Getting Data In

What is meant by Splunk integration?

Mohsin123
Path Finder

Hi,

what do you mean by integrating and application with Splunk and what are the steps?

0 Karma
1 Solution

tmarlette
Motivator

This is an extremely broad question, but I might be able to point you in the right direction.

Integrating an application with Splunk:

Integration generally consists of data on-boarding, data cleaning / parsing, and then dashboard creation.

  • first you need to get data from your application into Splunk
  • next, you'll need to clean that data so it makes sense, creating fields, events, transforms, etc..
  • finally, you'll be able to create dashboards showing your application / system within Splunk.

For each of these stages you'll need to understand the data you're looking at, as well as what the final goal is supposed to look like.
Also, for each of these stages, these short sentences do not encompass the entirety of work that goes into 'integration'.

It sounds like you're pretty new to Splunk, so your best bet is to get some education, or begin with a system that already has an app on splunkbase that's easy. This way you don't have to create everything from scratch, and you can start tinkering.

View solution in original post

desoto-chan
Explorer

as already mentioned, it's a broad question. by definition, integration is the process of bringing together the component sub-systems into one system. so you'll link(connect) splunk with other systems (like snow, jira sm, bmc, and others). that's at least what we do. depends on the use case. for our last customer, we integrated splunk with datadog via an external tool. it took few steps & happened in no time.

0 Karma

tmarlette
Motivator

This is an extremely broad question, but I might be able to point you in the right direction.

Integrating an application with Splunk:

Integration generally consists of data on-boarding, data cleaning / parsing, and then dashboard creation.

  • first you need to get data from your application into Splunk
  • next, you'll need to clean that data so it makes sense, creating fields, events, transforms, etc..
  • finally, you'll be able to create dashboards showing your application / system within Splunk.

For each of these stages you'll need to understand the data you're looking at, as well as what the final goal is supposed to look like.
Also, for each of these stages, these short sentences do not encompass the entirety of work that goes into 'integration'.

It sounds like you're pretty new to Splunk, so your best bet is to get some education, or begin with a system that already has an app on splunkbase that's easy. This way you don't have to create everything from scratch, and you can start tinkering.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...