action. For details, see Access control, roles, and capabilities.

    Expected result: The user can see the required dataset, creation, search, promotion, sharing, edit, or delete action in the workflow.

    If verification fails: Ask an administrator to grant or update the required role, dataset access level, or sharing capability.

  • Input and routing strategy

    How to verify: Confirm the supported input path, such as HEC, Universal Forwarder, or Heavy Forwarder, and decide whether matching events land only in Machine Data Lake or land in Machine Data Lake and also continue to an existing Splunk index path where supported.

    Expected result: Events are already reaching the Machine Data Lake-enabled Splunk Cloud Platform environment, and the expected routing model is documented before raw table creation.

    If verification fails: Prepare the source first. For details, see Prepare a data source for Machine Data Lake.