Splunk Firehose Nozzle for VMware Tanzu

This documentation describes the Splunk Firehose Nozzle for VMware Tanzu. Splunk Firehose Nozzle integrates with the VMware Tanzu Loggregator and forwards streaming logs and metrics from user apps and system components of Cloud Foundry to Splunk Enterprise. VMware Tanzu operators can then gain operational visibility over their VMware Tanzu infrastructure, including the health and performance of their apps and system components.

For more information about Loggregator, see the Loggregator Architecture topic in the Pivotal documentation.

Overview

The Splunk Firehose Nozzle for VMware Tanzu Tile streams logs and metrics from VMware Tanzu and forwards them to user-specified Splunk Enterprise indexers that are configured to receive data via HTTP Event Collector. VMware Tanzu operators and Splunk users can immediately search and analyze VMware Tanzu Firehose data from their Splunk Enterprise deployment to build reports, dashboards, and alerts on the health and performance of their apps.

Splunk Firehose Nozzle for VMware Tanzu includes the following key features:

  • Setup with out-of-the-box data parsing and enrichment for various VMware Tanzu event types.
  • Reliable event delivery by leveraging Splunk’s HTTP Event Collector endpoint.
  • Secure forwarding from VMware Tanzu into external Splunk environments using user-provided SSL certificates.
  • Scales out to meet increasing data volume and number of apps.
  • Comes with events tracing and memory queue pressure monitoring capabilities for back-pressure insights.

Product Snapshot

Element Details
Tile Version v1.2.3
Release Date Oct 18th, 2021
Compatible Ops Manager Versions v2.7.x, v2.8.x, v2.9.x, v2.10.x
Compatible VMware Tanzu Application Service for VMs (formerly known as Elastic Runtime) versions v2.7.x, v2.8.x, v2.9.x, v2.10.x, v2.11.x
BOSH stemcell version Ubuntu Xenial
IaaS Support vSphere, OpenStack, GCP, and AWS

Requirements

Splunk Firehose Nozzle for VMware Tanzu has the following system requirements.

  • An external Splunk Enterprise or Splunk Cloud 6.x or above deployment, configured with a HTTP Event Collector (HEC) token to receive data.

Splunk and the VMware Tanzu Ecosystem

See the following links to learn more about projects involving Splunk and VMware Tanzu:

Limitations

Feedback

Splunk Firehose Nozzle project is supported through Splunk support assuming the customer has a current Splunk support entitlement. For customers that do not have a current Splunk support entitlement, please provide any bugs, feature requests, or questions to the VMware Tanzu Feedback or to the splunk-firehose-nozzle GitHub project.