Prepare for onboarding
Verify the environment, permissions, service account, source input, and routing strategy before you land data in Machine Data Lake.
Use this section as a before-you-begin checklist. Complete each verification before creating a raw table or changing a production data route.
-
Machine Data Lake availability and supported Splunk Cloud Platform version
Confirm that Machine Data Lake is available in the Splunk Cloud Platform environment and that the environment runs a supported version.
Raw table creation, data landing, preview, raw search, and promotion workflows are available only in supported environments.
-
Data Management connection and search-head target
Confirm that the Data Management connection uses the intended Splunk Cloud Platform deployment and the correct search-head target. Confirm that the connection status is connected.
The connection determines where Data Management creates and manages raw tables, data landing definition, preview, raw search, and promotion workflows.
See:
-
Data Management service account
Confirm that the Data Management service account exists, is configured, and uses a role with the required capabilities.
Service-account configuration controls whether Data Management can create and manage Machine Data Lake resources in the target deployment.
See:
-
User permissions and dataset access
Confirm human-user permissions, dataset access levels, Open Sharing capability, and audit expectations.
Users see only the datasets and actions that roles, dataset permissions, administrator privileges, and supported policies allow.
-
Ingest Processor readiness
Confirm that Ingest Processor requirements are met, required resources are healthy, and you know how to verify inbound and outbound data metrics for an active pipeline.
Machine Data Lake uses Ingest Processor resources for data landing and streaming promotion workflows.
See:
-
SPL2-dependent service health
Confirm that SPL2-dependent services that support preview, raw search, analytics search, and promotions report healthy status.
These services must be available before users can validate, search, and activate landed data.
-
Supported input path
Confirm a supported input path, such as HEC, Universal Forwarder, or Heavy Forwarder.
Events must reach the Machine Data Lake-enabled Splunk Cloud Platform environment before data landing definition can select matching events.
-
Routing strategy for matching events
Decide whether matching events land only in Machine Data Lake, or land in Machine Data Lake and also continue to an existing Splunk index path where supported.
The routing decision controls whether current searches, dashboards, alerts, Enterprise Security content, or rollback plans continue using an existing index during onboarding.
-
Observable validation plan
Plan to use a uniquely identifiable test event and searches for Machine Data Lake and any preserved Splunk index path.
A test event verifies event arrival. Metadata in the Catalog can refresh later and must not be the only validation signal for recent data.
After you complete these checks, see Create a Machine Data Lake raw table.