An organization wants application logs captured by Instana agents to be forwarded to Splunk for long-term retention and SIEM analysis without installing additional collectors on monitored hosts. What is the supported Instana integration approach?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Instana supports log forwarding to Splunk via the HTTP Event Collector (HEC) integration. Administrators configure the Splunk HEC URL and authentication token in Instana's log management settings. Log data captured by the Instana agent is forwarded in near real time to Splunk, where it can be indexed, searched, and correlated with other security and operational data without requiring additional collector agents on monitored hosts.
Full explanation below image
Full Explanation
Instana supports log forwarding to Splunk via the HTTP Event Collector (HEC) integration. Administrators configure the Splunk HEC URL and authentication token in Instana's log management settings. Log data captured by the Instana agent is forwarded in near real time to Splunk, where it can be indexed, searched, and correlated with other security and operational data without requiring additional collector agents on monitored hosts. The correct answer is 'Configure Instana log forwarding to send logs to the Splunk HTTP Event Collector endpoint using a Splunk HEC token'. The incorrect options — 'Install a Splunk Universal Forwarder on each Instana-monitored host to tail and forward the Instana agent log files', "Use Instana's native Splunk plugin to stream all trace spans and infrastructure metrics in Splunk's proprietary wire format", 'Schedule periodic Instana log exports as compressed CSV files and import them into Splunk using a scripted input' — are wrong because they do not align with IBM Instana's architecture or recommended practices for this scenario. Understanding this concept is essential for the Domain 4: Integration domain of the IBM Instana Observability certification.