Set up Log Observer Connect for Splunk Enterprise 🔗
Set up Log Observer Connect by integrating Log Observer with Splunk Enterprise. If you are in a Splunk Cloud Platform environment and want to set up Log Observer Connect, see Set up Log Observer Connect for Splunk Cloud Platform.
When you set up Log Observer Connect, your Splunk Enterprise logs data remains in Splunk Enterprise. Log Observer Connect does not store or index your logs data. There is no additional charge for Log Observer Connect.
Region and version availability 🔗
Splunk Log Observer Connect is available in the AWS regions us0, us1, and eu0. Splunk Log Observer Connect is compatible with Splunk Enterprise 8.2 and higher.
You can collect data using both the Splunk Distribution of OpenTelemetry Collector and the Universal Forwarder without submitting any duplicate telemetry data. See Use the Collector with Splunk Universal Forwarder to learn how.
Set up Log Observer Connect 🔗
To set up Log Observer Connect for Splunk Enterprise, follow these steps:
In Observability Cloud, go to Settings > Log Observer Connect and click Add new connection.
Click Splunk Enterprise.
Follow the instructions in the integration wizard to do the following in Splunk Enterprise:
Create a new role in your Splunk Enterprise instance.
Select the Splunk Enterprise indexes that you want to search in Log Observer Connect.
Create and configure a new user in your Splunk Enterprise instance.
Obtain certificates for securing inter-Splunk communication. See Configure and install certificates in Splunk Enterprise for Splunk Log Observer Connect to learn how.
Manage concurrent search limits using your current strategy in Splunk Enterprise. All searches initiated by Log Observer Connect users go through the service account you create in Splunk Enterprise. For each active Log Observer Connect user, four back-end searches occur when a user performs a search in the Log Observer Connect UI. For example, if there are three concurrent users accessing the Log Observer Connect UI at the same time, the service account for Log Observer Connect initiates approximately 12 searches in Splunk Enterprise.