<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk OTEL Collector: Log Scarping Issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-OTEL-Collector-Log-Scarping-Issue/m-p/647888#M110165</link>
    <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have configured the Splunk OTEL collector to collect logs from OpenShift environment namespaces and Pods and send them to Splunk Enterprise using HEC (HTTP Event Collector). However, we are experiencing unusual behavior with the values.yaml configuration when it comes to collecting audit logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;logsCollection:&lt;BR /&gt;extraFileLogs:&lt;BR /&gt;filelog/audit-log-kube-apiserver:&lt;BR /&gt;include: [/var/log/kube-apiserver/audit.log]&lt;BR /&gt;start_at: beginning&lt;BR /&gt;include_file_path: true&lt;BR /&gt;include_file_name: false&lt;BR /&gt;resource:&lt;BR /&gt;com.splunk.source: /var/log/kube-apiserver/audit.log&lt;BR /&gt;host.name: 'EXPR(env("K8S_NODE_NAME"))'&lt;BR /&gt;com.splunk.sourcetype: kube:apiserver-audit&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm having an issue with the OTEL collector Pod. Whenever I restart it, it starts ingesting data from the beginning instead of resuming where it left off. I've tried modifying the "start_at" option by setting it to "current," but that didn't work. I also attempted removing the key-value pair, but it didn't solve the problem. I would greatly appreciate any assistance in resolving this matter.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 22 Jun 2023 08:52:27 GMT</pubDate>
    <dc:creator>vprasadeee_7</dc:creator>
    <dc:date>2023-06-22T08:52:27Z</dc:date>
    <item>
      <title>Splunk OTEL Collector: Log Scarping Issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-OTEL-Collector-Log-Scarping-Issue/m-p/647888#M110165</link>
      <description>&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We have configured the Splunk OTEL collector to collect logs from OpenShift environment namespaces and Pods and send them to Splunk Enterprise using HEC (HTTP Event Collector). However, we are experiencing unusual behavior with the values.yaml configuration when it comes to collecting audit logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;logsCollection:&lt;BR /&gt;extraFileLogs:&lt;BR /&gt;filelog/audit-log-kube-apiserver:&lt;BR /&gt;include: [/var/log/kube-apiserver/audit.log]&lt;BR /&gt;start_at: beginning&lt;BR /&gt;include_file_path: true&lt;BR /&gt;include_file_name: false&lt;BR /&gt;resource:&lt;BR /&gt;com.splunk.source: /var/log/kube-apiserver/audit.log&lt;BR /&gt;host.name: 'EXPR(env("K8S_NODE_NAME"))'&lt;BR /&gt;com.splunk.sourcetype: kube:apiserver-audit&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm having an issue with the OTEL collector Pod. Whenever I restart it, it starts ingesting data from the beginning instead of resuming where it left off. I've tried modifying the "start_at" option by setting it to "current," but that didn't work. I also attempted removing the key-value pair, but it didn't solve the problem. I would greatly appreciate any assistance in resolving this matter.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jun 2023 08:52:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-OTEL-Collector-Log-Scarping-Issue/m-p/647888#M110165</guid>
      <dc:creator>vprasadeee_7</dc:creator>
      <dc:date>2023-06-22T08:52:27Z</dc:date>
    </item>
  </channel>
</rss>

