All Apps and Add-ons

No proper ingestion from outcold setup for kubernetes to Splunk

sathwikr076
Communicator

Hello @outcoldman,

We are using monitoring kubernetes app to get the logs from kubernetes containers. The ingestion from our test containers is fine which was setup long before by different splunk admin but when we are trying to get the logs from our prod containers now and there is some problem. The logs ingest fine for few hours from the containers and there will be no ingestion after that. Unfortunately i don't have access to the kubernetes cotainers to see the outcold setup but i have been getting the error which says "Failed to post (statusCode=400, reason=Incorrect index, code=7). Retrying in few seconds" even though we have given the correct index. My question is if there is any problem with the setup there should be no ingestion but we are getting the logs and stops after few hours. Please let me know if you came across situation like this. Sorry i could not provide the outcold setup details on the kubernetes containers.

Thanks,
Sathwik.

0 Karma

outcoldman
Communicator

@sathwikr076 to be able to resolve this issue - will be better to send a support ticket to support@outcoldsolutions.com

The reason for this error is that HEC does not have access to write to this index, or this index does not exist on Splunk. Depending on the version of Collectord you are using, you can configure incorrect index behavior with the configuration, see https://www.outcoldsolutions.com/docs/monitoring-kubernetes/v5/splunk-output/#http-event-collector-i...

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...