Splunk

Connect Splunk to Sentry with the Data Forwarding feature.

This integration needs to be set up in each project for which you wish to use it. It is maintained and supported by the Sentry community.

Install and Configure

Navigate to Settings > Integrations > Splunk

splunk

Enabling HEC

To get started, you’ll need to first enable the HTTP Event Collector:

Under Settings, select Data Inputs:

splunk settings

Select HTTP Event Collector under Local Inputs:

splunk data inputs

Under your HEC settings, click "Global Settings":

splunk hec inputs

Change All Tokens to Enabled, and note the HTTP Port Number (8088 by default):

splunk hec global settings

Creating a Sentry Input

Under HTTP Event Collector, create a new Sentry input by clicking "New Token":

splunk new http input

Enter a name (e.g. Sentry), and click "Next":

splunk new input name

Select the index you wish to make accessible (e.g. main), and click "Review":

splunk new input index

You’ll be prompted to review the input details. Click "Submit" to continue:

splunk new input review

The input has now been created, and you should be presented with the Token Value:

splunk new input final

Enabling Splunk Forwarding

To enable Splunk forwarding, you’ll need the following:

  • Your instance URL (see note below)
  • The Sentry HEC token value

In Sentry, navigate to the project you want to forward events from, and click "Project Settings".

Data Forwarding

Configure Data Forwarding in [Project] > Settings > Data Forwarding, and provide the required information for the given integration.

After navigating to Data Forwarding, enable the Splunk integration:

splunk data forwarding setting

Your instance URL is going to vary based on the type of Splunk service you’re using. If you’re using self-service Splunk Cloud, the instance URL will use the input prefix:

Copied
https://input-<host>:8088

For all other Splunk Cloud plans, you’ll use the http-inputs prefix:

Copied
https://http-inputs-<host>:8088

If you’re using Splunk behind your firewall, you’ll need to fill in the appropriate host.

Once you’ve filled in the required fields, hit Save Changes:

splunk data forwarding setting complete

We’ll now begin forwarding all new events into your Splunk instance.

splunk search sentry

You can edit this page on GitHub.