All Apps and Add-ons

Line breaking for kubernetes logs which are ingesting using Monitoring Kubernetes - Metrics and Log Forwarding App

sathwikr076
Communicator

@outcoldman , we are using monitoring kubernetes app to ingest the logs from the Kubernetes containers but some of the logs are having some line breaking issue. I tried configuring using props.conf but the logs are not taking it. can you please let me know about this.

Thanks.

1 Solution

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to [email protected] and we will help you with that.

View solution in original post

outcoldman
Communicator

@sathwikr076 considering that Collectord is ingesting logs with Splunk HTTP Event Collector on events endpoint, that input method does not support props.conf. You need to configure event patterns on the source side. In case of Kubernetes you can define that with annotations for Pods or Workloads, like in the example https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/annotations/#defining-event-pattern (that is if you are using the latest version of our application v5.x)

If you need help with configuring the pattern, feel free to send email to [email protected] and we will help you with that.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...