Manage data and access with Observability Logs

Observability Logs uses Unified Identity, centralized RBAC, and data-level access control to govern logs in Splunk Observability Cloud.

Get started with Observability Logs

Use a supported Data Manager source or an OpenTelemetry-based integration to collect logs. Do not use other Splunk Cloud onboarding methods unless they are listed as supported for Observability Logs. For more information, see Get started with the Splunk Distribution of the OpenTelemetry Collector. Observability Logs is available only in regions where Splunk Observability Cloud and Splunk Cloud Platform support Unified Identity.

You need the o11y_admin role to access the Splunk Cloud stack. After provisioning, sign in to the Splunk Cloud stack as an administrator to:

  • Create roles.

  • Assign Splunk Cloud and Splunk Observability Cloud capabilities.

  • Assign index and dataset access for logs, metrics, and traces.

  • Configure SAML or Active Directory group mapping.

  • Add initial team members and confirm their Splunk Observability Cloud sign-in through Unified Identity and centralized RBAC.

End-User Workflow

After access is configured, sign in to Splunk Observability Cloud through Unified Identity. Your roles, capabilities, and data access are provided through centralized RBAC.

  • Open the Kubernetes navigator to view logs and metrics.

  • Build a Metrics, Events, Logs, and Traces (MELT) dashboard.

  • Create a log-based alert.

  • Investigate alerts in Log Explorer.

  • Use ad-hoc, or point-and-click queries and save refined searches to a dashboard for future troubleshooting.

Get data into Observability Logs

To get data into Observability Logs:

  1. In Splunk Observability Cloud, open Integrations and select a supported Data Manager source or OpenTelemetry-based integration. Supported Data Manager sources include:

    • source 1
    • source 2
  2. In Splunk Cloud, create a HEC token and an index to receive the logs. Create an ingest token for metrics and traces.

  3. Configure the HEC token and HEC endpoint manually in the OpenTelemetry Collector. Configure log routing to the index you created in Splunk Cloud, and make sure that the filelog receiver is enabled.

  4. Deploy the OpenTelemetry Collector or complete the Data Manager onboarding workflow. Verify that recent logs appear in Log Explorer and check the Collector's internal metrics to confirm that telemetry is being received and exported. For more information, see Internal metrics of the Collector.

Troubleshoot Splunk Cloud ingestion

If logs do not appear in Observability Logs, verify the Splunk Cloud configuration:
  1. Confirm that the destination index exists and search it for recent events.
  2. Confirm that the HEC token is enabled and associated with the correct index.
  3. Confirm that the HEC endpoint and token are configured correctly in the OpenTelemetry Collector.
  4. If you used Data Manager, confirm that the data input is active and review its HEC configuration.
  5. If the configuration is correct but data is still missing, contact Splunk Support.

Related pages: