Skip to main content
Skip to main content

Storing ClickHouse Cloud Audit logs into Splunk

ClickHouse Supported

Splunk is a data analytics and monitoring platform.

This add-on allows users to store the ClickHouse Cloud audit logs into Splunk. It uses ClickHouse Cloud API to download the audit logs.

This add-on contains only a modular input, no additional UI are provided with this add-on.

Installation

For Splunk Enterprise

Download the ClickHouse Cloud Audit Add-on for Splunk from Splunkbase.

Splunkbase website showing the ClickHouse Cloud Audit Add-on for Splunk download page - Zoomed

In Splunk Enterprise, navigate to Apps -> Manage. Then click on Install app from file.

Splunk Enterprise interface showing the Apps management page with Install app from file option - Zoomed

Select the archived file downloaded from Splunkbase and click on Upload.

Splunk app installation dialog for uploading the ClickHouse add-on - Zoomed

If everything goes fine, you should now see the ClickHouse Audit logs application installed. If not, consult the Splunkd logs for any errors.

Modular input configuration

To configure the modular input, you'll first need information from your ClickHouse Cloud deployment:

  • The organization ID
  • An admin API Key

Getting information from ClickHouse Cloud

Log in to the ClickHouse Cloud console.

Navigate to your Organization -> Organization details. There you can copy the Organization ID.

ClickHouse Cloud console showing the Organization details page with Organization ID - Zoomed

Then, navigate to API Keys from the left-end menu.

ClickHouse Cloud console showing the API Keys section in the left navigation menu - Zoomed

Create an API Key, give a meaningful name and select Admin privileges. Click on Generate API Key.

ClickHouse Cloud console showing the API Key creation interface with Admin privileges selected - Zoomed

Save the API Key and secret in a safe place.

ClickHouse Cloud console showing the generated API Key and secret to be saved - Zoomed

Configure data input in Splunk

Back in Splunk, navigate to Settings -> Data inputs.

Splunk interface showing the Settings menu with Data inputs option - Zoomed

Select the ClickHouse Cloud Audit Logs data input.

Splunk Data inputs page showing the ClickHouse Cloud Audit Logs option - Zoomed

Click "New" to configure a new instance of the data input.

Splunk interface for configuring a new ClickHouse Cloud Audit Logs data input - Zoomed

Once you have entered all the information, click Next.

Splunk configuration page with completed ClickHouse data input settings - Zoomed

The input is configured, you can start browsing the audit logs.

Usage

The modular input stores data in Splunk. To view the data, you can use the general search view in Splunk.

Splunk search interface showing ClickHouse audit logs data - Zoomed
Try ClickHouse Cloud for FREE

Easy data ingestion, automatic scaling, built-in SQL console and lots more.

Try it for Free