Getting Data In

Log field to Splunk using HEC appender

dlarah
New Member

Hi,
I want to log a field, in this case the app version of an application to splunk. The application runs in cloud foundry. The app version is available as an env variable.
I am using the HttpEventCollectorLogbackAppender (HECLogbackAppender)

First try: When I extend the HttpEventCollectorLogbackAppender class and add a variable appVersion, just like the other fields sourcetype, source, and so on, that doesn't work, it's not inside the json that's being sent to Splunk.

Second try: When I add the app_version with

MDC.put("app_version", my_app_version_from_env_var) 

(google for "logback MDC" for more information on MDC)
the app_version gets logged in the properties field of the json when the app starts, so all the Spring-related stuff that gets logged when a Spring application starts, contains "properties":{"app_version":"1.13"} in the json.
But after a few logs, the properties field does not appear anymore, and so doesn't the app_version.
Can someone help?

Regards

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...