Splunk-connect-for-kubernetes: Allow concat to be set by annotations

Created on 21 May 2020  路  4Comments  路  Source: splunk/splunk-connect-for-kubernetes

What would you like to be added:

Allow concat multiline regex settings and separator to be set by annotations. (firstline, lastline etc)

Why is this needed:

This would provide value and best fit the cloud native deployment and management model our customers want to use.

Users tend to turn on SCK then iterate over their key sourcetypes, updating the values and redeploying. This would allow data parsing rules to be easy to add and manage right from the k8s command line or build pipe, without the need for redeploy of the chart to add new rules to achieve beauty stacktraces and multiline logs.

enhancement good first issue

Most helpful comment

This will be key for my customer as they seek to move as much of the logging ops as possible out to the edge (developer). Multi-line logging is a huge requirement for them.

All 4 comments

This will be key for my customer as they seek to move as much of the logging ops as possible out to the edge (developer). Multi-line logging is a huge requirement for them.

This would be awesome for self service for our customers.

Thanks Matt, This will be very useful to control from Kubernetes artifacts.

I am aware that this would be a very nice feature, so i have looked into this, but it is not possible with currently existing fluentd plugins. just sharing information.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

matthewmodestino picture matthewmodestino  路  4Comments

stiller-leser picture stiller-leser  路  8Comments

MarkPare picture MarkPare  路  3Comments

aakashbhalla1 picture aakashbhalla1  路  6Comments

nisc-acooper picture nisc-acooper  路  10Comments