Splunk Dev

Running splunk in Google App Engine

gmcfall
Engager

We run parts of our application in Google App Engine (GAE).

Is it possible to forward logs from GAE to a remote Splunk indexer?
If so, how?

Tags (4)

Andreux
Splunk Employee
Splunk Employee

It's quite possible; looking at FirePython, it can see application logs from GAE applications. It places them into the HTTP response headers, allowing a Javascript client application to see logs from the GAE python application.

Though I haven't tried this, you could use a similar approach to send logs to the Splunk REST API data input endpoint /receivers/simple by using the GAE urlfetch API (google.appengine.api.urlfetch).

You may like to look at the FirePython middleware implementation here for more details about how to get at the log data, and the Splunk REST API documentation about how to format your HTTP requests.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...