Logs no longer visible in EFK after configuring secure forwarder

Solution Verified - Updated -

Issue

  • The cluster is configured as fluentd will send openshift logs to an external splunk instance based on this page
  • The logs are visible in splunk but no longer the logs are seen in the kibana portal or searchable in EFK.
  • The cluster should have logs available in both splunk and EFK, how could this be achieved?

Environment

  • Openshift Container Platform
    • v3.6+

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content