Splunk® Supported Add-ons

Splunk Add-on for Kafka

Download manual as PDF

Download topic as PDF

Inputs for the Splunk Add-on for Kafka

The Splunk Add-on for Kafka supports three different inputs.

  • A monitor input to collect log files from Kafka machines. This input requires a Splunk forwarder or single instance be installed directly on your Kafka machines.
  • A JMX input to collect performance metrics about your Kafka clusters. This input requires the Splunk Add-on for JMX to be installed on a heavy forwarder so that it can connect to the JMX server on your Kafka machines.
  • A modular input to consume messages from Kafka topics. This input requires the heavy forwarders collecting the Kafka data to be in the same network as your Kafka machines.

Each of the inputs is optional, so you can choose to configure all or only some of them. The diagram below shows a typical deployment scenario in a production environment using all three inputs.
This architectural diagram shows all three inputs, with arrows that show the data ingestion path for each input, from your Kafka servers to one of the three layers of your distributed Splunk platform architecture. Kafka log files collected via monitor inputs on locally installed forwarders can send data directly to indexers. Peformance metrics are collected with the Splunk Add-on for JMX from a heavy forwarder. Messages from Kafka topic are consumed via modular inputs on one or more heavy forwarders.

See the configuration instructions for each input.

Install the Splunk Add-on for Kafka
Configure monitor inputs for the Splunk Add-on for Kafka

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters