All Apps and Add-ons

No proper ingestion from outcold setup for kubernetes to Splunk

sathwikr076
Communicator

Hello @outcoldman,

We are using monitoring kubernetes app to get the logs from kubernetes containers. The ingestion from our test containers is fine which was setup long before by different splunk admin but when we are trying to get the logs from our prod containers now and there is some problem. The logs ingest fine for few hours from the containers and there will be no ingestion after that. Unfortunately i don't have access to the kubernetes cotainers to see the outcold setup but i have been getting the error which says "Failed to post (statusCode=400, reason=Incorrect index, code=7). Retrying in few seconds" even though we have given the correct index. My question is if there is any problem with the setup there should be no ingestion but we are getting the logs and stops after few hours. Please let me know if you came across situation like this. Sorry i could not provide the outcold setup details on the kubernetes containers.

Thanks,
Sathwik.

0 Karma

outcoldman
Communicator

@sathwikr076 to be able to resolve this issue - will be better to send a support ticket to support@outcoldsolutions.com

The reason for this error is that HEC does not have access to write to this index, or this index does not exist on Splunk. Depending on the version of Collectord you are using, you can configure incorrect index behavior with the configuration, see https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/splunk-output/#http-event-collector-i...

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...