Getting Data In

i am using openshift 4.16.32 and i used helm for splunk-otel-collector and i get this error in the pods

tawfiq15
New Member

2025-05-06T13:50:00.857Z error helper/transformer.go:118 Failed to process entry {"otelcol.component.id": "filelog", "otelcol.component.kind": "receiver", "otelcol.signal": "logs", "operator_id": "move", "operator_type": "move", "error": "move: field does not exist: attributes.uid", "action": "send", "entry.timestamp": "2025-05-06T13:49:09.153Z", "time": "2025-05-06T13:49:09.153467683+00:00", "log.file.path": "/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log", "stream": "stderr", "logtag": "F", "log": "2025-05-06T13:49:09.153Z\terror\thelper/transformer.go:118\tFailed to process entry\t{\"otelcol.component.id\": \"filelog\", \"otelcol.component.kind\": \"receiver\", \"otelcol.signal\": \"logs\", \"operator_id\": \"add\", \"operator_type\": \"add\", \"error\": \"evaluate value_expr: invalid operation: string + <nil> (1:18)\\n | \\\"kube:container:\\\"+resource[\\\"k8s.container.name\\\"]\\n | .................^\", \"action\": \"send\", \"entry.timestamp\": \"2025-05-06T13:48:59.854Z\", \"log.file.path\": \"/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log\", \"stream\": \"stderr\", \"logtag\": \"F\", \"log\": \"github.com/open-telemetry/opentelemetry-collector-contrib/pkg/stanza/operator/transformer/move.(*Transformer).Process\", \"time\": \"2025-05-06T13:48:59.854

Labels (2)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @tawfiq15 

Are you able to share your helm chart so I can check over it and compare to the log, please?

Below is the formatted version of the log to make it easier to read:

timestamp: 2025-05-06T13:50:00.857Z
level: error
file: helper/transformer.go:118
message: Failed to process entry
fields:
  otelcol.component.id: "filelog"
  otelcol.component.kind: "receiver"
  otelcol.signal: "logs"
  operator_id: "move"
  operator_type: "move"
  error: "move: field does not exist: attributes.uid"
  action: "send"
  entry.timestamp: "2025-05-06T13:49:09.153Z"
  time: "2025-05-06T13:49:09.153467683+00:00"
  log.file.path: "/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log"
  stream: "stderr"
  logtag: "F"
  log: |
    2025-05-06T13:49:09.153Z error helper/transformer.go:118 Failed to process entry
    {
      "otelcol.component.id": "filelog",
      "otelcol.component.kind": "receiver",
      "otelcol.signal": "logs",
      "operator_id": "add",
      "operator_type": "add",
      "error": "evaluate value_expr: invalid operation: string + <nil> (1:18)\n | \"kube:container:\"+resource[\"k8s.container.name\"]\n | .................^",
      "action": "send",
      "entry.timestamp": "2025-05-06T13:48:59.854Z",
      "log.file.path": "/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log",
      "stream": "stderr",
      "logtag": "F",
      "log": "github.com/open-telemetry/opentelemetry-collector-contrib/pkg/stanza/operator/transformer/move.(*Transformer).Process",
      "time": "2025-05-06T13:48:59.854
    }

 

Thanks

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...