- Print
- DarkLight
Integrate Splunk with Backblaze B2
- Print
- DarkLight
Splunk is a data analytics platform that provides data-driven insights across all aspects of a company. You can configure Splunk to use Backblaze B2 Cloud Storage. You must have your Backblaze B2 application key and bucket ready to set up the connection.
Enable Backblaze B2
Before you begin: You must have a Backblaze B2 Cloud Storage account. You can sign up here. If you already have a Backblaze account and the left navigation menu contains a B2 Cloud Storage section, your account is already enabled for Backblaze B2.
- Sign in to your Backblaze account.
- In the left navigation menu under Account, click My Settings.
- Under Enabled Products, select the checkbox to enable B2 Cloud Storage.
- Review the Terms and Conditions, and click OK to accept them.
Create a Bucket
- Sign in to your Backblaze account.
- In the left navigation menu under B2 Cloud Storage, click Buckets.
- Click Create a Bucket.
- Enter a name for your bucket.
Bucket names must be at least six characters and globally unique. A message is displayed if your bucket name is already in use. - Select a privacy setting: Private or Public.
Files that are in a private bucket require authentication to perform an action, for example, downloading. Public buckets do not require authentication so you can easily share files. You can change a bucket's privacy settings at any time. - If applicable, enable a Backblaze B2 server-side encryption key.
- Enable Object Lock to restrict a file from being modified or deleted for a specified period of time.
- Click Create a Bucket, and copy the value that is in the Endpoint field; you may need this value for other processes.
- Click Lifecycle Settings to control how long to keep the files in your new bucket.
Note the S3 endpoint listed here for use in another step.
Create an Application Key
Application keys control access to your Backblaze B2 Cloud Storage account and the buckets that are contained in your account.
- Sign in to your Backblaze account.
- In the left navigation menu under Account, click Application Keys.
- Click Add a New Application Key, and enter an app key name.
You cannot search an app key by this name; therefore, app key names are not required to be globally unique. - In the Allow Access to Bucket(s) dropdown menu, select All or a specific bucket.
- Select your access type (for example, Read and Write).
- Select the optional Allow List All Bucket Names checkbox (required for the Backblaze B2 S3-compatible API List Buckets operation).
- Click Create New Key, and note the resulting keyID and applicationKey values.
Set Up Splunk with Backblaze B2
- Using your computer's command line interface, open the Splunk
indexes.conf
file for editing. - Add the following information about your Backblaze B2 account to the
indexes.conf
file:- Your Backblaze B2 key ID
- Your Backblaze B2 application key
- Your Backblaze B2 endpoint URL
- Your Backblaze B2 endpoint region
The commands for editing your indexes.conf
file should be similar to the following example. Use your own Backblaze B2 account information instead of the placeholders for the access key, secret key, endpoint, and auth region.
[volume:B2]
storageType = remote
path = s3://smartstore/
remote.s3.access_key = <00512f95cf4dcf0000000004z>
remote.s3.secret_key = <K0041ZMxZEop4JkYzUJqEei1ZLep14z>
remote.s3.endpoint = https://s3.us-west-000.backblazeb2.com
remote.s3.auth_region = us-west-000