Universal splunk forwarder as sidecar not showing internal splunk logs

Started by hemanth674, July 03, 2024, 03:39:40 AM

Previous topic - Next topic


I have implemented a sidecar container to forward my main application logs to splunk. Have used universalsplunkforwarder image. After I deploy both my main application and forwarder seems up and running. But anyway not recieving any logs in splunk index specified. To troubleshoot splunkd log or any specific splunk internal logs are not found in /var/log path. Can someone please help how we enable this splunk internal logs?


Splunk Universal Forwarder configuration:
Ensure that the Splunk Universal Forwarder is correctly configured to forward logs to the desired Splunk instance.