Splunk Enterprise

Is it possible to forward log events from Splunk Forwarder to OpenTelemetry to Splunk?

Bryan_James
Observer

Hi Everyone!

Recently, we are opting to standardize our monitoring solution. Upon our initial research and development, OpenTelemetry has been the newly established standard for monitoring and observability. Our target is to migrate and be enabled on using OpenTelemetry as part of our policies and standard for monitoring.

We are aware that there is a product called "Splunk Observability Cloud" which onboards OTLP and any supported platforms to a unified observability stack. For the AIOps, I believe this is still within Splunk Enterprise. While previously we have explored the possible movement to cloud, currently, we are still using Splunk Enterprise.

We would like to know if there are any ways we can forward log events to OpenTelemetry, then to Splunk Enterprise. I know this might add overhead as adding another leg (OpenTelmetry) can add additional workload), but this is critical for us to standardize our current monitoring. Here's some items we want to explore:

Splunk-OTEL.drawio.png

 

Here's something we have researched before:

  • Splunk Ingest Actions - I think this is only available for Heavy Forwarder. The documentations however, wasn't able to detail out if OTEL endpoint is supported.
  • Splunk Transforms and Outputs (Heavy Forwarder) - On our initial testing, we weren't able to capture data on OTEL Collector.
  • I don't think there exist a configuration for Universal Forwarder to OTEL Collector.

May I kindly ask for inputs or any insights what are possible solutions for this?

Thank you very much in advanced!

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Enterprise and the Splunk forwarders do not support Open Telemetry.  OTEL is the domain of Splunk Observability, which is a different product/service.

Ingest Actions are available on indexer as well as HFs, but also do not support OTEL.

Consider using Cribl (cribl.io) to transform OTEL data into something Splunk Enterprise can ingest.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...