Observability Logs in Splunk Observability Cloud
Observability Logs in Splunk Observability Cloud is an offering for customers who want to manage logs, metrics, and traces in one place.
Observability Logs in Splunk Observability Cloud combines Splunk Cloud stack, an integrated logs experience, and shared identity and access management through Unified Identity, centralized role-based access control (RBAC), and data-level access control. It is intended for users who want to manage operational logs alongside metrics, events, and traces. The offering includes account provisioning, administration, and an end-user logs experience in Splunk Observability Cloud.
Splunk Cloud provides the administrative and log-management foundation, while Splunk Observability Cloud provides the end-user experience. Together, they provide one place to search, monitor, and troubleshoot operational logs alongside metrics, events, and traces. In Splunk Observability Cloud, users can work with logs in Log Explorer, charts, dashboards, and detectors, and use logs in existing Metrics, Events, Logs, and Traces (MELT) workflows.
Provisioning
Engage your account team to provision Observability Logs. After provisioning, you receive an email with access details for your Splunk Cloud stack. Unified Identity pairing between Observability Logs and Splunk Observability Cloud is completed automatically during provisioning.
Access and governance
Unified Identity pairing and centralized role-based access control (RBAC) are configured automatically during provisioning. Data-level access control can be configured in the Splunk Cloud stack for logs. For more information, see Unified Identity.
You need the o11y_admin role to access the Splunk Cloud stack. Administrators can create roles, assign capabilities, configure SAML or Active Directory group mapping, and assign index or dataset access. See Manage data and access with Observability Logs.
Retention and search
Observability Logs provides 15 or 30 days of hot-tier retention for indexed logs. After 30 days, logs are stored in a cold or frozen tier.
Migration path
If you already use Splunk Cloud and want to move to Observability Logs, purchase Observability Logs as a separate entitlement and migrate to a separate Observability Logs stack. In-stack migration is not supported.
If you start with Observability Logs, you can later move to full Splunk Cloud by purchasing the required Splunk Cloud entitlement. Your existing data, identity, RBAC, and configuration persist.