All Apps and Add-ons

Line breaking for kubernetes logs which are ingesting using Monitoring Kubernetes - Metrics and Log Forwarding App

sathwikr076
Communicator

@outcoldman , we are using monitoring kubernetes app to ingest the logs from the Kubernetes containers but some of the logs are having some line breaking issue. I tried configuring using props.conf but the logs are not taking it. can you please let me know about this.

Thanks.

1 Solution

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

View solution in original post

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...