Skip to content
fernet.consultores

Splunk Observability Cloud

Observability Architecture.

Design of the observability architecture: agents, gateways, egress paths, common attributes and sampling.

The problem we solve.

Without a clear architecture, every server sends data on its own, attributes don't match between teams and cardinality spikes. The result is expensive and hard to correlate.

What’s included.

  • Design of collectors in agent and gateway mode
  • Egress paths from segmented networks
  • Attribute and naming conventions
  • Trace sampling strategy
  • Architecture document reviewed with your teams

How we work.

Five phases, always in the same order. Select each one to see what happens in it. In full projects they map onto the stages of our method.

We review what's monitored today, with which tools, which incidents went unnoticed and what it costs.

We design the collection layer with OpenTelemetry: agents, gateways, egress paths, common attributes and sampling.

We document agents, gateways, egress paths, common attributes and sampling, with configuration templates.

We test the egress paths and correlation between signals in a pilot environment before rolling out the design.

We tune cardinality, sampling and detectors based on real usage to contain cost and noise.

Technical capabilities.

  • Splunk Distribution of the OpenTelemetry Collector
  • Agent and gateway mode
  • Load balancing
  • Semantic conventions
  • Tail sampling
  • Cloud integrations

Use cases.

Isolated environments

Route telemetry out through a single controlled point.

Multiple clouds

Unify collection across AWS, Azure, Google Cloud and data centres.

Planned growth

Design so services can multiply without rebuilding anything.

Benefits for your organisation.

  • Correlation between signals built into the design
  • Cardinality cost under control
  • A single, auditable egress path
  • A stable base to grow on

Deliverables.

  • Architecture document
  • Data flow diagrams
  • Attribute conventions
  • Configuration templates

Frequently asked questions.

Why agent and gateway?

The agent collects close to the source and the gateway concentrates, filters and is the single egress point. Separating them simplifies security and change.

Does it work for networks without internet access?

Yes. That's exactly the case where the gateway, behind a load balancer or a proxy, makes the difference.

Do you also design the logs side?

Yes, so logs share attributes with metrics and traces and can be correlated.

Shall we talk about Architecture?

Tell us about your situation. If this service is not what you need, we will tell you; if it is, we will propose a concrete first step.

Request this service