All Apps and Add-ons

Line breaking for kubernetes logs which are ingesting using Monitoring Kubernetes - Metrics and Log Forwarding App

sathwikr076
Communicator

@outcoldman , we are using monitoring kubernetes app to ingest the logs from the Kubernetes containers but some of the logs are having some line breaking issue. I tried configuring using props.conf but the logs are not taking it. can you please let me know about this.

Thanks.

1 Solution

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

View solution in original post

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...