icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Data Onboarding Checklist
SHA256 checksum (data-onboarding-checklist_007.tgz) 9ab6169cf037761b2d69c3d5db00c2122e356b49071c5c88fb1700c3c1a050f6 SHA256 checksum (data-onboarding-checklist_006.tgz) 692215fd7d9f1aae95fd275add57154a4d91f22122a65942ec4581cd42dcd6d1 SHA256 checksum (data-onboarding-checklist_005.tgz) f2caaec8a7e39cd9cb7dbb1b46da1a2491de73eadf01e3dcb1e05b78a3c884ef
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Data Onboarding Checklist

Splunk Cloud
Overview
Details
Data Onboarding Checklist helps to onboard sourcetypes using established best practices, avoid common pitfails and validate data.

"Garbage in, garbage out" is an important concept to keep in mind when working with data in Splunk. This phrase emphasizes that the quality of the input data has a direct impact on the accuracy and usefulness of the results obtained from Splunk. If low-quality, wrong-parsed or incomplete data is used as input, it can result in inaccurate or unreliable output. The Data Onboarding Checklist App provides required steps and assists you during Get-Data-In-Process.

This is a beta release. Send your feedback, corrections and suggestions to splunk@compek.net

Onboarding Checklist helps to onboard sourcetypes using established best practices, avoid common pitfails and validate data.

"Garbage in, garbage out" is an important concept to keep in mind when working with data in Splunk. This phrase emphasizes that the quality of the input data has a direct impact on the accuracy and usefulness of the results obtained from Splunk. If low-quality, wrong-parsed or incomplete data is used as input, it can result in inaccurate or unreliable output. The Onboarding Checklist provides required steps and assists you during Get-Data-In-Process.

Go through these steps from top to bottom. Click on each step to perform validation and read additional information.

CheckExpected Result
Source: Timestamp and TimezoneTimestamp and Timezone are correct, there are no "future" events.
Indexer: Timestamp and TimezoneTimestamp and Timezone are correct, there are no "future" events.
Logging delayThere are no significat logging delays.
Indexer: Timestamp RecognitionTimestamp parsed correctly, there are no "defaulting to previous" .
Index is explicitly definedCorrect index is used. Nothing in "main" or "lastchance".
Sourcetype is explicitly definedCorrect sourcetype.
Host extractionMake sure host extracted or set correctly.
IntegrityAll events reach Splunk, no events are lost.
Integrity (network interruptions)Short network interruptions shouldn't lead to a loss of events.
Secure TransferTLS, certificate validation, mTLS
TruncationLong events aren't truncated.
Multiline for single-line-eventsThere are no multiline events for single-line sourcetypes.
Linebreaking of multiline eventsMultiline events are splitted correctly.
DuplicatesThere are no duplicate events.
Field ExtractionEvents parsed correctly, fields are extracted.
Setting locationAll settings are placed inside of the respective App/TA. There are no sourcetype related configuration settings in system/local or in unrelated apps/TAs.
Magic 8All of the "Magic 8" configurations are explicitly defined.

Some tips:

  • Start with validation and fixing timestamp issues, before continuing with other steps.
  • Unless all timestamp issues are fixed, set the time picker's latest time in the future, for example +1d - this allows to include events with the wrong timestamp.
  • Most queries require access to the _internal index.

Release Notes

Version 0.0.7
Feb. 29, 2024

added integrity testing scripts and SPL searches

Version 0.0.6
May 25, 2023

improved timestamp error detection, minor fixes

Version 0.0.5
May 3, 2023

first public release, consider it beta


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.