All Apps and Add-ons

How to connect Heroku and Splunk (not storm!)

ripper234
Explorer

I found this article about hooking up Heroku to Splunk Storm.

We are not using Splunk Storm, but rather a standalone installation of Splunk (4.3.2). How do I connect it to Heroku logs?

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You should be able to do something similar (but simpler) on the splunk side by creating a Splunk syslog (or UDP) listener port, and using the same method as described on the Heroku side to send the data there instead. Of course you will have to deal with your own firewalls and security (which is what the extra steps in Storm address). I don't know if there are other options to get data out of Heroku, but if the syslog/UDP one works with Storm, it will work with Splunk on-premise.

View solution in original post

himynamesdave
Contributor

Update: for anyone running 6+ you can install this app https://apps.splunk.com/app/1873/ (also contains full instructions of how to ingest Heroku syslog drains for any Splunk version)

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You should be able to do something similar (but simpler) on the splunk side by creating a Splunk syslog (or UDP) listener port, and using the same method as described on the Heroku side to send the data there instead. Of course you will have to deal with your own firewalls and security (which is what the extra steps in Storm address). I don't know if there are other options to get data out of Heroku, but if the syslog/UDP one works with Storm, it will work with Splunk on-premise.

ripper234
Explorer

Works like a charm - you can add a source right from the web UI. I used a TCP source and it worked.

0 Karma

ripper234
Explorer

Any documentation on how to do what you just described?

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It appears the Heroku output is a TCP syslog stream, so I think you should be able to use the TCP rather than UDP input.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...