All Apps and Add-ons

Line breaking for kubernetes logs which are ingesting using Monitoring Kubernetes - Metrics and Log Forwarding App

sathwikr076
Communicator

@outcoldman , we are using monitoring kubernetes app to ingest the logs from the Kubernetes containers but some of the logs are having some line breaking issue. I tried configuring using props.conf but the logs are not taking it. can you please let me know about this.

Thanks.

1 Solution

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

View solution in original post

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...