Introducing Edge Processor: Next Gen Data Transformation

We get it — not only can it take a lot of time, money and resources to get data into Splunk, but it also takes effort to shape the data in a way that will provide you the most value. But it doesn’t have to anymore, thanks to Splunk’s latest innovation in data processing.

Splunk is pleased to announce the general availability of Splunk Edge Processor, a service offering within Splunk Cloud Platform designed to help customers achieve greater efficiencies in data transformation close to the data source, and improved visibility into data in motion. Edge Processor provides customers new abilities to filter and mask, and otherwise transform their data, before routing it to supported destinations. Edge Processor joins Ingest Actions as part of Splunk’s pre-ingest data transformation capabilities. All current Edge Processor features are free to all Splunk Cloud customers.

What gives Edge Processor its data transformation power is Splunk’s next generation data search and preparation language, SPL2. With SPL2, customers have much more flexibility to shape data so that it is formatted exactly how they want before sending it to be indexed.

Unique to Edge Processor is its architecture, chiefly the cloud-based control plane. Edge Processor nodes are easily installed and configured on customer servers or customer cloud infrastructure using a single command, and managed completely from Splunk Cloud Platform. These nodes are an intermediate forwarding tier, and receive data from edge sources. Customers manage their entire fleet of edge processors and have visibility into both inbound and outbound data volumes through their edge processor network, all from a single place. Any node can then scale horizontally to handle increasing processing or data volume requirements by simply adding instances.

Customers have detailed metrics to view the impact of their pipelines on data flowing through each of their edge processors and can closely track unexpected spikes or troughs in their data

From the central cloud control plane, customers define data processing logic — pipelines — that dictate their desired filtering, masking and routing logic, and can apply their pipelines to any or all edge processors in their network. Edge Processor pipelines are constructed using SPL2 in the new pipeline editor experience, where users can see previews of the data showing the impact of applying a pipeline before making a change.

The data plane remains completely within the customer control — customers point data sources to an edge processor node that is installed on their hosts, and that data is only sent to where customers direct it to be sent. At launch, Edge Processor can receive data from Splunk Universal and Heavyweight Forwarders, and route data to Splunk Enterprise, Splunk Cloud Platform, and Amazon S3.1

Customers have a guided pipeline editor experience with the ability to preview the effect of their pipeline on sample data that they provide

Edge Processor using SPL2 makes data transformation easy and flexible. One of the most common use cases for Edge Processor is to filter verbose data sources, such as Windows event logs, to retain selected events or content within an event. An explicit set of examples for this use case is retaining only Windows events that match a certain event code, masking the extensive message field at the end of Windows events, and routing an unfiltered copy of data to an AWS S3 bucket. The pipelines below show how these examples are constructed; the user controls what data the pipeline applies to, how that data is to be processed, and then where the processed data is routed to.

Pipeline definition (SPL2)
$source
$destination
Filter Windows system events on event id, route to Splunk Cloud index “Security”
$pipeline =
| from $source
// Extract event code field
| rex field=_raw
/EventCode=(?P<event_code>\d+)/
// retain all events with windows event code = 9
| where event_code = 9
| into $destination;
sourcetype =
winEventLog:
system
Splunk index:
Security
Mask Windows system events to remove the final “Message” contents, route this copy to Splunk Cloud index “Main”
$pipeline =
| from $source
| eval _raw=replace(_raw,
/(Message=.*[\r\n?|\n])((?:.|\r\n?|\n)
*)/, "\\...")
| into $destination;
sourcetype =
winEventLog:
system
Splunk index:
Main
Route unfiltered copy of ALL Windows events to AWS S3 bucket “Windows”
$pipeline =
| from $source
| into $destination;
Sourcetype =
winEventLog*
S3 bucket:
Windows

With Edge Processor, customers will experience increased visibility of data in motion and improved productivity, simplicity, and control of data transformations, all at scale. What’s more, Edge Processor is another capability to help customers manage costs and boost value from your Splunk investment, serving as a sort of forcing function to organize and prioritize your data according to use case so that you work with just the data you want, in the location you need it.

If you are a current Splunk Cloud Platform customer hosted in the US or Dublin Splunk Cloud regions, you can get access to Edge Processor today. Contact by your Splunk sales representative, or send an email to EdgeProcessor@splunk.com with your company name, Splunk cloud stack name, and Splunk Cloud region. If you are a Splunk Cloud Platform customer hosted in other Splunk Cloud regions, also contact your Splunk sales representative or send an email to get on the list to be enabled once Edge Processor is available in your region.

For more about Edge Processor, including release plans to support additional sources, destinations, and new functionality, see release notes and documentation.

[1] See release notes for updates on new features, including additional supported sources and destinations.

----------------------------------------------------
Thanks!
Jodee Varney

Related Articles

Access the Cloud Monitoring Console from Anywhere
Platform
2 Minute Read

Access the Cloud Monitoring Console from Anywhere

Have you ever wanted to check the status of your Splunk Cloud Platform deployment but can't easily access your laptop? We've got you covered — the Cloud Monitoring Console is now available on Spunk Mobile.
Empower Your Organization with Splunk On the Go
Platform
2 Minute Read

Empower Your Organization with Splunk On the Go

Get an overview of Splunk Mobile, learn about new Splunk Mobile features, and find out how easy it is to build dashboards for Splunk Mobile.
Go with your Data Flow - Improve your Machine Learning Pipelines
Platform
3 Minute Read

Go with your Data Flow - Improve your Machine Learning Pipelines

How do you organize the data flow in Splunk Enterprise or Splunk Cloud? Splunker Philipp Drieger shares typical data pipeline patterns that will help you improve your existing or future machine learning workflows with MLTK or DLTK.
Dashboard Studio Tips: What's New in 8.2.2106
Platform
2 Minute Read

Dashboard Studio Tips: What's New in 8.2.2106

You asked, we answered. The Dashboard Studio release in Splunk Cloud Platform 8.2.2106 comes with improvements requested by you: UI to add data sources to inputs, hiding the Edit or Open in Search buttons, a brand new markdown visualization, and more!
Deep Learning Toolkit 3.6 - Automated Machine Learning, Random Cut Forests, Time Series Decomposition, and Sentiment Analysis
Platform
3 Minute Read

Deep Learning Toolkit 3.6 - Automated Machine Learning, Random Cut Forests, Time Series Decomposition, and Sentiment Analysis

We’re excited to share that the Deep Learning Toolkit App for Splunk (DLTK) is now available in version 3.6 for Splunk Enterprise and Splunk Cloud. Read all about the updates here.
Introducing Splunk Federated Search
Platform
3 Minute Read

Introducing Splunk Federated Search

We’re excited to share that the Splunk Federated Search is now generally available starting in Splunk Cloud Platform 8.1.2103 and Splunk Enterprise 8.2! Get an introduction to Federated Search and see how you can enjoy a unified search experience across your data ecosystem.
Cyclical Statistical Forecasts and Anomalies – Part 5
Platform
5 Minute Read

Cyclical Statistical Forecasts and Anomalies – Part 5

When your datasets are far from simple, your anomaly detection techniques must evolve to scale with the growing complexity. In this blog, you will learn various ways to take your anomaly detection to the next level no matter the complexity of your data.
Dashboard Studio: Dashboard Customization Made Easy
Platform
4 Minute Read

Dashboard Studio: Dashboard Customization Made Easy

Learn more about Splunk Dashboard Studio, a new and intuitive dashboard-building experience, with native capabilities for customizing layout or colors, and adding images or text boxes.
Removing Python® 2 from New Splunk Cloud and Splunk Enterprise Releases Starting Fall 2021
Platform
3 Minute Read

Removing Python® 2 from New Splunk Cloud and Splunk Enterprise Releases Starting Fall 2021

Python 2 will be removed from all new Splunk Cloud and Splunk Enterprise releases starting Fall 2021. Learn how to confirm full Python 3 app readiness for confidence in migrations.