Prepare for onboarding

Verify the environment, permissions, service account, source input, and routing strategy before you land data in Machine Data Lake.

Use this section as a before-you-begin checklist. Complete each verification before creating a raw table or changing a production data route.

  • Machine Data Lake availability and supported Splunk Cloud Platform version

    Confirm that Machine Data Lake is available in the Splunk Cloud Platform environment and that the environment runs a supported version.

    Raw table creation, data landing, preview, raw search, and promotion workflows are available only in supported environments.

    See Machine Data Lake prerequisites.

  • Data Management connection and search-head target

    Confirm that the Data Management connection uses the intended Splunk Cloud Platform deployment and the correct search-head target. Confirm that the connection status is connected.

    The connection determines where Data Management creates and manages raw tables, data landing definition, preview, raw search, and promotion workflows.

    See:

  • Data Management service account

    Confirm that the Data Management service account exists, is configured, and uses a role with the required capabilities.

    Service-account configuration controls whether Data Management can create and manage Machine Data Lake resources in the target deployment.

    See:

  • User permissions and dataset access

    Confirm human-user permissions, dataset access levels, Open Sharing capability, and audit expectations.

    Users see only the datasets and actions that roles, dataset permissions, administrator privileges, and supported policies allow.

    See Access control, roles, and capabilities.

  • Ingest Processor readiness

    Confirm that Ingest Processor requirements are met, required resources are healthy, and you know how to verify inbound and outbound data metrics for an active pipeline.

    Machine Data Lake uses Ingest Processor resources for data landing and streaming promotion workflows.

    See:

  • SPL2-dependent service health

    Confirm that SPL2-dependent services that support preview, raw search, analytics search, and promotions report healthy status.

    These services must be available before users can validate, search, and activate landed data.

    See Machine Data Lake prerequisites.

  • Supported input path

    Confirm a supported input path, such as HEC, Universal Forwarder, or Heavy Forwarder.

    Events must reach the Machine Data Lake-enabled Splunk Cloud Platform environment before data landing definition can select matching events.

    See Prepare a data source for Machine Data Lake.

  • Routing strategy for matching events

    Decide whether matching events land only in Machine Data Lake, or land in Machine Data Lake and also continue to an existing Splunk index path where supported.

    The routing decision controls whether current searches, dashboards, alerts, Enterprise Security content, or rollback plans continue using an existing index during onboarding.

    See Choose an MDL data strategy.

  • Observable validation plan

    Plan to use a uniquely identifiable test event and searches for Machine Data Lake and any preserved Splunk index path.

    A test event verifies event arrival. Metadata in the Catalog can refresh later and must not be the only validation signal for recent data.

    See Onboard your first data source.

After you complete these checks, see Create a Machine Data Lake raw table.