Hi
My environment is as below AWS EKS cluster and on premise Splunk. I have configured Splunk connector with indexRouting enabled. There is situation where I am seeing logs in EKS pods which are not moved to Splunk. In this case how to debug the issue to find the root cause.
Please help, i am new to K8 and Splunk.
Thanks.
Hi @rmurali4u
Check the time format of the events not moved, if they have a european data (dd/mm/yyyy) Splunk takes an american format (mm/dd/yyyy) so events of 9th of december are indexed at the 12 of september.
Ciao.
Giuseppe