-
Notifications
You must be signed in to change notification settings - Fork 185
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Splunk Universal Forwarder trying to setup HEC #763
Comments
I have also been faicing the same issue for a while now on all 9.x version of image. 8.2.x works fine. Can someone please look into this. Its really proving difficult. I faced similar issues in July too splunk/docker-splunk#557 I am using the image in K8s so i always trigger failures whenever i try to mount custom configs via configMap. Someone please help. I have support case open but that's giving little traction. Will update this issue if theres a breakthrough there. ConfigMap apiVersion: v1
data:
inputs.conf: |
# watch all files in <path>
[monitor:///var/log/containers/app*.log]
sourcetype = changeme1
index = changeme
kind: ConfigMap
metadata:
namespace: dev
name: splunk-configs
labels:
app: splunk-forwarder
component: agent Daemonset Manifest ....
volumeMounts:
- mountPath: "/opt/splunkforwarder/etc/apps/data/local/inputs.conf"
subPath: inputs.conf
readOnly: false
name: splunk-forwarder-config
...
volumes:
- name: splunk-forwarder-config
configMap:
name: splunk-configs
|
thanks for reporting. looking into the issue @PA7R14RCH @Iammusa18 |
Hello @PA7R14RCH @lachmatt, may I ask if this issue still happens? And if possible, could you provide steps for reproducing it? |
Attempting to install a universal forwarder on a host and it continues to fail on task [splunk_universal_forwarder : Setup global HEC]
According to Splunk, Universal Forwarders are not setup for HEC for input/output
Splunk Community
Splunk Doc
Is there a chance we could add a conditional to that HEC task if it does need to be there and allow for flush handlers afterwards? I tested removing the task itself and was successful running the universal forwarder container. It took a bit more finesse to get the handlers to run, but I think it's because I don't understand the code enough. Again, I reserve the right to be completely wrong.
Thoughts, Comments, Jokes?
The text was updated successfully, but these errors were encountered: