What’s New in the Splunk® Dataflow Template

The Splunk Dataflow template is an indispensable tool that allows Google Cloud customers to easily engineer a horizontally scalable and fault-tolerant logging export pipeline into Splunk® Enterprise and Splunk Cloud Platform™. I’m excited to share the news about recent improvements Google has made to this Splunk template across the following areas:

I’m particularly excited about the support for data format compatibility between Dataflow delivered events and the Pub/Sub input in the Splunk Add-on for Google Cloud Platform. For Splunk customers, a common message format means Dataflow sourced events can benefit from the sourcetype assignment and CIM mapping provided as part of the official Add-on.

The Splunk Dataflow template can now also encode the “fields” metadata key in event messages. This is great for customers who want to attach custom indexed metadata to Google Cloud log messages using JavaScript user-defined functions (UDF) prior to Splunk delivery. Imagine being able to populate Google resource labels as Splunk event metadata during log export. Now you can!

Finally, for anyone who has ever struggled to debug UDF failures in a Dataflow pipeline, you’ll be happy to know that the logging and troubleshooting experience has really improved. Instead of silent failures, you’ll find UDF error logs waiting for your inspection in the normal Dataflow worker logs.

While I’ve briefly covered a high-level overview of the Splunk Dataflow template improvements Google has been working on lately, there’s a lot more to learn about.You can read a full explanation of what’s new and improved on the Google Cloud blog. And remember, all improvements are customer-driven, so keep your ideas coming!

Related Articles

Splunk Delivers Real-Time Salesforce Visibility with New Streaming API Integration
Partners
3 Minute Read

Splunk Delivers Real-Time Salesforce Visibility with New Streaming API Integration

Great news … Splunk and Salesforce have your back. Salesforce has created a new Streaming API that is available at no extra cost as part of Salesforce’s powerful Event Monitoring capability. Real-time events are critical to immediately identify and respond to internal and external threats to sensitive data or performance bottlenecks.
Register Today for Splunk 2021 Virtual Global Partner Summit
Partners
2 Minute Read

Register Today for Splunk 2021 Virtual Global Partner Summit

Register now for the free Splunk 2021 Virtual Global Partner Summit (GPS), a two-day virtual event running across all time zones (AMER: April 7-8 from 8:00 am - 4:00 pm PDT; APAC: April 8-9 from 8:00 am - 4:00 pm SGT; and EMEA: April 8-9 from 8:00 am - 4:00 pm BST) where you will gain the knowledge to help your customers turn their data into doing by accelerating their digital transformation and cloud adoption.
Esports Racing Analytics, Powered By Splunk
Partners
6 Minute Read

Esports Racing Analytics, Powered By Splunk

This post will introduce you to the Logitech McLaren G Challenge and walk you through how we instrumented racing simulators, and leveraged Splunk Enterprise to provide high fidelity insights into both the drivers, and the tracks they’re racing on.