Splunk Observability Cloud Documentation Observability
  • Service description
  • API docs
  • Blog
  • Training
  • EN | JA
  • Free Trial

Splunk

Get started

  • Get started with Splunk Observability Cloud
  • Overview
  • Architecture
  • Get started guide for admins TOGGLE
  • AI Assistant in Observability Cloud
  • Prompt guide and library for AI Assistant in Observability Cloud
  • Service description
  • Free and paid courses
  • Free trial and guided onboarding
  • About Mobile TOGGLE
  • Support

Scenarios and tutorials

  • Scenarios
  • Tutorials

Splunk platform users

  • Splunk Observability Cloud and the Splunk platform
  • Unified Identity
  • Centralized user and role management
  • Scenarios

Administer Splunk Observability Cloud

  • Set up your Splunk Observability Cloud organization
  • Authentication and Security TOGGLE
  • User and team management TOGGLE
  • Send alert notifications to other services TOGGLE
  • View organization metrics
  • Monitor subscription usage and billing TOGGLE
  • Org reference info TOGGLE

Get your data in

  • Get data into Splunk Observability Cloud
  • Compatibility and requirements
  • Available integrations TOGGLE
  • Connect to your cloud service provider TOGGLE
  • Private connectivity TOGGLE
  • Splunk Distribution of the OpenTelemetry Collector TOGGLE
  • Collect infrastructure metrics and logs TOGGLE
  • Instrument back-end services TOGGLE
  • Instrument serverless functions TOGGLE
  • Instrument front-end applications TOGGLE
  • Other data ingestion methods

Understand and analyze your data

  • Data types in Splunk Observability Cloud
  • Use internal search
  • Metrics, metadata and events TOGGLE
  • Data tools TOGGLE
  • SignalFlow and analytics TOGGLE

Dashboards and charts

  • Dashboards TOGGLE
  • Charts TOGGLE
  • Navigate with data links
  • Select the time range
  • Read and write permissions

Alerts, detectors, and SLOs

  • Alerts and detectors TOGGLE
  • Service level objectives TOGGLE

Application Performance Monitoring

  • Introduction to Splunk APM
  • Key concepts in Splunk APM
  • Scenarios for troubleshooting errors and monitoring application performance using Splunk APM TOGGLE
  • Set up Splunk APM TOGGLE
  • Manage services, spans, and traces in Splunk APM TOGGLE
  • Analyze services with span tags and MetricSets TOGGLE
  • Correlate traces to track Business Workflows TOGGLE
  • Visualize and alert on your application in Splunk APM TOGGLE
  • AlwaysOn Profiling TOGGLE
  • Monitor Database Query Performance TOGGLE
  • Use data links to connect APM properties to relevant resources TOGGLE
  • Filter data in Splunk APM

Infrastructure

  • Introduction
  • Key concepts
  • Set up Infrastructure Monitoring
  • Monitor services and hosts
  • Use navigators
  • Filter data
  • Metrics pipeline management TOGGLE
  • Network Explorer TOGGLE
  • Virtual metrics
  • Resolution and data retention
  • Resolution and data retention (DPM)

Log Observer Connect

  • Splunk Log Observer Connect
    • Introduction to Splunk Log Observer Connect
    • Set up Log Observer Connect for Splunk Cloud Platform
    • Set up Log Observer Connect for Splunk Enterprise
    • Troubleshoot Log Observer Connect setup
    • Reset the default Log Observer Connect index
    • Scenario: Aisha troubleshoots workflow failures with Log Observer Connect
    • View overall system health using the timeline
    • Ensure the correct mapping of your severity key
    • Query logs in Log Observer Connect
    • Browse logs in the logs table
    • Search logs by keywords or fields
    • Open logs in Splunk platform
    • Create field aliases
    • View individual log details
    • Display a field separately in the log details flyout
    • Group logs by fields using log aggregation
    • Add logs data to Splunk Observability Cloud dashboards
    • Where does a log’s logical time come from?
    • Save and share Log Observer Connect queries
    • Forward Log Observer logs data to the Splunk platform
    • Accomplish logs pipeline rules in Splunk platform
    • Log Observer Connect limits

Real User Monitoring

  • Introduction to Splunk RUM
  • Key concepts in Splunk RUM
  • Splunk RUM scenario library TOGGLE
  • Set up Splunk RUM
  • Use controls for sensitive data in Splunk RUM
  • Data collected by Splunk RUM
  • Create custom events
  • Error monitoring and crash aggregation in Tag spotlight
  • Identify errors in browser spans
  • Filter your data by tags in Splunk RUM
  • Write custom rules for URL grouping in Splunk RUM
  • Alert on Splunk RUM data
  • Splunk RUM dashboards TOGGLE
  • Splunk RUM metrics reference
  • Session replay in Splunk RUM
  • Filter and troubleshoot with custom tags
  • Experiment with the demo applications for Splunk RUM for Mobile
  • Third-party software

Synthetics

  • Introduction to Splunk Synthetic Monitoring
  • Key concepts in Splunk Synthetic Monitoring
  • Synthetics built-in dashboards
  • Synthetics scenario library TOGGLE
  • Set up Splunk Synthetic Monitoring
  • Browser tests for webpages TOGGLE
  • Uptime tests for port and HTTP TOGGLE
  • API tests for endpoints TOGGLE
  • Test status TOGGLE
  • Advanced test configurations TOGGLE
  • Troubleshoot tests TOGGLE

Splunk On-Call

  • Introduction to Splunk On-Call TOGGLE
  • User management TOGGLE
  • Create and manage on-call schedules TOGGLE
  • Alerts TOGGLE
  • Notifications TOGGLE
  • Incidents TOGGLE
  • Mobile app TOGGLE
  • Reports TOGGLE
  • Integrations with Splunk On-Call TOGGLE

Release notes

  • Release notes overview TOGGLE

Reference and Legal

  • Third-party software credits
  • Glossary
  • Contribute to our documentation

Related Topics

  • Documentation overview
    • Previous: Resolution and data retention in Splunk Infrastructure Monitoring (DPM plans only)
    • Next: Introduction to Splunk Log Observer Connect
Docs » Splunk Log Observer Connect
Edit this page
Learn how

Splunk Log Observer Connect 🔗

  • Introduction to Splunk Log Observer Connect

  • Set up Log Observer Connect for Splunk Cloud Platform

  • Set up Log Observer Connect for Splunk Enterprise

  • Troubleshoot Log Observer Connect setup

  • Reset the default Log Observer Connect index

  • Scenario: Aisha troubleshoots workflow failures with Log Observer Connect

  • View overall system health using the timeline

  • Ensure the correct mapping of your severity key

  • Query logs in Log Observer Connect

  • Browse logs in the logs table

  • Search logs by keywords or fields

  • Open logs in Splunk platform

  • Create field aliases

  • View individual log details

  • Display a field separately in the log details flyout

  • Group logs by fields using log aggregation

  • Add logs data to Splunk Observability Cloud dashboards

  • Where does a log’s logical time come from?

  • Save and share Log Observer Connect queries

  • Forward Log Observer logs data to the Splunk platform

  • Accomplish logs pipeline rules in Splunk platform

  • Log Observer Connect limits

To keep up to date with changes in Log Observer Connect, see the Splunk Observability Cloud release notes.

This page was last updated on Feb 21, 2025.


❮
Previous
Resolution and data retention in Splunk Infrastructure Monitoring (DPM plans only)
Next
Introduction to Splunk Log Observer Connect
❯



  • API docs
  • Blog
  • Training
  • Free Trial

Was this topic useful?

Did you know that you can edit this page? Learn how!

Was this documentation topic helpful?

Please specify the reason

Comment should have a minimum of 5 characters and a maximum of 1,000 characters.

Submit

Feedback submitted, thank you! We resolve documentation feedback based on the severity of the issue reported, as well as an assessment of the potential number of customers who might be affected.

If you have a question about using Splunk software, we encourage you to check Splunk Answers or Splunk community Slack to see if similar questions have been answered, or to post your question for others to answer. If you have an active support entitlement and believe that your situation is caused by a product defect, file a support case in the Support portal https://login.splunk.com/page/sso_redirect?type=portal.

We are currently moving to a new documentation site. Expect a delay in responding to your feedback and applying any updates based on your feedback. Thank you for your patience and understanding while we work to bring you an improved documentation experience!

Splunk

Get started

  • Get started with Splunk Observability Cloud
  • Overview
  • Architecture
  • Get started guide for admins TOGGLE
  • AI Assistant in Observability Cloud
  • Prompt guide and library for AI Assistant in Observability Cloud
  • Service description
  • Free and paid courses
  • Free trial and guided onboarding
  • About Mobile TOGGLE
  • Support

Scenarios and tutorials

  • Scenarios
  • Tutorials

Splunk platform users

  • Splunk Observability Cloud and the Splunk platform
  • Unified Identity
  • Centralized user and role management
  • Scenarios

Administer Splunk Observability Cloud

  • Set up your Splunk Observability Cloud organization
  • Authentication and Security TOGGLE
  • User and team management TOGGLE
  • Send alert notifications to other services TOGGLE
  • View organization metrics
  • Monitor subscription usage and billing TOGGLE
  • Org reference info TOGGLE

Get your data in

  • Get data into Splunk Observability Cloud
  • Compatibility and requirements
  • Available integrations TOGGLE
  • Connect to your cloud service provider TOGGLE
  • Private connectivity TOGGLE
  • Splunk Distribution of the OpenTelemetry Collector TOGGLE
  • Collect infrastructure metrics and logs TOGGLE
  • Instrument back-end services TOGGLE
  • Instrument serverless functions TOGGLE
  • Instrument front-end applications TOGGLE
  • Other data ingestion methods

Understand and analyze your data

  • Data types in Splunk Observability Cloud
  • Use internal search
  • Metrics, metadata and events TOGGLE
  • Data tools TOGGLE
  • SignalFlow and analytics TOGGLE

Dashboards and charts

  • Dashboards TOGGLE
  • Charts TOGGLE
  • Navigate with data links
  • Select the time range
  • Read and write permissions

Alerts, detectors, and SLOs

  • Alerts and detectors TOGGLE
  • Service level objectives TOGGLE

Application Performance Monitoring

  • Introduction to Splunk APM
  • Key concepts in Splunk APM
  • Scenarios for troubleshooting errors and monitoring application performance using Splunk APM TOGGLE
  • Set up Splunk APM TOGGLE
  • Manage services, spans, and traces in Splunk APM TOGGLE
  • Analyze services with span tags and MetricSets TOGGLE
  • Correlate traces to track Business Workflows TOGGLE
  • Visualize and alert on your application in Splunk APM TOGGLE
  • AlwaysOn Profiling TOGGLE
  • Monitor Database Query Performance TOGGLE
  • Use data links to connect APM properties to relevant resources TOGGLE
  • Filter data in Splunk APM

Infrastructure

  • Introduction
  • Key concepts
  • Set up Infrastructure Monitoring
  • Monitor services and hosts
  • Use navigators
  • Filter data
  • Metrics pipeline management TOGGLE
  • Network Explorer TOGGLE
  • Virtual metrics
  • Resolution and data retention
  • Resolution and data retention (DPM)

Log Observer Connect

  • Splunk Log Observer Connect
    • Introduction to Splunk Log Observer Connect
    • Set up Log Observer Connect for Splunk Cloud Platform
    • Set up Log Observer Connect for Splunk Enterprise
    • Troubleshoot Log Observer Connect setup
    • Reset the default Log Observer Connect index
    • Scenario: Aisha troubleshoots workflow failures with Log Observer Connect
    • View overall system health using the timeline
    • Ensure the correct mapping of your severity key
    • Query logs in Log Observer Connect
    • Browse logs in the logs table
    • Search logs by keywords or fields
    • Open logs in Splunk platform
    • Create field aliases
    • View individual log details
    • Display a field separately in the log details flyout
    • Group logs by fields using log aggregation
    • Add logs data to Splunk Observability Cloud dashboards
    • Where does a log’s logical time come from?
    • Save and share Log Observer Connect queries
    • Forward Log Observer logs data to the Splunk platform
    • Accomplish logs pipeline rules in Splunk platform
    • Log Observer Connect limits

Real User Monitoring

  • Introduction to Splunk RUM
  • Key concepts in Splunk RUM
  • Splunk RUM scenario library TOGGLE
  • Set up Splunk RUM
  • Use controls for sensitive data in Splunk RUM
  • Data collected by Splunk RUM
  • Create custom events
  • Error monitoring and crash aggregation in Tag spotlight
  • Identify errors in browser spans
  • Filter your data by tags in Splunk RUM
  • Write custom rules for URL grouping in Splunk RUM
  • Alert on Splunk RUM data
  • Splunk RUM dashboards TOGGLE
  • Splunk RUM metrics reference
  • Session replay in Splunk RUM
  • Filter and troubleshoot with custom tags
  • Experiment with the demo applications for Splunk RUM for Mobile
  • Third-party software

Synthetics

  • Introduction to Splunk Synthetic Monitoring
  • Key concepts in Splunk Synthetic Monitoring
  • Synthetics built-in dashboards
  • Synthetics scenario library TOGGLE
  • Set up Splunk Synthetic Monitoring
  • Browser tests for webpages TOGGLE
  • Uptime tests for port and HTTP TOGGLE
  • API tests for endpoints TOGGLE
  • Test status TOGGLE
  • Advanced test configurations TOGGLE
  • Troubleshoot tests TOGGLE

Splunk On-Call

  • Introduction to Splunk On-Call TOGGLE
  • User management TOGGLE
  • Create and manage on-call schedules TOGGLE
  • Alerts TOGGLE
  • Notifications TOGGLE
  • Incidents TOGGLE
  • Mobile app TOGGLE
  • Reports TOGGLE
  • Integrations with Splunk On-Call TOGGLE

Release notes

  • Release notes overview TOGGLE

Reference and Legal

  • Third-party software credits
  • Glossary
  • Contribute to our documentation

Related Topics

  • Documentation overview
    • Previous: Resolution and data retention in Splunk Infrastructure Monitoring (DPM plans only)
    • Next: Introduction to Splunk Log Observer Connect
Privacy | Terms | Export Control | © 2005 - 2025 Splunk LLC All rights reserved.
Splunk, Splunk>, Turn Data Into Doing, and Data-to-Everything are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.
Feedback