Getting Data In

How to handle multiline Kubernetes logs?

New Member

Hi, I'm trying to make multiline work
I posted an issue here [][]

Basically it seems to work (multiline are single event in Splunk) but I'm getting a lot of errors in Splunk pod logs. I believe one per 5 second per log file

"deadlock; recursive locking" ,Hi mmodestino,

I'm trying to make the multiline work. I posted an issue on Github
It kind of works but I'm getting "deadlock; recursive locking" errors in the Splunk pod logs. A lot of them. I think every 5 seconds for every log file, for every splunk pod

Why is it going into a loop?

Tags (2)
0 Karma


Converted from an answer to an old question into a new question.

If this reply helps you, an upvote would be appreciated.
0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!