Splunk Integration

The Splunk integration in HPE Aruba Networking Central uses a built-in extension that allows you to forward the HPE Aruba Networking Central monitoring data (such as metrics, alerts, events, and so on) to your Splunk instance for further analysis, visualization, and correlation with other data sources.

Note:

The Splunk extension is available as a limited feature on select clusters; currently, this extension not available on the DL360 3-node cluster.

Presently, the Splunk extension solely offers the Client Insights endpoint data. For additional information, contact your Account Manager.

The integration typically involves the following steps:

  1. Configuration in Splunk—configure Splunk to receive data from HPE Aruba Networking Central by setting up data inputs, using Splunk's HTTP Event Collector (HEC) to receive data over HTTP.

  2. Configuration in HPE Aruba Networking Central—set up the integration within the HPE Aruba Networking Central environment by configuring data forwarding rules and specifying the Splunk endpoint details.

  3. Data forwardingHPE Aruba Networking Central forwards relevant monitoring data to Splunk according to the configured rules and settings.

  4. Visualization and analysis—once the data is received in Splunk, you can use Splunk's search and visualization capabilities to analyze the data, create dashboards, and generate reports.

  5. Correlation with other data—you can correlate HPE Aruba Networking Central monitoring data with other data sources within Splunk to gain deeper insights into the performance and health of your applications and infrastructure.