Log forwarded metadata keys to Splunk in RHOCP 4
Issue
- It's log forwarded the logs to Splunk and the name of the fields received is not the recommended by Splunk for the Event metadata
- When log forwarding to Splunk from the Red Hat Logging stack, the key
host
is not received in the Event metadata, instead, it's visible the keyhostname
- When log forwarding to Splunk from the Red Hat Logging stack, the key
source
is not received being the expected content in the Event metadata keyfile
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging (RHOL)
- 5
- Fluentd
- Vector
- Splunk
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.