Decide whether Machine Data Lake fits

Decide whether Machine Data Lake is the right model for your source data, routing needs, consumption paths, and governance requirements before you prepare for onboarding.

Use this section to decide whether Machine Data Lake fits the data source that you want to onboard. Before you prepare the environment, define the ingest and routing strategy, the post-landing consumption path, and the custody, retention, permissions, and governance requirements for the data.

Complete the following decisions before you move to onboarding:

  • Confirm whether the data source is a good fit for Machine Data Lake or whether a direct Splunk index path, federated search path, or existing system of record is simpler.

  • Choose how matching events enter Machine Data Lake, including whether to land only in Machine Data Lake or preserve an existing Splunk index path where supported.

  • Choose how to consume landed data after onboarding, such as raw search, static promotion to a Splunk index or analytics table, streaming promotion to a Splunk index, Open Sharing, or federated access to data that remains elsewhere.

  • Confirm custody, governance, retention, permissions, validation, and rollback requirements for the selected strategy.

Start with Choose an MDL data strategy, then review the architecture, concepts, and raw table model for details that affect your decision.

After you choose a data strategy, see Prepare for onboarding.