Watch On-Demand. This thread is for the Community Office Hours session on Data Management in Observability Cloud on Tues, May 20, 2025 at 1pm PT / 4pm ET.
Ask the experts at Community Office Hours! An ongoing series where technical Splunk experts answer questions and provide how-to guidance on various Splunk product and use case topics.
What can I ask in this AMA?
- What capabilities does Splunk have to balance costs and data volume?
- How does the Splunk Distribution of the OpenTelemetry Collector help filter out data to reduce ingestion costs?
- What are some ways that I can scale confidently without breaking the bank?
- How can I filter, aggregate, and archive data for optimal storage and analytics?
- Anything else you'd like to learn about!
Please submit your questions at registration. You can also head to the #office-hours user Slack channel to ask questions (request access here).
Pre-submitted questions will be prioritized. After that, we will open the floor up to live Q&A with meeting participants.
Look forward to connecting!
Hello! Here are the recap materials from the session:
Here are the questions that we received in the session (more detailed solutions and info can be found in the slide deck)
Q1: What is the best strategy to reduce ingestion costs? is there a way to show how much is being reduced?
A:
Documentation:
Q2: What are the best recommendations relating to data retention in Splunk, or even cold restore?
A:
Metrics
APM
RUM
Synthetics
Metric Data: 13 Months
Logs
Other
Documentation:
Q3: How would I manage log ingestion made by fluent like we do with Splunk Universal Forwarder and props?
A: The Fluent Forward receiver allows the Splunk Distribution of the OpenTelemetry Collector to collect events using the bundled Fluentd application. The receiver accepts data formatted as Fluent Forward events through a TCP connection. All three Fluent event types, message, forward, and packed forward, are supported, including compressed packed forward.
However, this integration will be deprecated in October of 2025 as we have shifted to native OpenTelemetry log collection.
Our best practice recommendation is as follows:
Documentation: