User Tools

Site Tools


3rd-party-integrations:logs

This is an old revision of the document!


ZEDEDA: Third Party Integrations & Data Streams

Step-by-step guide to forwarding edge telemetry from ZEDEDA Cloud to an external observability backend.

A Third Party Integration defines where telemetry goes (a Splunk HEC endpoint or an OpenTelemetry gRPC collector). A Data Stream defines what telemetry is sent (application logs, events, or device metrics) and binds it to an integration. You must create the integration first, then attach one or more data streams to it.

  • Captured on UI Version 19.2.9 / API Version 19.2.28.
  • Both features live under the Enterprise scope, so this is enterprise-admin configuration, not per-project.

<note> Media upload: This page references 15 screenshots in the zededa:integrations namespace. Upload all files into that namespace via the Media Manager. If your DokuWiki install rewrites hyphens to underscores on upload, adjust the 3rd-party-integrations references to match. </note>

Prerequisites

  • An enterprise account with admin rights to the Enterprise menu.
  • Endpoint details for your backend (host, port, and an auth token).
  • For Splunk: an HTTP Event Collector (HEC) token and the HEC URL path.
  • For OpenTelemetry: an OTLP/gRPC endpoint and a bearer token.

Part 1 — Create a Third Party Integration

Step 1.1 — Open Third Party Integrations

From the top-right user avatar, open the menu and go to Enterprise → Third Party Integrations.

Enterprise menu - Third Party Integrations

Step 1.2 — Add Integration

The Third Party Integrations panel lists existing integrations. Click Add Integration.

Add Integration tile

Step 1.3 — Choose Category and Type

Give the integration a Name, then pick the Integration Category. Two categories are available: Data and Remote Orchestration. For log/event/metric forwarding, choose Data.

Integration Category dropdown

Then pick the Integration Type. For the Data category the available types are Splunk and OpenTelemetry (gRPC).

Integration Type dropdown

Step 1.4a — OpenTelemetry (gRPC) integration

Fill in the OpenTelemetry fields and click Add.

OpenTelemetry integration details

Field Example value Notes
Name MC-OTEL Friendly label referenced later by Data Streams
Integration Category Data
Integration Type OpenTelemetry (gRPC)
Bearer Token abcd2334…c801b Auth credential sent to the collector
Skip Verify On Skip TLS certificate verification
Enable TLS On Use TLS for the gRPC connection
Host your.otel.url OTLP/gRPC collector hostname
Port 4317 Default OTLP/gRPC port

Step 1.4b — Splunk integration

Alternatively, fill in the Splunk fields and click Add.

Splunk integration details

Field Example value Notes
Name MC-SPLUNK
Integration Category Data
Integration Type Splunk
HTTP Event Collector Token abcd1234…c801b7 Splunk HEC token
Skip Verify On Skip TLS certificate verification
Enable TLS On Use TLS for the HEC connection
Host your.splunk.url Splunk HEC host
Port 8088 Default Splunk HEC port
URL Extension services/collector/event HEC event endpoint path

Step 1.5 — Verify the integrations

The panel now shows each integration as a card with its Name, Category, and Type, plus a status badge.

Integrations: MC-OTEL Initialized, MC-SPLUNK Verified

  • Verified (green check): the platform has confirmed connectivity to the endpoint (MC-SPLUNK above).
  • Initialized (amber triangle): the integration has been created but is not yet confirmed/verified (MC-OTEL above).
  • Use the trash icon on a card to delete an integration.

Part 2 — Create Data Streams

Step 2.1 — Open Data Streams

From the same avatar menu, go to Enterprise → Data Streams.

Enterprise menu - Data Streams

Step 2.2 — Add Data Stream

Click Add Data Stream.

Add Data Stream tile

Step 2.3 — Choose a Data Streaming Type

Open Data Streaming Type. Three telemetry categories are available:

Data Streaming Type dropdown

Type Sends
Application Logs Streaming Logs from edge applications
Events Streaming Platform / device events
Device Metrics Edge node telemetry metrics

Step 2.4 — Bind to an integration

Set the Name, leave Enable Streaming on, then select a Third Party Integration. The dropdown lists the integrations created in Part 1.

Third Party Integration dropdown listing MC-OTEL and MC-SPLUNK

Step 2.5 — Example: three streams to MC-OTEL

Create one stream per telemetry type, all pointing at the same integration.

Application Logs → MC-OTEL (name MC-OTEL-STREAM):

Application Logs Streaming to MC-OTEL

Events → MC-OTEL (name MC-EVENT-STREAM):

Events Streaming to MC-OTEL

Device Metrics → MC-OTEL (name MC-DEVICE-METRICS):

Device Metrics to MC-OTEL

  • Repeat the same three types against MC-SPLUNK to fan telemetry out to both backends.

Step 2.6 — Review all data streams

Each stream shows its Name, Type, target Integration, and a green Streaming badge when active.

All six data streams active

Name Type Integration
SPLUNK-STREAM-LOGS Application Logs Streaming MC-SPLUNK
SPLUNK-EVENTS Events Streaming MC-SPLUNK
SPLUNK-DEVICE-METRICS Device Metrics MC-SPLUNK
MC-OTEL-STREAM Application Logs Streaming MC-OTEL
MC-EVENT-STREAM Events Streaming MC-OTEL
MC-DEVICE-METRICS Device Metrics MC-OTEL

Notes

  • Create the integration before the data stream; the stream's Third Party Integration dropdown only lists existing integrations.
  • You can stream all three telemetry types to the same integration, and to more than one integration in parallel.
  • The Enable Streaming toggle lets you pause a stream without deleting it.
  • Default ports: Splunk HEC 8088, OTLP/gRPC 4317.

Reference

3rd-party-integrations/logs.1782587017.txt.gz · Last modified: by mc