Sending logs to external logger with OpenShift metadata
Issue
- We have an internally hosted Splunk cluster that is used to aggregate and search through our application logs
- Trying to understand what the full capabilities are for getting my OpenShift-hosted application logs in Splunk, with high-fidelity metadata
- Logs are missing OpenShift context (pod name, deployment name, app name, etc.). Logs are being “packaged” up in a wrapper json object.
- Ideally our apps log message would be the only part of the event, and we could leverage the json syntax highlighting, search enhancements, etc.
Environment
- Red Hat OpenShift Container Platform
- 3.3, 3.4, 3.5, 3.6, 3.7, 3.9, 3.10
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.