Uploaded image for project: 'OpenShift Logging'
  1. OpenShift Logging
  2. LOG-7026

Honor splunk Event metadata keys

XMLWordPrintable

    • Icon: Epic Epic
    • Resolution: Duplicate
    • Icon: Normal Normal
    • None
    • None
    • None
    • None
    • TBD
    • Future Sustainability
    • False
    • Hide

      None

      Show
      None
    • False
    • Not Selected
    • NEW
    • To Do
    • NEW

      Proposed title of this feature request

      Honor Splunk Event metadata key names

      What is the nature and description of the request?

      Currently, it's not honored the Splunk Event metadata key names where some keys are optional as: "time", "host", "source", "sourcetype", "index", "fields".

      But, for example, instead of the "host" key, it's received "hostname" key and similar situation is observed that the "source" key is not present being used a different key.

      Why does the customer need this? (List the business requirements)

      1.Receiving the keys as Splunk is expecting as per Splunk Event metadata

      2.Having normalized below the same keys from different log sources, not only OpenShift clusters the logs for managing them later: filtering/reporting in an easier way

      List any affected packages or components.

      Collectors: Vector - Fluentd

              Unassigned Unassigned
              rhn-support-ocasalsa Oscar Casal Sanchez
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: