Configure Cloud Pub/Sub inputs for Splunk Add-on for Google Cloud Platform¶
Version 4.0.0 of the Splunk Add-on for Google Cloud Platform introduced sourcetype changes to the Pub/Sub input to support Data Manager compatibility. Check with your Splunk platform administrator to verify your prebuilt Splunk searches.
Configure Cloud Pub/Sub inputs for Splunk Add-on for Google Cloud Platform using Splunk Web or via configuration file, using the information in the inputs parameters table below.
Configure Cloud Pub/Sub inputs using the Splunk Web¶
Follow these steps to configure Cloud Pub/Sub inputs.
- Select Create New Input in the Inputs tab, and choose Cloud Pub/Sub.
- Enter the Name, Credentials, Projects, Pub/Sub Subscriptions and Index using the information in the inputs parameter table.
Note
Do not go to the Splunk Add-on for Google Cloud Platform configuration page under Settings, and then Data Inputs to configure Google Cloud Platform inputs. This page is not supported for this type of input.
Configure Cloud Pub/Sub inputs using the configuration file¶
Follow these steps to configure Cloud Pub/Sub inputs.
- Edit (or create)
local/inputs.confunder$SPLUNK_HOME/etc/apps/Splunk_TA_google-cloudplatform/. - Add or update a stanza using the following template (See the
google_cloud_pubsub_inputs.conf.spec, contained in the$SPLUNK_HOME/etc/apps/Splunk_TA_google-cloudplatform/READMEdirectory for reference):[google_cloud_pubsub://<name>] google_credentials_name = <value> google_project = <value> google_subscriptions = <value> index = <value> pubsub_region = <region>
Leave pubsub_region empty or set it to global to use the default
global endpoint (pubsub.googleapis.com). Set it to a supported GCP
region (for example, europe-southwest1) to use the corresponding
locational endpoint.
- Save and return to your Splunk instance.
Note
Restart your Splunk platform after making changes to your configuration (.conf) files.
Input parameters¶
Each attribute in the following table corresponds to a field in Splunk Web or in a configuration file:
| Attribute | Corresponding field in Splunk Web | Description |
|---|---|---|
name |
Name | Enter a unique name of the Google Cloud Pub/Sub input. |
google_credentials_name |
Credentials | Stanza name defined in google_cloud_credentials.conf. |
google_project |
Project | Google pubsub project ID. |
google_subscriptions |
Pub/Sub Subscriptions | Google pubsub subscription names. You can add several subscriptions separated by “,”. |
index |
Index | The index in which to store Google Cloud Pub/Sub data. |
pubsub_region |
Pub/Sub Region | Optional. The GCP region for the Pub/Sub locational endpoint. Leave empty or select Global (default) to use pubsub.googleapis.com. Set to a supported GCP region (for example, europe-southwest1) to route pull requests to the locational endpoint europe-southwest1-pubsub.googleapis.com. Use a locational endpoint when the topic’s message storage policy has in-transit enforcement enabled. See Troubleshoot Pub/Sub locational endpoint issues if you encounter 400 Bad Request errors. |