The Splunk Firehose Nozzle for Pivotal Platform was developed as an application that runs with Pivotal Application Service (PAS). The Nozzle subscribes to the Loggregator endpoint and writes events to an external Splunk environment.
- The Splunk Firehose Nozzle for Pivotal Platform collects events from the Pivotal Platform Loggregator endpoint and streams them to Splunk via HTTP event collector (HEC). Nozzle has in-memory queue buffers to increase reliability, and has parallel client to scale out multiple ingestion channels to HEC.
- The Splunk Firehose Nozzle for Pivotal Platform can be deployed natively within a PAS environment and is available as a free tile from Pivotal.
- The Splunk HTTP Event Collector clients run concurrently, consuming events from the queue to enrich Pivotal Platform events by attaching metadata fields. For scaling out, add as many HECs and place a load balancer in front.
- After data has been ingested into Splunk, it can be explored using the Splunk Add-on for Cloud Foundry—an add-on to Splunk Enterprise which parses data from any Cloud Foundry distribution—which includes pre-built panels and pre-configured search parameters.