All Apps and Add-ons

How to connect Heroku and Splunk (not storm!)

ripper234
Explorer

I found this article about hooking up Heroku to Splunk Storm.

We are not using Splunk Storm, but rather a standalone installation of Splunk (4.3.2). How do I connect it to Heroku logs?

Tags (1)
0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You should be able to do something similar (but simpler) on the splunk side by creating a Splunk syslog (or UDP) listener port, and using the same method as described on the Heroku side to send the data there instead. Of course you will have to deal with your own firewalls and security (which is what the extra steps in Storm address). I don't know if there are other options to get data out of Heroku, but if the syslog/UDP one works with Storm, it will work with Splunk on-premise.

View solution in original post

himynamesdave
Contributor

Update: for anyone running 6+ you can install this app https://apps.splunk.com/app/1873/ (also contains full instructions of how to ingest Heroku syslog drains for any Splunk version)

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You should be able to do something similar (but simpler) on the splunk side by creating a Splunk syslog (or UDP) listener port, and using the same method as described on the Heroku side to send the data there instead. Of course you will have to deal with your own firewalls and security (which is what the extra steps in Storm address). I don't know if there are other options to get data out of Heroku, but if the syslog/UDP one works with Storm, it will work with Splunk on-premise.

ripper234
Explorer

Works like a charm - you can add a source right from the web UI. I used a TCP source and it worked.

0 Karma

ripper234
Explorer

Any documentation on how to do what you just described?

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

It appears the Heroku output is a TCP syslog stream, so I think you should be able to use the TCP rather than UDP input.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...