Configuring Splunk Vector to Use Application Timestamps for Log Forwarding in OpenShift Container Platform
Issue
- Experiencing difficulties with serialising
applicationevents when forwarding logs tosplunk. - Desire to utilise the
timestampproduced by theapplicationinstead of the one added by thelogging operatorfor better event ordering.
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging Operator (RHOL)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.