Skip to content
Merged
Show file tree
Hide file tree
Changes from 19 commits
Commits
Show all changes
26 commits
Select commit Hold shift + click to select a range
7aa99ca
Adding OpenTelemetry Monitoring App docs
chetanchoudhary-sumo Aug 21, 2025
1e9b372
updating monitor details
chetanchoudhary-sumo Aug 22, 2025
4b99edf
updating filename, adding sidebar
chetanchoudhary-sumo Aug 25, 2025
7677a81
Updating s3 links for screenshots
chetanchoudhary-sumo Aug 25, 2025
e96d736
Merge branch 'main' into otel-collector-doc
jpipkin1 Aug 25, 2025
d3bdbc3
Updates from review
jpipkin1 Aug 25, 2025
6147568
adding form screenshot, made few updates
chetanchoudhary-sumo Aug 26, 2025
b5c07a4
Merge remote-tracking branch 'refs/remotes/origin/otel-collector-doc'…
chetanchoudhary-sumo Aug 26, 2025
afe751a
Implementing more feedbacks
chetanchoudhary-sumo Aug 26, 2025
4750b0e
Merge branch 'main' into otel-collector-doc
chetanchoudhary-sumo Aug 26, 2025
b06ff66
Updates
amee-sumo Aug 26, 2025
bc09e7c
Update cid-redirects.json
amee-sumo Aug 26, 2025
4a09bf7
release note and product list
amee-sumo Aug 26, 2025
3d02c1a
Remove hard-coded links, formatting edits
kimsauce Aug 30, 2025
bbe0de2
Merge branch 'main' into otel-collector-doc
kimsauce Aug 30, 2025
f209074
Update docs/integrations/sumo-apps/opentelemetry-collector-insights.md
kimsauce Aug 30, 2025
b0ed1d5
Update docs/integrations/sumo-apps/opentelemetry-collector-insights.md
kimsauce Aug 30, 2025
69642ae
Update docs/integrations/google/cloud-security-command-center.md
kimsauce Aug 30, 2025
fd6f6cf
Update docs/integrations/google/cloud-security-command-center.md
kimsauce Aug 30, 2025
2551bd7
Update docs/integrations/google/cloud-security-command-center.md
kimsauce Aug 30, 2025
ae2dc9d
Merge branch 'main' into otel-collector-doc
amee-sumo Sep 2, 2025
b44b1b1
Update docs/integrations/sumo-apps/opentelemetry-collector-insights.md
kimsauce Sep 2, 2025
7b6d1fa
Update docs/integrations/google/cloud-security-command-center.md
kimsauce Sep 2, 2025
d2d55c4
Update docs/integrations/google/cloud-security-command-center.md
kimsauce Sep 2, 2025
24e0d0e
Update docs/integrations/sumo-apps/opentelemetry-collector-insights.md
kimsauce Sep 2, 2025
cf753dd
Merge branch 'main' into otel-collector-doc
kimsauce Sep 2, 2025
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 5 additions & 5 deletions docs/integrations/google/cloud-security-command-center.md
Original file line number Diff line number Diff line change
Expand Up @@ -190,7 +190,7 @@ This app uses the [Findings](https://cloud.google.com/security-command-center/do
}
],
"relatedFindingUri": {

}
}
},
Expand All @@ -210,7 +210,7 @@ This app uses the [Findings](https://cloud.google.com/security-command-center/do
"principalEmail": "service-project-175089404040@gcp-sa-ktd-hpsa.iam.gserviceaccount.com",
"callerIp": "147.45.44.104",
"callerIpGeo": {

},
"userAgent": "Google-KTD-Control",
"serviceName": "k8s.io",
Expand Down Expand Up @@ -288,7 +288,7 @@ This app uses the [Findings](https://cloud.google.com/security-command-center/do
<details>
<summary>Vulnerability</summary>

```json
```json
{
"message": {
"data": {
Expand Down Expand Up @@ -468,8 +468,8 @@ This section describes the Sumo Logic pipeline for collecting the data from Goog
Follow the steps below to integrate the Google Cloud Security Command Center (SCC) app:

1. Enable the [Security Command Center (SCC)](https://cloud.google.com/security-command-center/docs/activate-scc-overview) at the GCP console.
1. In Sumo Logic, [configure the Google Cloud Platform source](https://help.sumologic.com/docs/send-data/hosted-collectors/google-source/google-cloud-platform-source/#configure-agoogle-cloud-platform-source).
1. In the GCP console, configure a Pub/Sub Topic for [GCP](https://help.sumologic.com/docs/send-data/hosted-collectors/google-source/google-cloud-platform-source/#configure-a-pubsub-topicfor-gcp). This topic will be used to send SCC findings from GCP to Sumo Logic.
1. In Sumo Logic, [configure the Google Cloud Platform source](/docs/send-data/hosted-collectors/google-source/google-cloud-platform-source/#configure-agoogle-cloud-platform-source).
1. In the GCP console, configure a Pub/Sub Topic for [GCP](/docs/send-data/hosted-collectors/google-source/google-cloud-platform-source/#configure-a-pubsub-topicfor-gcp). This topic will be used to send SCC findings from GCP to Sumo Logic.
1. In the SCC blade of the GCP console, click **Continuous Exports**. <br/><img src={useBaseUrl('https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Google+Cloud+-+Security+Command+Center/step4.png')} alt="Google Cloud Storage dashboards" width="500" />
1. In the GCP console, export the findings from SCC to the [Pub/Sub Topic](https://cloud.google.com/security-command-center/docs/how-to-export-data?_gl=1*1dt4zsw*_ga*ODU1MTc4OTQ1LjE3Mzg3ODM5NzI.*_ga_WH2QY8WWF5*czE3NDY2Mzc3MzQkbzMkZzEkdDE3NDY2MzgxNDUkajYwJGwwJGgw#configure-pubsub-exports) created above.

Expand Down
36 changes: 17 additions & 19 deletions docs/integrations/sumo-apps/opentelemetry-collector-insights.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,9 +31,7 @@ Following are the [fields](/docs/manage/fields/) which will be created as part o

Before configuring the OTEL Collector integration, ensure you have the following prerequisites in place:

1. **Sumo Logic OTLP Source**: You need to create an OTLP source in your Sumo Logic hosted collector. The OTLP source will provide the endpoint URL that the OTEL Collector will use to send telemetry data.

**Documentation**: [Creating a Sumo Logic OTLP Source](https://help.sumologic.com/docs/send-data/hosted-collectors/http-source/otlp/)
1. **Sumo Logic OTLP Source**. You need to create an OTLP source in your Sumo Logic hosted collector. The OTLP source will provide the endpoint URL that the OTEL Collector will use to send telemetry data. Learn more at [Creating a Sumo Logic OTLP Source](/docs/send-data/hosted-collectors/http-source/otlp/).

### For metrics collection

Expand Down Expand Up @@ -77,7 +75,7 @@ In this step, you will configure the OpenTelemetry Collector's built-in telemetr

Below are the inputs required:

- **OTLP Endpoint**: Your Sumo Logic OTLP endpoint URL.
- **OTLP Endpoint**. Your Sumo Logic OTLP endpoint URL.


```yaml
Expand Down Expand Up @@ -107,13 +105,13 @@ service:
deployment.environment: ${DEPLOYMENT_ENVIRONMENT}
```

You can add any custom fields which you want to tag along with the data ingested in Sumo.
You can add any custom fields which you want to tag along with the data ingested in Sumo Logic.

import EnvVar from '../../reuse/apps/opentelemetry/env-var-required.md';

<EnvVar/>

<img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/OpenTelemetry-Collector-Insights/opentelemetry-collector-insights-configure-form.png' style={{border:'1px solid gray'}} alt="YAML" />
<img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/OpenTelemetry-Collector-Insights/opentelemetry-collector-insights-configure-form.png' style={{border:'1px solid gray'}} alt="YAML" width="700"/>

### Step 3: Send logs and metrics to Sumo Logic

Expand All @@ -137,31 +135,31 @@ import LogsIntro from '../../reuse/apps/opentelemetry/send-logs-intro.md';

1. Add the telemetry configuration to your existing collector configuration file in `/etc/otelcol-sumo/conf.d/` or directly in the main configuration file.
2. Place Env file in the following directory:
```sh
/etc/otelcol-sumo/env/
```
```sh
/etc/otelcol-sumo/env/
```
3. Restart the collector using:
```sh
sudo systemctl restart otelcol-sumo
```
```sh
sudo systemctl restart otelcol-sumo
```

</TabItem>
<TabItem value="Windows">

1. Add the telemetry configuration to your existing collector configuration file in `C:\ProgramData\Sumo Logic\OpenTelemetry Collector\config\conf.d` or the main configuration file.
2. Restart the collector using:
```sh
Restart-Service -Name OtelcolSumo
```
```sh
Restart-Service -Name OtelcolSumo
```

</TabItem>
<TabItem value="macOS">

1. Add the telemetry configuration to your existing collector configuration file in `/etc/otelcol-sumo/conf.d/` or the main configuration file.
2. Restart the otelcol-sumo process using:
```sh
otelcol-sumo --config /etc/otelcol-sumo/sumologic.yaml --config "glob:/etc/otelcol-sumo/conf.d/*.yaml"
```
```sh
otelcol-sumo --config /etc/otelcol-sumo/sumologic.yaml --config "glob:/etc/otelcol-sumo/conf.d/*.yaml"
```

</TabItem>
<TabItem value="Chef">
Expand Down Expand Up @@ -419,4 +417,4 @@ import CreateMonitors from '../../reuse/apps/create-monitors.md';
| `OpenTelemetry Collector Insights - Collector Instance is Down` | This alert fires when a Collector instance stops sending telemetry for more than 10 minutes, indicating it is down or has a connectivity issue. | Missing Data | Data Found |
| `OpenTelemetry Collector Insights - Exporter Queue Nearing Capacity` | This alert fires when an exporter's sending queue is over 90% full. This is a strong leading indicator of back pressure and imminent data loss. | Count > = 90 | Count < 90 |
| `OpenTelemetry Collector Insights - High Memory Usage (RSS)` | This alert fires when a Collector's memory usage (RSS) exceeds 2GB. This could be an early indicator of a memory leak or an under-provisioned host. | Count > 2000000000 | Count < = 2000000000 |
| `OpenTelemetry Collector Insights - High Metadata Cardinality` | This alert fires when the batch processor is handling more than 1000 unique combinations of metadata. This is a known cause of performance degradation, high CPU, and high memory usage. | Count > 1000 | Count < = 1000 |
| `OpenTelemetry Collector Insights - High Metadata Cardinality` | This alert fires when the batch processor is handling more than 1000 unique combinations of metadata. This is a known cause of performance degradation, high CPU, and high memory usage. | Count > 1000 | Count < = 1000 |