Uploaded image for project: 'OpenShift Logging'
  1. OpenShift Logging
  2. LOG-6859

Splunk Event Metadata

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Unresolved
    • Icon: Normal Normal
    • Logging 6.3.0
    • None
    • Log Collection
    • None
    • Splunk Event Metadata
    • False
    • None
    • False
    • Not Selected
    • NEW
    • Administer, API, Release Notes
    • To Do
    • OBSDA-735 - Honor splunk Event metadata keys
    • OBSDA-735Honor splunk Event metadata keys
    • NEW
    • 100% To Do, 0% In Progress, 0% Done
    • Enhancement
    • S

      Goals

      • Use splunk metadata keys when forwarding
      • Define "default" values for the metadata keys when non are specified
      • Allow admins to specify metadata keys using established patterns for ClusterLogForwarder
         

        Non-Goals

      • Allowing user's to fully manipulate event payloads

      Motivation

      Splunk is a commonly used log aggregation service that has has a well defined API to make user of its feature set. Users wish to take full advantage of these features (e.g. optimized indexing, faster searching) but need the ClusterLogForwarder to expose additional configuration.

      Alternatives

      Acceptance Criteria

      • Verify the Collector sets the `host` when forwarding logs
      • Verify the ClusterLogForwarder API has fields that allows setting: `source`, `index_fields` using the ClusterLogForwarder templating
      • Verify the Collector sets `host`, `source`, `sourcetype` with Red Hat 'defaults' when not otherwise spec'd in the ClusterLogForwarder
      • Verify the Collector forwards logs with the desired data when the metadata fields are set in the API

      Risk and Assumptions

      Documentation Considerations

      • Update API docs
      • Document the default behavior when nothing is specified

      Open Questions

      Additional Notes

              Unassigned Unassigned
              jcantril@redhat.com Jeffrey Cantrill
              Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

                Created:
                Updated: