All skills
secondsky avatar

/sap-btp-cloud-logging

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

This skill provides comprehensive guidance for SAP Cloud Logging service on SAP BTP. Use when setting up Cloud Logging instances, configuring log ingestion from Cloud Foundry or Kyma runtimes, implementing OpenTelemetry observability, analyzing logs/metrics/traces in OpenSearch Dashboards, configuring SAML authentication, managing certificates, or troubleshooting ingestion issues. Covers service plans (dev/standard/large), all 4 instance creation methods (BTP Cockpit, CF CLI, BTP CLI, Service Operator), all 4 ingestion methods (Cloud Foundry, Kyma, OpenTelemetry, JSON API), and security best practices.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-btp-cloud-logging

This session only. Nothing lands on disk.

referencesopentelemetry-ingestion.md

≈2.7k tokens on demand. Your agent reads this file only when SKILL.md points to it.

SAP Cloud Logging - OpenTelemetry Ingestion Reference

Source: https://github.com/SAP-docs/btp-cloud-logging/blob/main/docs/ingest-via-opentelemetry-api-endpoint-fdc78af.md Last Updated: 2025-11-22


Table of Contents


Overview

SAP Cloud Logging accepts OpenTelemetry data through OTLP using a unified endpoint for logs, metrics, and traces. Only gRPC protocol is supported - http/protobuf and http/json must be converted using OpenTelemetry Collector.


Index Patterns

Signal Type Index Pattern
Logs logs-otel-v1-*
Metrics metrics-otel-v1-*
Traces otel-v1-apm-span-*
Service Map otel-v1-apm-service-map

Note: Attribute names have dots (.) replaced with @ due to OpenSearch/Lucene limitations. Example: service.name becomes service@name.


Enable OTLP Endpoint

Step 1: Update Instance Configuration

cf update-service <instance-name> -c '{
  "ingest_otlp": {
    "enabled": true
  }
}'

Or via BTP CLI:

btp update services/instance \
  --subaccount <SUBACCOUNT_ID> \
  --name <instance-name> \
  --parameters '{"ingest_otlp": {"enabled": true}}'

Step 2: Create New Service Binding

cf create-service-key <instance-name> otlp-key
cf service-key <instance-name> otlp-key

Service Key Credentials

When OTLP is enabled, bindings include these additional credentials:

Credential Format Description
ingest-otlp-endpoint hostname:443 gRPC endpoint
ingest-otlp-cert PEM Client certificate
ingest-otlp-key PKCS#8 Private key
server-ca PEM Server CA certificate

Certificate Configuration

Validity Period

Setting Value
Default Validity 90 days
Configurable Range 1-180 days
Parameter certValidityDays

Configure Custom Validity

cf create-service-key <instance-name> my-key -c '{"certValidityDays": 180}'

Certificate Rotation

Deleting a service key/binding does NOT revoke the certificate. To invalidate certificates:

  1. Use root CA rotation (rotate_root_ca parameter)
  2. Or wait for certificate expiration

Manual Configuration

Generic OpenTelemetry SDK Setup

# Python example
from opentelemetry import trace
from opentelemetry.sdk.trace import TracerProvider
from opentelemetry.sdk.trace.export import BatchSpanProcessor
from opentelemetry.exporter.otlp.proto.grpc.trace_exporter import OTLPSpanExporter

# Configure exporter with mTLS
exporter = OTLPSpanExporter(
    endpoint="<ingest-otlp-endpoint>",
    credentials=ssl_channel_credentials(
        root_certificates=open("server-ca.pem", "rb").read(),
        private_key=open("client-key.pem", "rb").read(),
        certificate_chain=open("client-cert.pem", "rb").read(),
    ),
)

# Set up provider
provider = TracerProvider()
processor = BatchSpanProcessor(exporter)
provider.add_span_processor(processor)
trace.set_tracer_provider(provider)

OpenTelemetry Collector Configuration

Use when you need to convert http/protobuf or http/json to gRPC:

# otel-collector-config.yaml
receivers:
  otlp:
    protocols:
      http:
        endpoint: 0.0.0.0:4318
      grpc:
        endpoint: 0.0.0.0:4317

exporters:
  otlp/cls:
    endpoint: "<ingest-otlp-endpoint>"
    tls:
      cert_file: /certs/client.crt
      key_file: /certs/client.key
      ca_file: /certs/server-ca.crt

service:
  pipelines:
    traces:
      receivers: [otlp]
      exporters: [otlp/cls]
    metrics:
      receivers: [otlp]
      exporters: [otlp/cls]
    logs:
      receivers: [otlp]
      exporters: [otlp/cls]

Java Automation

SAP provides a BTP Observability Extension that automatically configures OTLP exporters.

Maven Dependency

<dependency>
  <groupId>com.sap.cloud.environment.servicebinding</groupId>
  <artifactId>java-modules-bom</artifactId>
  <version>${sap.cloud.sdk.version}</version>  <!-- Pin to specific version -->
  <type>pom</type>
  <scope>import</scope>
</dependency>

<dependency>
  <groupId>com.sap.cloud.observability</groupId>
  <artifactId>observability-client</artifactId>
</dependency>

Note: For production, pin versions instead of using LATEST. Check SAP Cloud SDK releases for current stable versions.

How It Works

  1. Extension automatically scans environment variables for Cloud Logging bindings
  2. Configures OTLP exporters for logs, metrics, and traces
  3. No manual endpoint configuration required

Spring Boot Integration

# application.yaml
management:
  tracing:
    sampling:
      probability: 1.0
@SpringBootApplication
public class Application {
    public static void main(String[] args) {
        SpringApplication.run(Application.class, args);
    }
}

Node.js Automation

SAP provides a dedicated Cloud Logging exporter package.

Installation

npm install @sap/cloud-logging-client

Usage

const { CloudLoggingExporter } = require('@sap/cloud-logging-client');

// Automatically scans VCAP_SERVICES for Cloud Logging binding
const exporter = new CloudLoggingExporter();

// Configure OpenTelemetry SDK
const { NodeTracerProvider } = require('@opentelemetry/sdk-trace-node');
const { BatchSpanProcessor } = require('@opentelemetry/sdk-trace-base');

const provider = new NodeTracerProvider();
provider.addSpanProcessor(new BatchSpanProcessor(exporter.getTraceExporter()));
provider.register();

Features

  • Automatic binding detection from VCAP_SERVICES
  • Pre-configured exporters for logs, metrics, and traces
  • Handles mTLS certificate configuration

User-Provided Service for OTLP

For scenarios where you need to manually configure OTLP credentials (e.g., sharing across spaces):

# Create credentials.json with OTLP service key values
cat > credentials.json << 'EOF'
{
  "ingest-otlp-endpoint": "<endpoint>:443",
  "ingest-otlp-cert": "<client-cert>",
  "ingest-otlp-key": "<client-key>",
  "server-ca": "<server-ca>"
}
EOF

# Create user-provided service with "Cloud Logging" tag
cf cups <service-name> -p credentials.json -t "Cloud Logging"

Important: The Cloud Logging tag is required for automatic detection by SAP libraries.


Attribute Name Mapping

Important: Signal and resource attribute names have dots (.) replaced with @ and contain a prefix specifying the attribute type.

Original Attribute Mapped Attribute
service.name resource@service@name
http.method attributes@http@method
span.kind span@kind

This mapping is due to OpenSearch/Lucene field name limitations.


Kubernetes/Kyma Setup

Deploy Credentials as Secret

apiVersion: v1
kind: Secret
metadata:
  name: cls-otlp-credentials
  namespace: my-app
type: Opaque
stringData:
  OTEL_EXPORTER_OTLP_ENDPOINT: "<ingest-otlp-endpoint>"
  OTEL_EXPORTER_OTLP_CERTIFICATE: |
    <ingest-otlp-cert content>
  OTEL_EXPORTER_OTLP_CLIENT_KEY: |
    <ingest-otlp-key content>
  OTEL_EXPORTER_OTLP_CA_CERTIFICATE: |
    <server-ca content>

Application Deployment

apiVersion: apps/v1
kind: Deployment
metadata:
  name: my-app
spec:
  template:
    spec:
      containers:
      - name: app
        envFrom:
        - secretRef:
            name: cls-otlp-credentials
        volumeMounts:
        - name: certs
          mountPath: /certs
          readOnly: true
      volumes:
      - name: certs
        secret:
          secretName: cls-otlp-credentials

Troubleshooting

Connection Refused

  1. Verify ingest_otlp.enabled: true in instance configuration
  2. Check endpoint format is hostname:443 (not `https://...``)
  3. Verify firewall/network allows gRPC traffic

Certificate Errors

  1. Ensure all three certificates are provided:
    • Client certificate (ingest-otlp-cert)
    • Client key (ingest-otlp-key)
    • Server CA (server-ca)
  2. Verify certificate hasn't expired
  3. Check PEM format is correct (includes headers)

Data Not Appearing

  1. Check correct index pattern in Dashboards
  2. Remember attribute name transformation (. → @)
  3. Verify data is being exported (check collector logs)

Protocol Mismatch

  • Symptom: "protocol not supported" errors
  • Solution: OTLP endpoint only accepts gRPC. Use OpenTelemetry Collector to convert http protocols.

Documentation Links

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides operational guidance for SAP BTP Cloud Logging, including setup instructions, CLI commands, and telemetry configuration. It identifies an inherent surface for indirect prompt injection through the ingestion of external log data.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    8/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2025-11-27",
  "source_documentation": "https://github.com/SAP-docs/btp-cloud-logging",
  "sap_help_portal": "https://help.sap.com/docs/cloud-logging"
}

README badge

README badge for secondsky/sap-skills/sap-btp-cloud-logging