Hi all,
I am very new to Splunk and trying to avoid sending metrics to Splunk from the sc4s container.
Memory consumption is really growing to > 250Mb and we use sc4s only for sending ~100 lines every 10m, so metrics is really not necessary for us.
I have tried to set syslog-ng source s_internal to a null destination but cant make it work.
Any advice would be greatly appreciated.
Thank you very much
Daniel
Hi,
Thank you for your aswer.
I'm trying to prevent SC4S to send via HEC syslog-ng logs, metrics and any other traffic besides the actual logs becase we have a low ressources environment.
In /opt/sc4s/local/config/destinations/block_me.conf:
destination d_block_metrics {
file("/dev/null");
};
And in /opt/sc4s/local/config/log_paths/block_me.conf:
log {
source(s_internal);
source(s_system);
#destination(d_hec_debug);
destination(d_block_metrics);
flags(final);
};
I guess I'm doing something wrong because even with flags(final); all metrics and errors are still being sent to Splunk.
I just need to restrict ressources because used memory grows uncontrollably until it reaches the 256Mb allocated to the container.
Thank's a lot
Daniel
I have a couple of questions:
- Are you trying to get rid of the the metrics data from Splunk's metrics.log?
- Can you post the props and transforms config that you tried?
What you're trying to do may not "fix" the memory utilization on your container.