All Apps and Add-ons

Line breaking for kubernetes logs which are ingesting using Monitoring Kubernetes - Metrics and Log Forwarding App

sathwikr076
Communicator

@outcoldman , we are using monitoring kubernetes app to ingest the logs from the Kubernetes containers but some of the logs are having some line breaking issue. I tried configuring using props.conf but the logs are not taking it. can you please let me know about this.

Thanks.

1 Solution

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

View solution in original post

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to support@outcoldsolutions.com and we will help you with that.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...