Timestamp was not found warning in Collector Pods while forwarding logs to Splunk in RHOCP 4
Issue
Collectorpod repeatedly logstimestamprelated warnings for thesplunk_hec_logssink.-
The following warning messages appear in the
collectorpod logs when forwarding logs to aSplunk:YYYY-MM-DDTHH:MM:SS.XXXXXZ WARN sink{component_kind="sink" component_id=output_splunk_aosqe component_type=splunk_hec_logs}: vector::internal_events::splunk_hec::sink: Timestamp was not found. Deferring to Splunk to set the timestamp. internal_log_rate_limit=true YYYY-MM-DDTHH:MM:SS.XXXXXZ WARN sink{component_kind="sink" component_id=output_splunk_aosqe component_type=splunk_hec_logs}: vector::internal_events::splunk_hec::sink: Internal log [Timestamp was not found. Deferring to Splunk to set the timestamp.] is being suppressed to avoid flooding
Environment
- Red Hat OpenShift Container Platform (RHOCP)
- 4
- Red Hat OpenShift Logging (RHOL)
- 6.3.0
- Vector
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.