New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fields column in Splunk Hec output plugin is not working . #505
Comments
@ahma and @saiinuganti - Is this issue resolved? I'm facing a similar issue except I don't have any filtering enabled. Thanks in advance. Error Msg: |
Describe the bug:
fields column in Splunk Hec output plugin is not converting as per fluentd spec in fluentd.conf in secret file
Expected behaviour:
expected config in fluentd.conf ( in secrets)
what i get is
fields {"dummy":" "}
so logging operator cannot separate dummy from original message to an indexed field.
Steps to reproduce the bug:
Additional context:
the main idea is to separate dummy from the original message to an indexed field in Splunk. But when using above config there is no change in the original message. but when I edited secrets to change fluentd.conf to
instead of fields {"dummy":" "} then I could see the change in my Splunk output . So I doubt that Splunk output plugin in logging operator is not writing the correct format to underlying fluentd.conf
Environment details:
/kind bug
The text was updated successfully, but these errors were encountered: