aiFWall Logo aiFObserve

Distributed, Contextual Visibility & Governance for Enterprise AI Traffic. No Agents, No APIs, No

Splunk OTLP Capture Guide For Unified aiFObserve

Best Capture Source

Export security events from Splunk Enterprise, Splunk Cloud, or Splunk Enterprise Security through an OTLP-capable pipeline. Preserve index, sourcetype, source, CIM fields, and raw event text.

Basic Logging

Extended Logging

User And App Identity

OTLP Mapping Notes

Map Splunk metadata into attributes such as splunk.index, splunk.sourcetype, splunk.source, and event.original. Keep CIM field names alongside vendor raw fields when possible.

Source