<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Kubernetes/OpenShift Splunk Connect: How to send logs from specific namespace to an index? in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Kubernetes-OpenShift-Splunk-Connect-How-to-send-logs-from/m-p/541666#M9658</link>
    <description>&lt;P&gt;Yes, connect for Kubernetes supports the use of annotations to route data. Please ensure to use the latest, currently 1.4.6 at time of writing this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/splunk/splunk-connect-for-kubernetes#managing-sck-log-ingestion-by-using-annotations" target="_blank"&gt;https://github.com/splunk/splunk-connect-for-kubernetes#managing-sck-log-ingestion-by-using-annotations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 28 Feb 2021 14:17:30 GMT</pubDate>
    <dc:creator>mattymo</dc:creator>
    <dc:date>2021-02-28T14:17:30Z</dc:date>
    <item>
      <title>Kubernetes/OpenShift Splunk Connect: How to send logs from specific namespace to an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Kubernetes-OpenShift-Splunk-Connect-How-to-send-logs-from/m-p/537673#M9657</link>
      <description>&lt;P&gt;I have a Splunk Connect instance on my OpenShift cluster that's currently sending all logs to a logging index. There's no special configuration and the only tweeking done after installation is pointing to the right Splunk instance / applying the HEC token value.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a way to set the config map such that all logs from a namespace (i.e. 'specificApplication') goes to an index?&lt;/P&gt;&lt;P&gt;Here's a snippet of what the current config map for logging looks like - not sure if this would shed insight as I'm not too familiar with Splunk:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;lt;match&amp;nbsp;**&amp;gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;@type&amp;nbsp;splunk_hec&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;protocol&amp;nbsp;http&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;hec_host&amp;nbsp;"xx.x.xx.xx"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;hec_port&amp;nbsp;8088&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;hec_token&amp;nbsp;"#{ENV['SPLUNK_HEC_TOKEN']}"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;index_key&amp;nbsp;index&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;#insecure_ssl&amp;nbsp;true&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;host&amp;nbsp;"#{ENV['K8S_NODE_NAME']}"&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;source_key&amp;nbsp;source&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;sourcetype_key&amp;nbsp;sourcetype&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 28 Jan 2021 17:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Kubernetes-OpenShift-Splunk-Connect-How-to-send-logs-from/m-p/537673#M9657</guid>
      <dc:creator>catherinelam</dc:creator>
      <dc:date>2021-01-28T17:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: Kubernetes/OpenShift Splunk Connect: How to send logs from specific namespace to an index?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Kubernetes-OpenShift-Splunk-Connect-How-to-send-logs-from/m-p/541666#M9658</link>
      <description>&lt;P&gt;Yes, connect for Kubernetes supports the use of annotations to route data. Please ensure to use the latest, currently 1.4.6 at time of writing this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/splunk/splunk-connect-for-kubernetes#managing-sck-log-ingestion-by-using-annotations" target="_blank"&gt;https://github.com/splunk/splunk-connect-for-kubernetes#managing-sck-log-ingestion-by-using-annotations&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 14:17:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Kubernetes-OpenShift-Splunk-Connect-How-to-send-logs-from/m-p/541666#M9658</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2021-02-28T14:17:30Z</dc:date>
    </item>
  </channel>
</rss>

