====== ZEDEDA: Third Party Integrations & Data Streams ====== Step-by-step guide to forwarding edge telemetry from ZEDEDA Cloud to an external observability backend. A **Third Party Integration** defines //where// telemetry goes (a Splunk HEC endpoint or an OpenTelemetry gRPC collector). A **Data Stream** defines //what// telemetry is sent (application logs, events, or device metrics) and binds it to an integration. You must create the integration first, then attach one or more data streams to it. * Captured on UI Version ''19.2.9'' / API Version ''19.2.28''. * Both features live under the **Enterprise** scope, so this is enterprise-admin configuration, not per-project. ---- **Media upload:** This page references 15 screenshots in the ''3rd-party-integrations'' namespace. Upload all files into that namespace via the Media Manager. If your DokuWiki install rewrites hyphens to underscores on upload, adjust the ''{{...}}'' references to match. ---- ===== Prerequisites ===== * An enterprise account with admin rights to the **Enterprise** menu. * Endpoint details for your backend (host, port, and an auth token). * For Splunk: an HTTP Event Collector (HEC) token and the HEC URL path. * For OpenTelemetry: an OTLP/gRPC endpoint and a bearer token. ===== Part 1 — Create a Third Party Integration ===== ==== Step 1.1 — Open Third Party Integrations ==== From the top-right user avatar, open the menu and go to **Enterprise → Third Party Integrations**. {{:3rd-party-integrations:3rd-party-integrations.jpg?500|Enterprise menu - Third Party Integrations}} ==== Step 1.2 — Add Integration ==== The Third Party Integrations panel lists existing integrations. Click **Add Integration**. {{:3rd-party-integrations:3rd-party-integrations-add.jpg?420|Add Integration tile}} ==== Step 1.3 — Choose Category and Type ==== Give the integration a **Name**, then pick the **Integration Category**. Two categories are available: ''Data'' and ''Remote Orchestration''. For log/event/metric forwarding, choose **Data**. {{:3rd-party-integrations:3rd-party-integrations-add-details.jpg?700|Integration Category dropdown}} Then pick the **Integration Type**. For the Data category the available types are **Splunk** and **OpenTelemetry (gRPC)**. {{:3rd-party-integrations:3rd-party-integrations-types.jpg?420|Integration Type dropdown}} ==== Step 1.4a — OpenTelemetry (gRPC) integration ==== Fill in the OpenTelemetry fields and click **Add**. {{:3rd-party-integrations:3rd-party-integrations-add-details-otel.jpg?700|OpenTelemetry integration details}} ^ Field ^ Example value ^ Notes ^ | Name | ''MC-OTEL'' | Friendly label referenced later by Data Streams | | Integration Category | ''Data'' | | | Integration Type | ''OpenTelemetry (gRPC)'' | | | Bearer Token | ''abcd2334...c801b'' | Auth credential sent to the collector | | Skip Verify | On | Skip TLS certificate verification | | Enable TLS | On | Use TLS for the gRPC connection | | Host | ''your.otel.url'' | OTLP/gRPC collector hostname | | Port | ''4317'' | Default OTLP/gRPC port | ==== Step 1.4b — Splunk integration ==== Alternatively, fill in the Splunk fields and click **Add**. {{:3rd-party-integrations:3rd-party-integrations-add-details-splunk.jpg?700|Splunk integration details}} ^ Field ^ Example value ^ Notes ^ | Name | ''MC-SPLUNK'' | | | Integration Category | ''Data'' | | | Integration Type | ''Splunk'' | | | HTTP Event Collector Token | ''abcd1234...c801b7'' | Splunk HEC token | | Skip Verify | On | Skip TLS certificate verification | | Enable TLS | On | Use TLS for the HEC connection | | Host | ''your.splunk.url'' | Splunk HEC host | | Port | ''8088'' | Default Splunk HEC port | | URL Extension | ''services/collector/event'' | HEC event endpoint path | ==== Step 1.5 — Verify the integrations ==== The panel now shows each integration as a card with its **Name**, **Category**, and **Type**, plus a status badge. {{:3rd-party-integrations:3rd-party-integrations-end.jpg?700|Integrations: MC-OTEL Initialized, MC-SPLUNK Verified}} * **Verified** (green check): the platform has confirmed connectivity to the endpoint (MC-SPLUNK above). * **Initialized** (amber triangle): the integration has been created but is not yet confirmed/verified (MC-OTEL above). * Use the trash icon on a card to delete an integration. ===== Part 2 — Create Data Streams ===== ==== Step 2.1 — Open Data Streams ==== From the same avatar menu, go to **Enterprise → Data Streams**. {{:3rd-party-integrations:3rd-party-integrations-add-data-stream.jpg?540|Enterprise menu - Data Streams}} ==== Step 2.2 — Add Data Stream ==== Click **Add Data Stream**. {{:3rd-party-integrations:3rd-party-integrations-add-data-stream-button.jpg?360|Add Data Stream tile}} ==== Step 2.3 — Choose a Data Streaming Type ==== Open **Data Streaming Type**. Three telemetry categories are available: {{:3rd-party-integrations:3rd-party-integrations-add-data-stream-types.jpg?420|Data Streaming Type dropdown}} ^ Type ^ Sends ^ | Application Logs Streaming | Logs from edge applications | | Events Streaming | Platform / device events | | Device Metrics | Edge node telemetry metrics | ==== Step 2.4 — Bind to an integration ==== Set the **Name**, leave **Enable Streaming** on, then select a **Third Party Integration**. The dropdown lists the integrations created in Part 1. {{:3rd-party-integrations:3rd-party-integrations-add-data-stream-3rd-p-int.jpg?700|Third Party Integration dropdown listing MC-OTEL and MC-SPLUNK}} ==== Step 2.5 — Example: three streams to MC-OTEL ==== Create one stream per telemetry type, all pointing at the same integration. **Application Logs → MC-OTEL** (name ''MC-OTEL-STREAM''): {{:3rd-party-integrations:3rd-party-integrations-add-data-stream-otel.jpg?700|Application Logs Streaming to MC-OTEL}} **Events → MC-OTEL** (name ''MC-EVENT-STREAM''): {{:3rd-party-integrations:3rd-party-integrations-add-data-stream-otel-event.jpg?700|Events Streaming to MC-OTEL}} **Device Metrics → MC-OTEL** (name ''MC-DEVICE-METRICS''): {{:3rd-party-integrations:3rd-party-integrations-add-data-stream-otel-device.jpg?700|Device Metrics to MC-OTEL}} * Repeat the same three types against ''MC-SPLUNK'' to fan telemetry out to both backends. ==== Step 2.6 — Review all data streams ==== Each stream shows its **Name**, **Type**, target **Integration**, and a green **Streaming** badge when active. {{:3rd-party-integrations:all-data-streams-final.jpg?700|All six data streams active}} ^ Name ^ Type ^ Integration ^ | SPLUNK-STREAM-LOGS | Application Logs Streaming | MC-SPLUNK | | SPLUNK-EVENTS | Events Streaming | MC-SPLUNK | | SPLUNK-DEVICE-METRICS | Device Metrics | MC-SPLUNK | | MC-OTEL-STREAM | Application Logs Streaming | MC-OTEL | | MC-EVENT-STREAM | Events Streaming | MC-OTEL | | MC-DEVICE-METRICS | Device Metrics | MC-OTEL | ===== Notes ===== * Create the integration **before** the data stream; the stream's Third Party Integration dropdown only lists existing integrations. * You can stream all three telemetry types to the same integration, and to more than one integration in parallel. * The **Enable Streaming** toggle lets you pause a stream without deleting it. * Default ports: Splunk HEC ''8088'', OTLP/gRPC ''4317''. ===== Reference ===== * ZEDEDA Help: https://help.zededa.com