Splunk Search

Get source logs from pod

jocteau
New Member

Hello,

I'm really a newbie with Splunk and just started to use it.
First, can someone recommend me good tutorials about Splunk?

And second, we have Splunk logging our whole infrastructure (jobs failing, crons, daemons, API calls etc...). I already set up  a dashboard to monitor everything. But now I would like to be able to get the whole output of a "pod".
For example: 

Screen Shot 2021-02-10 at 5.14.07 PM.pngScreen Shot 2021-02-10 at 5.14.07 PM.png

I would like to get the same output as when I click on `Event Actions > Show Source` but only for the pod:
`cron-prod-campaignactivator-1612980360-49zss`.
How would look like my query? 

Thank you in advance,
Jeremy

Labels (1)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

your query would be

index=eks sourcetype=fluent pod=cron-prod-campaignactivator-1612980360-49zss
| table _raw

Is that what you want to see?

As far as Splunk tutorials go, have a look at Splunk fundamentals 1 free course

https://www.splunk.com/en_us/training/free-courses/splunk-fundamentals-1.html

 

jocteau
New Member

Hi Bowesmana!

when I try to run this query, I sadly don't get any results, should I run it in a different place?

Screen Shot 2021-02-11 at 1.30.32 PM.pngScreen Shot 2021-02-11 at 1.30.32 PM.png

 

0 Karma

bowesmana
SplunkTrust
SplunkTrust

@jocteau 

Your original post, and my reply show the index value as eks. Looks like you have a typo, as you have put

index=ek

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

All Work and No Play? Not at .conf26! Unwind at These Evening Events

Between hands-on technical sessions, keynote reveals, and diving into live architectures, .conf26 is packed ...

Join the Hackathon at .conf26 and build a No-Code AI agent

Join us for the AI Agent Buildathon, an in-person, three-hour hands-on Hackathon where you’ll use Splunk Agent ...