View data flow information about the Ingest Processor

The Ingest Processor measures data flow metrics as it processes data. These metrics are sent to and read from the _metrics index of the Splunk Cloud Platform deployment that's connected to the Ingest Processor tenant. You can access a detailed view of the inbound and outbound data metrics of your Ingest Processor and confirm whether data is flowing through as expected.

To access data flow information about the Ingest Processor, navigate to the Ingest Processor page.

Note: Do not use the data volume metrics on the Ingest Processor page to plan for Splunk Cloud Platform license usage and provisioning. License usage is based on actual event sizes at ingest time, while the Ingest Processor page shows in-memory event sizes at processing time. Due to the variances between in-memory event sizes and actual event sizes, the data volume metrics on the Ingest Processor page are not accurate for estimating and tracking license usage.

By default, the page shows metrics from the last 30 minutes. You can modify the time range by using the Metrics: Last 30 mins drop-down list. The metrics are not shown in real-time, so you must refresh the page to see the latest.

Be aware that historical metrics only include connected data sources and currently applied pipelines. If you delete a pipeline, then metrics associated with them are not included on this page.

The following table describes the data flow information that is available on the Ingest Processor page.

Component Information displayed
Volume processed in the last <time range> chart
  • The amount of inbound data that the Ingest Processor is receiving.

  • The amount of outbound data that the Ingest Processor is sending out to data destinations.

Note: You can optionally filter the chart for metrics that pertain to specific host, source, or sourcetype values by changing the All data drop-down list on the chart.
Received data page tab
  • The source types of the data that the Ingest Processor is receiving.
  • The amount of data, per source type, that the Ingest Processor is receiving.
Pipelines page tab
  • The number of pipelines that are applied to this Ingest Processor.
  • The amount of inbound data that each pipeline is receiving.
  • The amount of outbound data that each pipeline is sending to data destinations.

    Note: By comparing these inbound and outbound data metrics, you can see how much data is being filtered out by each pipeline.
  • The destinations that each pipeline is configured to send data out to.

This data flow information provides an overview of how the Ingest Processor handles data. If you identify a problem, you can view logs to gain further insights and troubleshoot the problem. See View logs for the Ingest Processor solution.

See also

The Cloud Monitoring Console includes a dashboard for monitoring your Ingest Processor license usage. To navigate to this dashboard, select Usage summary on the Ingest Processor page. For more information, see Use the Ingest Processor dashboard in the Splunk Cloud Platform Admin Manual.