Splunk Tech Talks
Deep-dives for technical practitioners.

One Log To Rule Them All: Centralized Troubleshooting With Splunk Logs

LesediK
Splunk Employee
Splunk Employee

Screenshot 2023-05-01 at 12.32.51 PM.png

 

WATCH NOW 

In this session, discover how your logs in Splunk help you get more context, reduce silos and improve collaboration across ITOps and engineers. With a cool demo led by our talented PM, you’ll learn how to extend logs from Splunk Cloud Platform or Splunk Enterprise and reuse them in Splunk Observability Cloud.

 

(view in My Videos)

You’ll see how  to correlate logs with traces and metrics in a single point-and-click interface and improve the visibility of your environment. Finally, you’ll learn more about our freshly launched logging features that will help you perform better log-based analysis.

Tune in to learn about using your logs for Observability  use cases:

  • Tool consolidation and operational efficiency
  • In-context debugging and root-cause analysis alongside APM and Infrastructure Monitoring
  • Metrics-based monitoring and alerting in customized dashboards

 

Our Speakers

Joanna Zouhour, Product Marketing Manager, Splunk

Rebecca Tortell, Sr. Principal Product Manager, Splunk

LesediK
Splunk Employee
Splunk Employee

May 23 2023 - LIVE Tech Talks Integrations with logs in Observability (3).jpg

​Additional resources  to ​continue your Splunk Logs journey

Training and Courses

Documentation

Customer Success Services

Blog Posts

Research

Splunk Observability Cloud Free Trial 

Related Webinar

LesediK
Splunk Employee
Splunk Employee

Return Home with Knowledge - LIVE Tech Talks Integrations with logs in Observability.jpg

Q&A

Here are a few questions and answers submitted by attendees:

 

Q. Does Splunk Observability Cloud need any agent installed on containers? 

A. Here's our documentation about how to set up the Splunk OpenTelemetry collector

LesediK_7-1676518142760.png

Q. Is there a free cloud sandbox for this (I googled "splunk free sandbox" and got no results). A few years back there were many cloud sandbox options?

A. Get started with a TRIAL.

LesediK_7-1676518142760.png

Q. Is Log Observer available for Splunk Enterprise? Didn't see an app for it on Splunkbase?

A. Log Observer is a no-code experience in Observability Cloud, which is delivered as a SaaS product and not a Splunkbase app. 

LesediK_7-1676518142760.png

Q. How does Splunk Observability Cloud compare to Dynatrace?

A. With Splunk Observability Cloud you can apply the Splunk logs that you're already collecting to your Observability use cases. Other vendors wouldn't be able to show the whole picture in one product. Hope this helps!

LesediK_7-1676518142760.png

Q. Do the trials have demo data?

A. Every Observability Cloud trial includes sample metrics. When you're choosing how to get data in, you'll have the choice to set up the demo system "HipsterShop" to send in sample data to your account, and see the same kind of data I showed today. 

LesediK_7-1676518142760.png

Q. Can you reference or link the Observability dashboards from Splunk Cloud?

A. This is a direction we're looking into. It's somewhat more supported to link to Splunk Cloud from Observability dashboards through a feature called Data Links. Learn more 

LesediK_7-1676518142760.png

Q. From a cyber security/incident response perspective, how does this compare to Splunk Enterprise Security?

A. Splunk Observability Cloud is designed for Devops troubleshooting. This shares elements with security incident response but is distinct in some important ways like the data it uses and the response steps available in the UI. Hope this helps. 

LesediK_7-1676518142760.png

Q. So this supports analyzing logs in the Hybrid cloud right?

A. You can connect logs from Splunk Cloud or Splunk Enterprise to Observability Cloud using Log Observer Connect.

LesediK_7-1676518142760.png

Q. How is Observability being licensed?

A. Check out this page on our website for pricing and packaging information.

LesediK_7-1676518142760.png

Q. Are we able to still write SPL if we need to? also can we do joins and combine lookups like we do in splunk enterprise? are there any features from splunk enterprise dropped in the log observer? Is the summary index feature still available?

A. Log Observer is a no-code experience in Observability Cloud, designed for folks who don't need or want to use the SPL-based interface in Enterprise to troubleshoot with logs. If you need to use SPL, like for joins or combines, Splunk Enterprise is the right interface for you!

LesediK_7-1676518142760.png

Q. If I’m already a Splunk Platform and Observability user, do I get access to these logs capabilities?

A. Yes, you can!

LesediK_7-1676518142760.png

Q. How can I get started today with Splunk Observability Cloud ?

A.

  • Reach out to your account manager
  • Get a 14-day free trial on www.splunk.com 

LesediK_7-1676518142760.png

Q. Does this cost more? Adding logs can have an impact on your Splunk Platform data usage.

A. Talk to your account manager for further details.

LesediK_7-1676518142760.png

Q. Can I connect logs to Observability if I use Splunk on-prem?

A. Observability is provided as SaaS but yes you can. 

LesediK_7-1676518142760.png

Q. Do I need Infrastructure Monitoring, APM or RUM to get started with logs in Observability?

A. In addition to logs data, Observability Cloud also includes infrastructure and application performance monitoring. You need IM or APM or the Observability Cloud Suite.

LesediK_7-1676518142760.png

Q. Where can I learn more about Splunk Observability Cloud?

A. You can visit our website or reach out to your account manager! We’ll also soon launch a way for you to learn more about Observability directly on Splunk Cloud via an app.

LesediK
Splunk Employee
Splunk Employee

Checkout the Blog post and view video highlights, all under 5 minutes! View now One Log to Rule Them All

Contributors
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...