Splunk Enterprise

Is it possible to forward log events from Splunk Forwarder to OpenTelemetry to Splunk?

Bryan_James
Observer

Hi Everyone!

Recently, we are opting to standardize our monitoring solution. Upon our initial research and development, OpenTelemetry has been the newly established standard for monitoring and observability. Our target is to migrate and be enabled on using OpenTelemetry as part of our policies and standard for monitoring.

We are aware that there is a product called "Splunk Observability Cloud" which onboards OTLP and any supported platforms to a unified observability stack. For the AIOps, I believe this is still within Splunk Enterprise. While previously we have explored the possible movement to cloud, currently, we are still using Splunk Enterprise.

We would like to know if there are any ways we can forward log events to OpenTelemetry, then to Splunk Enterprise. I know this might add overhead as adding another leg (OpenTelmetry) can add additional workload), but this is critical for us to standardize our current monitoring. Here's some items we want to explore:

Splunk-OTEL.drawio.png

 

Here's something we have researched before:

  • Splunk Ingest Actions - I think this is only available for Heavy Forwarder. The documentations however, wasn't able to detail out if OTEL endpoint is supported.
  • Splunk Transforms and Outputs (Heavy Forwarder) - On our initial testing, we weren't able to capture data on OTEL Collector.
  • I don't think there exist a configuration for Universal Forwarder to OTEL Collector.

May I kindly ask for inputs or any insights what are possible solutions for this?

Thank you very much in advanced!

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Enterprise and the Splunk forwarders do not support Open Telemetry.  OTEL is the domain of Splunk Observability, which is a different product/service.

Ingest Actions are available on indexer as well as HFs, but also do not support OTEL.

Consider using Cribl (cribl.io) to transform OTEL data into something Splunk Enterprise can ingest.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...