Deploying the IBM Z Operational Log and Data Analytics application on the Splunk platform
To use the dashboards and searches for Z operational insights in Splunk, deploy the IBM Z® Operational Log and Data Analytics application (Log and Data Analytics application) on the Splunk platform. You can visit the video library (https://zaiops.github.io/zlda/) to watch the demo videos about the end-to-end deployment process.
Before you begin
Verify that the system requirements are met, as described in Planning for deployment of the Splunk platform, and that all prerequisite software is configured and is running.
About this task
- Single Splunk Enterprise system
- See Deploying the Z Operational Log and Data Analytics application on a single Splunk Enterprise system.
- Clustered Splunk environment
- See Deploying the Z Operational Log and Data Analytics application in a clustered Splunk environment.
The Splunk HEC is an HTTP API endpoint that enables you to send data directly to Splunk over HTTP or HTTPS. If the Splunk HEC feature is enabled in Splunk, Z Common Data Provider can send data directly to Splunk through the HEC rather than sending data through the Data Receiver.
- If you want to use the Z Common Data Provider Data Receiver, you must also install the Z Operational Log and Data Analytics Splunk application, as described in both Deploying the Z Operational Log and Data Analytics application on a single Splunk Enterprise system and Deploying the Z Operational Log and Data Analytics application in a clustered Splunk environment.
- If you want to use the Splunk HEC, you must complete the steps in Sending data directly to Splunk by using Splunk HEC as the subscriber.
If you will use the Z Operational Log and Data Analytics searches and dashboards, you must also deploy the IBM Z Operational Log and Data Analytics application either on a single Splunk Enterprise system or in a clustered Splunk environment.