Skip to content
fernet.consultores

Splunk Cloud

Data Onboarding & Integration.

We onboard your data sources into Splunk properly parsed, normalised to the Common Information Model and with an owner.

The problem we solve.

A badly onboarded source is worse than a missing one: wrong timestamps, unextracted fields, split or duplicated events. Searches fail silently and security detections miss what they should catch.

What’s included.

  • Analysis of each source and its volume
  • Configuration of inputs, sourcetypes and parsing
  • Normalisation to the Common Information Model
  • Filtering and masking of sensitive data before indexing
  • Source catalogue with owner and retention

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review your platform, your data sources, your searches and your licence consumption to know where you stand.

We design the solution on Splunk Cloud Platform: indexes, retention, ingest paths, apps and access controls.

We configure inputs, sourcetypes, field extraction and CIM mapping, and filter or mask anything that should not be indexed.

We validate timestamps, fields, volume and CIM conformance with verification searches that we hand over to you.

We measure usage, performance and cost after go-live and adjust what isn't adding value.

Technical capabilities.

  • props.conf and transforms.conf
  • Splunkbase add-ons
  • Common Information Model
  • HTTP Event Collector
  • Data Manager for cloud sources
  • Ingest Actions

Use cases.

Security sources

Firewalls, proxies, Active Directory and endpoints ready for detection.

In-house applications

Logs from internal applications with a custom format.

Public cloud

Logs from AWS, Azure or Google Cloud.

Benefits for your organisation.

  • Reliable searches from day one
  • Detections that see the right data
  • Less useless volume indexed
  • Compliant handling of sensitive data

Deliverables.

  • Configuration for each source
  • Parsing and CIM validation
  • Source catalogue
  • Guide for onboarding new sources

Frequently asked questions.

What if there's no add-on for our source?

We build one: field extraction, a custom sourcetype and CIM mapping, documented so your team can maintain it.

Can you hide personal data?

Yes, by masking or discarding it before indexing, according to what your regulations require.

How do we know a source is well onboarded?

We validate timestamps, fields, volume and CIM conformance with verification searches that we hand over to you.

Shall we talk about Data Onboarding & Integration?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service