Migrate Configurations
Convert OpenTelemetry, Chronicle Forwarder, and Splunk Universal Forwarder configurations into Bindplane resources with Pipeline Intelligence.
Last updated
Was this helpful?
Convert OpenTelemetry, Chronicle Forwarder, and Splunk Universal Forwarder configurations into Bindplane resources with Pipeline Intelligence.
Pipeline Intelligence can convert existing configurations from several vendors into Bindplane configurations. You can provide your current configuration file, run the Pipeline Intelligence analysis, review the compatible resources, and create a configuration.


Pipeline Intelligence will analyze an OpenTelemetry configuration and return compatible sources, processors, and destinations. Resources that are available in your available components but not as a Bindplane resource will be shown as a custom resource.
The OpenTelemetry migrator is only available for Enterprise, Bindplane Enterprise (Google Edition), and Honeycomb licenses.
Pipeline Intelligence maps all Chronicle Forwarder collector types (Splunk, syslog, file, packet capture, Kafka, and web proxy) into Bindplane sources, adds processors for standardization, and creates a Google SecOps destination.
Syslog collectors map to separate TCP and/or UDP sources, preserving their port settings. The web proxy and PCAP collector types automatically translate to OS-appropriate capture methods: npcap on Windows and libpcap (via tcpdump) on Linux. Tcpdump is typically preinstalled, but the collector host must have it available. See PCAP source prerequisites for details. Kafka collectors translate to the Kafka stream source with their corresponding broker configuration.
Bindplane supports both Chronicle Forwarder configuration formats:
Two-file configuration (more common): Upload the main configuration file containing your collectors plus the separate authentication file containing credentials and TLS settings.
Single-file configuration: Upload your combined configuration file in the first field and leave the second field blank.
For instructions on how to download your Chronicle Forwarder configuration files, see here.
For more information about migrating from the legacy Chronicle Forwarder, see here.
Pipeline Intelligence will map several Splunk inputs – Monitor, Windows Event Log Monitor, TCP, UDP, Batch – into Bindplane sources. Pipeline Intelligence will map HTTP outputs into corresponding Splunk HEC destinations.
Last updated
Was this helpful?
Was this helpful?