Splunk Log Observer Connect for Virtual Appliance
Splunk Log Observer Connect for Virtual Appliance enriches the application logs with metadata specific to Splunk AppDynamics Virtual Appliance. To view logs in Splunk Enterprise in context of an application monitored by Splunk AppDynamics Self Hosted Virtual Appliance, you must integrate Splunk AppDynamics Self Hosted Virtual Appliance with Splunk Enterprise, depending on your deployment. Using the deep links on the Controller UI, you can directly navigate from Splunk AppDynamics Self Hosted Virtual Appliance to Splunk Enterprise with a single sign-on and view the logs corresponding to the application, tier, node, business transaction, and transaction snapshot. With logs, you can further drill down to identify the root cause and the source of an issue and then initiate remediation actions.
License Requirements
To integrate Splunk AppDynamics Self Hosted Virtual Appliance with Splunk Enterprise, you need an active:
-
Splunk AppDynamics On-premises license
-
Splunk Enterprise license depending on your deployment
Integration Steps
To integrate Splunk AppDynamics Self Hosted Virtual Appliance with Splunk Enterprise, perform the following tasks:
Sequence | Task | Description |
---|---|---|
1 | Configure Splunk service account user | Create a service account in Splunk Enterprise for Splunk AppDynamics Self Hosted Virtual Appliance integration. This user is used to access the indexes for applications for application logs are stored. |
2 | Configure universal forwarder | Configure your existing universal forwarder to send meta data specific to Splunk AppDynamics Self Hosted Virtual Appliance and augment them with logs. |
3 | Configure the Splunk AppDynamics agents | Configure Java, .Net, and Node.js agents to enrich the log data with request GUID, business transaction ID, and node ID. |
4 |
Configure the application loggers: | Configure the Java, .NET, and Node.js application loggers to enrich the log data. The configuration of the logger will vary based on whether you are using structured or unstructured logs, as well as the type of logging framework being utilized. |
5 | Install the Universal Integration Layer service in the cluster | Install the service endpoints and pods in the cluster that are required for the integration. |
6 | Configure Splunk AppDynamics On-Premises for Splunk Log Observer Connect | Configure the on-premises Controller to view the logs in Splunk Enterprise. |
7 | Ensure that Splunk AppDynamics Self Hosted Virtual Appliance can communicate with Splunk Enterprise. |