Prerequisites

Before using the Self-Healing Pipeline feature, verify that your environment meets the following requirements:
  1. Splunk platform environment:

    Make sure you have admin permissions in this Splunk Cloud environment. The Ingest Monitoring app (splunk-ingest-monitoring v1.4.0) is installed.

  2. Common Information Model (CIM) Add-on:

    The Splunk Common Information Model (CIM) app (Splunk_SA_CIM) is installed on your Splunk Cloud Platform instance.

  3. Data model acceleration:

    Acceleration is enabled on the CIM data models you want to monitor (for example: Authentication, Network Traffic, Endpoint, and so on). To verify, perform the following steps:
    1. In Splunk, navigate to Settings > Data Models..

    2. Find the relevant data model and confirm that the Acceleration is turned on.