Splunk® Supported Add-ons

Splunk Add-on for Google Cloud Platform

Configure Compute Engine inputs for Splunk Add-on for Google Cloud Platform

Configure Compute Engine inputs for Splunk Add-on for Google Cloud Platform using Splunk Web or via configuration file, using the information in the inputs parameters table below.

The Resource Metadata input has been renamed to Compute Engine starting in version 4.0.

Configure Compute Engine inputs using Splunk Web

  1. Click Create New Input in the Inputs tab, and then choose Resource Metadata, and then choose Compute Engine
  2. Enter the Name, Credentials, Project, Zones, APIs with suitable intervals, Index, and Sourcetype using the information in the inputs parameter table.
  3. Save your changes.

Do not navigate to the Splunk Add-on for Google Cloud Platform configuration page under Settings > Data Inputs to configure Google Cloud Platform inputs. This page is not supported for this type of input.

Configure Compute Engine inputs using configuration files

  1. Create a file named google_cloud_resource_metadata_inputs.conf under $SPLUNK_HOME/etc/apps/Splunk_TA_google-cloudplatform/local.
  2. Create stanzas using the following template. See the google_cloud_resource_metadata_inputs.conf.spec file in $SPLUNK_HOME/etc/apps/Splunk_TA_google-cloudplatform/README for reference).
    [<name>]
    google_apis= <value>
    google_credentials_name = <value>
    google_project = <value>
    google_zones = <value>
    index = <value>
    sourcetype = <value>
    
  3. Save and return to your Splunk instance.

Restart your Splunk platform after making changes to configuration (.conf) files.

Input Parameters

Each attribute in the following table corresponds to a field in Splunk Web.

Attribute Corresponding field in Splunk Web Description
name Name Enter a unique name of the Compute Engine input.
google_credentials_name Credentials The stanza name defined in google_cloud_credentials.conf
google_project Project Google Project ID
google_zones Zones A deployment area for Google Cloud resources within a region.
google_apis APIs Resources of Compute Engine.
index Index The index where your Google Cloud Platform data is stored.
sourcetype Sourcetype Name of the sourcetype.
Last modified on 26 April, 2024
Configure Google Workspace audit logs for the Splunk Add-on for Google Cloud Platform   Configure Cloud Storage inputs for Splunk Add-on for Google Cloud Platform

This documentation applies to the following versions of Splunk® Supported Add-ons: released


Was this topic useful?







You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters