Get started

Enable the Ingest Monitoring app.

Perform the following steps to enable the Ingest Monitoring app:
  1. Log in to your Splunk Cloud Platform instance with an sc_admin or an admin account.

  2. Open the Ingest Monitoring app.

  3. If this is your first time, complete the guided setup and select the indexes you want to monitor.

  4. Select Submit to enable monitoring.

  5. Make sure there is a Data Management navigation pane on the left side of the app.

After setting up, the app begins collecting ingestion metrics and enables the alert system.

Verify the CIM non-compliance template is available

Perform the following steps to verify that the template is available:

  1. In the left navigation page of the Ingest Monitoring app, select Alerts.

  2. Select New alert rule.

  3. On the templates page, confirm that the CIM non-compliance template appears as an option.