Splunk Search

Get source logs from pod

jocteau
New Member

Hello,

I'm really a newbie with Splunk and just started to use it.
First, can someone recommend me good tutorials about Splunk?

And second, we have Splunk logging our whole infrastructure (jobs failing, crons, daemons, API calls etc...). I already set up  a dashboard to monitor everything. But now I would like to be able to get the whole output of a "pod".
For example: 

Screen Shot 2021-02-10 at 5.14.07 PM.png

I would like to get the same output as when I click on `Event Actions > Show Source` but only for the pod:
`cron-prod-campaignactivator-1612980360-49zss`.
How would look like my query? 

Thank you in advance,
Jeremy

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

your query would be

index=eks sourcetype=fluent pod=cron-prod-campaignactivator-1612980360-49zss
| table _raw

Is that what you want to see?

As far as Splunk tutorials go, have a look at Splunk fundamentals 1 free course

https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html

 

jocteau
New Member

Hi Bowesmana!

when I try to run this query, I sadly don't get any results, should I run it in a different place?

Screen Shot 2021-02-11 at 1.30.32 PM.png

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

@jocteau 

Your original post, and my reply show the index value as eks. Looks like you have a typo, as you have put

index=ek

 

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...