Splunk® Supported Add-ons

Splunk Add-on for Kafka

Acrobat logo Download manual as PDF

Acrobat logo Download topic as PDF

Inputs for the Splunk Add-on for Kafka

The Splunk Add-on for Kafka supports three different inputs.

  • A monitor input to collect log files from Kafka machines. This input requires a Splunk forwarder or single instance be installed directly on your Kafka machines.
  • A JMX input to collect performance metrics about your Kafka clusters. This input requires the Splunk Add-on for JMX to be installed on a heavy forwarder so that it can connect to the JMX server on your Kafka machines.
  • A modular input to consume messages from Kafka topics. This input requires the heavy forwarders collecting the Kafka data to be in the same network as your Kafka machines.

Each of the inputs is optional, so you can choose to configure all or only some of them. The diagram below shows a typical deployment scenario in a production environment using all three inputs.
This architectural diagram shows all three inputs, with arrows that show the data ingestion path for each input, from your Kafka servers to one of the three layers of your distributed Splunk platform architecture. Kafka log files collected via monitor inputs on locally installed forwarders can send data directly to indexers. Peformance metrics are collected with the Splunk Add-on for JMX from a heavy forwarder. Messages from Kafka topic are consumed via modular inputs on one or more heavy forwarders.

See the configuration instructions for each input.

Last modified on 24 April, 2018
Install the Splunk Add-on for Kafka
Configure monitor inputs for the Splunk Add-on for Kafka

This documentation applies to the following versions of Splunk® Supported Add-ons: released

Was this documentation topic helpful?

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters