-
Feature
-
Resolution: Unresolved
-
Normal
-
None
-
None
-
False
-
False
What is the problem that your customer is facing?
The customer needs to be able to split Service Mesh logs so that Errors are sent to SPLUNK and will be used for alerting. The errors sent to Splunk also need to have any PII data masking.
A copy of all logs is to be sent to Kafka which is then sent to MongoDB for access by the support teams.
The customer is currently building this using fluentD that we will run on OCP4 but would prefer to use the operator version.
What is the business impact, if any, if this request will not be made
available?
The customer is currently testing this functionality as they are building this with FluentD.
What are your expectations for this feature?
The customer would like the Log forwarding functionality in OCP4 to be uplifted to support regex for splitting files and masking file content as can be done with FluentD.
The customer would like support for SASL/GSSAPI to be included in the ClusterLogForward API to allow authentication to Kafka using Kerberos.
In simple words, As a requirement, the customer wants to filter the lines of text in logs before sending these logs to third-party systems such as Splunk.
They implemented similar functionality in OCP3 using fluentd filters but they cannot implement this feature in OCP4 and if they try to install a custom fluend agent then it could impact default platform logging.
Have you done this before and/or outside of support and if yes, how?
(Optional)
NA