Skip to main content


Splunk Lantern

Getting help with Log Observer


Training: Using the Splunk Log Observer

This course is designed for developers responsible for debugging their own applications, and for SREs responsible for troubleshooting performance issues. The Splunk Log Observer is built primarily for DevOps teams working on applications built on modern tech stacks (containerized micro-services). It describes how to use the tool to work with log data using the no-code user interface. You will learn to create, save, and share search filters; and to investigate the shape of your log data.  You will analyze logs with aggregation functions and group by rules, and you will create rules to manipulate incoming data, as well as to generate synthetic metrics from log data.

Technical help - OnDemand Services (ODS)

ODS consultants work with you directly to help you get answers to general questions, get insight on best practices, explore functionality, deploy or review the health of your instance, and implement your use cases. Most customers have OnDemand Services included as a part of their license purchase, but they do expire at the end of each quarter. Use them as early as possible in the quarter by following these instructions from the OnDemand Services Portal End User Guide

  1. Open a request under the product Observability Cloud, Infrastructure Monitoring, APM, Log Observer.
  2. Select the task Ask a DevOps Expert.
  3. Wait for the consultant to reach out to you directly to help.

If you cannot open a case or do not know if you have OnDemand access, contact your Splunk Customer Success Manager/Advocate or Account Team or the ODS team at for clarification and assistance.

Plan Implement Use/Adopt Scale/Optimize

All Products:

  • Use Case Advisory Discussion
  • Architecture Diagram Creation
  • Blockchain: Advisory Session


  • Cloud Migration Assessment


  • Post Implementation Review
  • Smart Agent for Single Integration Configuration Guidance
  • OTel Collector Configuration Guidance

Log Observer:

  • FluentD Configuration
  • Log Processing Rule Configuration
  • Metricization Rule Configuration
  • Infinite Logging Configuration


  • Create a Simple Detector
  • Assist with Building a Simple Dashboard or Charts


  • Getting Started with Splunk Observability Cloud

Infrastructure Monitoring:

  • Getting Started with Splunk Infrastructure Monitoring
  • Assist with Exporting Data
  • Assist with a Supported Cloud Integration
  • Assist with a Supported Library Configuration
  • Assist with the Configuration of prometheus-exporter


  • Create Custom Span Tags
  • Assist with Auto-instrumentation
  • Usage Assessment
  • Dashboard Administration Assistance
  • Chart or Dashboard Optimization
  • Detector Optimization

Project-based services

Project-Based Services are much more involved, typically larger-scale services engagements compared to ODS. With these, you will work with a Splunk Engagement Manager to determine and finalize the scope of the project. Once everything is signed off, we will work with you in lockstep to deliver on the agreed-upon project. If you’d like to explore options here, please get in touch with us via this contact form or get in touch with your account manager


Even the most savvy customer will need a little help. Whether it’s error messages, unexplained or unexpected behaviors, or incidents and outages, Technical Support is the first line of defense for all of your post-sales issues. Splunk Support Engineers will partner with you to ensure your environment is optimized to drive your journey with a
focus on long-term technical health, so you can realize your ROI as soon as possible.

To review what is included with the Standard and Premium support programs, click here.

The Support Portal can be accessed from the home page for logged in users, or from the Splunk product application user interface. Bring up the navigation menu, scroll to the bottom of the side-bar, select Help & Support, and then select Support and Community. From there you will be able to open a support case.

In-App chat is also available for customers with Premium Support entitlement. It is accessed through the drawer or icon in the bottom right corner of the application. Engage there to be connected with a Support Engineer.

Splunk comprehensive resource guide

Splunk wants you to succeed. If you haven't yet found the right resource to help you get the job done, take a look at our comprehensive help guide. Find online, self-paced courses or an instructor to come to your workplace to teach you and your peers together. Download a trial to learn by playing or join a live BOTS event just to play. Connect with Splunk enthusiasts near you, contact an Assigned Expert to dig into a difficult problem, or flaunt your Splunk talent by sporting the last Splunk t-shirt. However you want to get more involved and deepen your Splunk skills, we have an option for you.