coreos / bugs

Issue tracker for CoreOS Container Linux
https://coreos.com/os/eol/
146 stars 30 forks source link

How can I forward /var/log/journal/* logs using Splunk universal forwarder #2641

Closed alpana17 closed 4 years ago

alpana17 commented 4 years ago

My inputs.conf at /opt/splunkforwarder/etc/system/local/inputs.conf looks like [monitor:///var/log/journal/dcf370a7752c4b14b6f7be387fabdf5f/system.journal] _TCP_ROUTING = IHF-ext_encrypted ignoreOlderThan = 7d index = os disabled = 0 sourcetype = syslog

But I can not see logs in splunk

ajeddeloh commented 4 years ago

We don't know about splunk, as it's not part of the OS; this isn't an OS bug. I recommend asking splunk.