Splunk Tech Talks
Deep-dives for technical practitioners.

Connect your Splunk Enterprise Logs with Observability Data

LesediK
Splunk Employee
Splunk Employee

WATCH NOW 

DevOps Edition

Connect your Splunk Enterprise Logs with Observability Data for Faster Troubleshooting and Cross Team Collaboration

Finally, leverage the power of Splunk Enterprise data in Splunk Observability Cloud with Log Observer Connect! Log Observer Connect is a new feature that lets observability users explore the data you’re already sending to your existing Splunk instances with Splunk Log Observer’s intuitive no-code interface for faster troubleshooting and root-cause analysis.

Since Log Observer is part of Splunk Observability Cloud this integration brings metrics, traces, and all your log data, in context, in one UI so SREs and developers can troubleshoot mission critical applications quickly. Bonus, if you happen to be an existing Splunk Enterprise customer who has Splunk Infrastructure Monitoring, Splunk APM, or Splunk Observability Cloud licenses, you automatically get Log Observer Connect at no extra cost.

(view in My Videos)



Watch  and  learn how to get started right away with Log Observer Connect:

  • Set-up roles and permissions in Splunk Enterprise
  • Configure access in Observability Cloud
  • Deep dive into Splunk Enterprise data using intuitive filtering options and save interesting filters as a saved query
  • Finally, find related content from Splunk Enterprise in other Splunk Observability Cloud products such as Splunk Infrastructure Monitoring and Splunk APM that helps developers and SREs with faster root cause analysis!!
LesediK
Splunk Employee
Splunk Employee

Here are additional resources to continue on your journey.

LesediK
Splunk Employee
Splunk Employee

Questions Asked

Q: What impact to SVCs does Log Observer have?

  • A: It depends on usage, really. Log Observer dispatches queries when the user performs operations on the page. All searches are on-demand.

Q: If we are doing SSO and whitelisting IPs, how do you set up the connection?

  • A: At this time, we expect a user to act as a service account to query Splunk. 

Q: Do the Splunk Enterprise search heads have to have a publicly routable internet address for Log Observer to access them?

  • A: At this time - yes. we connect to port 8089. 
Contributors
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...