Closed amweiss closed 2 years ago
@amweiss Thanks for bringing this to our attention.
Can you clarify what you mean by "infrastructure logs"? Are they the same log messages from your application as the ones seen in Splunk, just in a different view in New Relic?
Sorry, it used to be called that I think. It's the "logger" url of New Relic One from the fluentd log shipper: https://docs.newrelic.com/docs/logs/forward-logs/fluentd-plugin-log-forwarding
Yep, it's the exact same log lines in splunk and new relic (I guess I should have not redacted the whole thing 🙃) trace id and all, they are just no longer connected to APM like they were before for logs-in-context when we used the enricher and formatter.
@amweiss Thanks for clarifying. At this point I think it would be better to work this issue through our support ticketing system (please reference this GH issue when creating the ticket though). I'm not sure at this point whether the issue is with how our agent is sending the data, or with how the UI/backend is trying to find your logs for that APM logs view. (One of the reasons why it will be better to work this through support is that we will need to be able to see the account-specific data which you are quite understandably hiding in your screenshots in order to answer this question.)
I'll close this issue once the support ticket has been created.
@nr-ahemsath Case #00036857 created.
We have an existing log shipping setup and tried to use the new log decorating (the old serilog enricher worked fine as well). However, now the logs aren't linked in APM even though they show up in the infrastructure logs.
Description Splunk log:
Infrastructure logs:
APM logs:
Serilog formatter changed from:
NewRelic.LogEnrichers.Serilog.NewRelicFormatter, NewRelic.LogEnrichers.Serilog
toSerilog.Formatting.Json.JsonFormatter, Serilog
withrenderMessage=true
andlocalDecorating enabled="true"
set in the config.If you need diagnostic logs, I'll send them though a support ticket.