Splunk Enterprise

Is it possible to forward log events from Splunk Forwarder to OpenTelemetry to Splunk?

Bryan_James
Explorer

Hi Everyone!

Recently, we are opting to standardize our monitoring solution. Upon our initial research and development, OpenTelemetry has been the newly established standard for monitoring and observability. Our target is to migrate and be enabled on using OpenTelemetry as part of our policies and standard for monitoring.

We are aware that there is a product called "Splunk Observability Cloud" which onboards OTLP and any supported platforms to a unified observability stack. For the AIOps, I believe this is still within Splunk Enterprise. While previously we have explored the possible movement to cloud, currently, we are still using Splunk Enterprise.

We would like to know if there are any ways we can forward log events to OpenTelemetry, then to Splunk Enterprise. I know this might add overhead as adding another leg (OpenTelmetry) can add additional workload), but this is critical for us to standardize our current monitoring. Here's some items we want to explore:

Splunk-OTEL.drawio.png

 

Here's something we have researched before:

  • Splunk Ingest Actions - I think this is only available for Heavy Forwarder. The documentations however, wasn't able to detail out if OTEL endpoint is supported.
  • Splunk Transforms and Outputs (Heavy Forwarder) - On our initial testing, we weren't able to capture data on OTEL Collector.
  • I don't think there exist a configuration for Universal Forwarder to OTEL Collector.

May I kindly ask for inputs or any insights what are possible solutions for this?

Thank you very much in advanced!

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk Enterprise and the Splunk forwarders do not support Open Telemetry.  OTEL is the domain of Splunk Observability, which is a different product/service.

Ingest Actions are available on indexer as well as HFs, but also do not support OTEL.

Consider using Cribl (cribl.io) to transform OTEL data into something Splunk Enterprise can ingest.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...