Monitoring the status of OpenTelemetry Collectors

Manage OpenTelemetry Collectors in Splunk Enterprise by monitoring collector status, reviewing collector metadata, and assigning remote configuration to supported collectors.

Use the OTel Collectors area in agent management to monitor the health and status of OpenTelemetry Collector agents, view details about connected collectors, inspect effective configurations, and assign configuration sets to collectors that report remote configuration capabilities.

OpenTelemetry Collectors collect traces, logs, and metrics. For more information, see https://opentelemetry.io/docs/collector/.

OTel Collectors connect to agent management using the Open Agent Management Protocol (OpAMP). This open standard enables centralized communication, status reporting, effective configuration reporting, and remote configuration delivery. For more information about OpAMP, see https://opentelemetry.io/docs/specs/opamp/.

Architecture and communication

The OTel Collector initiates the connection to Splunk Enterprise using the OpAMP extension. The connection uses OpAMP over HTTPS to the Splunk management port (default 8089):

CODE
https://<agent-management-host>:8089/services/tenant/agent-management/v2/opamp/otel

The OpAMP service runs inside Splunk Enterprise as the opamp-svc sidecar. Collectors authenticate with a bearer token and periodically send heartbeat, status, and capability information. Splunk Enterprise stores and displays the reported collector metadata in the OTel Collectors view.

Note: Remote configuration is supported for OTel Collectors that report the OpAMP AcceptsRemoteConfig capability. To report remote configuration status, collectors also report the OpAMP ReportsRemoteConfig capability. Collectors without remote configuration capabilities continue running with their local configuration only.

Server roles

Enable the OTel Collectors management feature on the same Splunk Enterprise instance that serves as your agent management.

Resilience and availability

If the agent management server or the opamp-svc sidecar is unavailable, existing OTel Collectors continue running with their current configuration. Collectors cannot report heartbeat, status, effective configuration, or remote configuration status during the outage, so Splunk Enterprise shows them as offline after missed heartbeats. When connectivity returns, collectors reconnect, resume reporting, and the UI status updates automatically.