New Features for Data Inputs

Note:

Data Manager became Data Inputs.

We renamed Data Manager to Data Inputs to better reflect our unified approach to data ingestion. While the name changed, all your existing configurations remain the same.

In Splunk 10.4 and later, a navigation panel consolidates Data Inputs and related features into a single location. From there, you can switch between pages and manage all your data from one place.

Note: Beta features described in this document are provided by Splunk to you "as is" without any warranties, maintenance and support, or service-level commitments. Splunk makes this Beta feature available at its sole discretion and may discontinue it at any time. These documents are not yet publicly available and we ask that you keep this information confidential. Use of Beta features is subject to the

Splunk Pre-Release Agreement for Hosted Services

.
Version 1.17.0 of Data Inputs was released May 21, 2026. It includes the following new features:
New feature Description
Sensor event filters

Control which CrowdStrike Falcon security events are ingested into Splunk. Configure filters in Include or Drop mode during input creation or editing. Filters are shared resources that propagate changes to all referencing inputs.

See Onboard CrowdStrike data

Device properties filters

Control which device fields appear in enriched events. Choose between Enrich mode (include only listed fields) and Drop mode (exclude listed fields) to tailor device context to your analysis needs without ingesting unnecessary data.

See Onboard CrowdStrike data

Shared configurations

Reuse a single filter or API client configuration across multiple CrowdStrike inputs. Edit a shared configuration once, and the change applies everywhere it is referenced.

See CrowdStrike introduction

System-preset filters

Get started immediately with two read-only default configurations that match the behavior of the previous add-on implementation. Clone a preset at any time to create a fully editable copy tailored to your requirements.

See CrowdStrike introduction

Data Management side navigation panel Navigate between Data Management-integrated applications from a collapsible side panel on the left.
Azure Function version bump to 4.5 All Azure CLI and PowerShell commands displayed in the UI for Azure Activity Logs and Active Directory Logs now deploy or update to Azure Monitor Logs Azure Function version 4.5. Existing inputs running version 4.4 can upgrade using the update commands on the input details page.

See Update Azure data inputs to the newest ARM template version

UI theme upgrade The application uses an updated design system. All pages follow the user's color scheme (light and dark) and density setting. Typography, spacing, and interactive controls have been updated across every page.