|
9128 | 9128 | </span> |
9129 | 9129 | </a> |
9130 | 9130 |
|
9131 | | - <nav class="md-nav" aria-label="Issue: Unable to retrieve logs from non RFC-5424 compliant sources"> |
9132 | | - <ul class="md-nav__list"> |
9133 | | - |
9134 | | - <li class="md-nav__item"> |
9135 | | - <a href="#issue-terminal-is-overwhelmed-by-metrics-and-internal-processing-messages-in-a-custom-environment-configuration" class="md-nav__link"> |
9136 | | - <span class="md-ellipsis"> |
9137 | | - Issue: Terminal is overwhelmed by metrics and internal processing messages in a custom environment configuration |
9138 | | - </span> |
9139 | | - </a> |
9140 | | - |
9141 | | -</li> |
9142 | | - |
9143 | | - <li class="md-nav__item"> |
9144 | | - <a href="#issue-you-are-missing-cef-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9145 | | - <span class="md-ellipsis"> |
9146 | | - Issue: You are missing CEF logs that are not RFC compliant |
9147 | | - </span> |
9148 | | - </a> |
9149 | | - |
9150 | | -</li> |
9151 | | - |
9152 | | - <li class="md-nav__item"> |
9153 | | - <a href="#issue-you-are-missing-vmware-cb-protect-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9154 | | - <span class="md-ellipsis"> |
9155 | | - Issue: You are missing VMWARE CB-PROTECT logs that are not RFC compliant |
9156 | | - </span> |
9157 | | - </a> |
9158 | | - |
9159 | | -</li> |
9160 | | - |
9161 | | - <li class="md-nav__item"> |
9162 | | - <a href="#issue-you-are-missing-cisco-ios-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9163 | | - <span class="md-ellipsis"> |
9164 | | - Issue: You are missing CISCO IOS logs that are not RFC compliant |
9165 | | - </span> |
9166 | | - </a> |
9167 | | - |
9168 | | -</li> |
9169 | | - |
9170 | | - <li class="md-nav__item"> |
9171 | | - <a href="#issue-you-are-missing-vmware-vsphere-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9172 | | - <span class="md-ellipsis"> |
9173 | | - Issue: You are missing VMWARE VSPHERE logs that are not RFC compliant |
9174 | | - </span> |
9175 | | - </a> |
9176 | | - |
9177 | | -</li> |
9178 | | - |
9179 | | - <li class="md-nav__item"> |
9180 | | - <a href="#issue-you-are-missing-raw-bsd-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9181 | | - <span class="md-ellipsis"> |
9182 | | - Issue: You are missing RAW BSD logs that are not RFC compliant |
9183 | | - </span> |
9184 | | - </a> |
9185 | | - |
9186 | | -</li> |
9187 | | - |
9188 | | - <li class="md-nav__item"> |
9189 | | - <a href="#issue-you-are-missing-raw-xml-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9190 | | - <span class="md-ellipsis"> |
9191 | | - Issue: You are missing RAW XML logs that are not RFC compliant |
9192 | | - </span> |
9193 | | - </a> |
9194 | | - |
9195 | | -</li> |
9196 | | - |
9197 | | - <li class="md-nav__item"> |
9198 | | - <a href="#issue-you-are-missing-hpe-jetdirect-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9199 | | - <span class="md-ellipsis"> |
9200 | | - Issue: You are missing HPE JETDIRECT logs that are not RFC compliant |
9201 | | - </span> |
9202 | | - </a> |
9203 | | - |
9204 | | -</li> |
9205 | | - |
9206 | | - </ul> |
9207 | | - </nav> |
9208 | | - |
9209 | 9131 | </li> |
9210 | 9132 |
|
9211 | 9133 | </ul> |
|
9455 | 9377 | </span> |
9456 | 9378 | </a> |
9457 | 9379 |
|
9458 | | - <nav class="md-nav" aria-label="Issue: Unable to retrieve logs from non RFC-5424 compliant sources"> |
9459 | | - <ul class="md-nav__list"> |
9460 | | - |
9461 | | - <li class="md-nav__item"> |
9462 | | - <a href="#issue-terminal-is-overwhelmed-by-metrics-and-internal-processing-messages-in-a-custom-environment-configuration" class="md-nav__link"> |
9463 | | - <span class="md-ellipsis"> |
9464 | | - Issue: Terminal is overwhelmed by metrics and internal processing messages in a custom environment configuration |
9465 | | - </span> |
9466 | | - </a> |
9467 | | - |
9468 | | -</li> |
9469 | | - |
9470 | | - <li class="md-nav__item"> |
9471 | | - <a href="#issue-you-are-missing-cef-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9472 | | - <span class="md-ellipsis"> |
9473 | | - Issue: You are missing CEF logs that are not RFC compliant |
9474 | | - </span> |
9475 | | - </a> |
9476 | | - |
9477 | | -</li> |
9478 | | - |
9479 | | - <li class="md-nav__item"> |
9480 | | - <a href="#issue-you-are-missing-vmware-cb-protect-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9481 | | - <span class="md-ellipsis"> |
9482 | | - Issue: You are missing VMWARE CB-PROTECT logs that are not RFC compliant |
9483 | | - </span> |
9484 | | - </a> |
9485 | | - |
9486 | | -</li> |
9487 | | - |
9488 | | - <li class="md-nav__item"> |
9489 | | - <a href="#issue-you-are-missing-cisco-ios-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9490 | | - <span class="md-ellipsis"> |
9491 | | - Issue: You are missing CISCO IOS logs that are not RFC compliant |
9492 | | - </span> |
9493 | | - </a> |
9494 | | - |
9495 | | -</li> |
9496 | | - |
9497 | | - <li class="md-nav__item"> |
9498 | | - <a href="#issue-you-are-missing-vmware-vsphere-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9499 | | - <span class="md-ellipsis"> |
9500 | | - Issue: You are missing VMWARE VSPHERE logs that are not RFC compliant |
9501 | | - </span> |
9502 | | - </a> |
9503 | | - |
9504 | | -</li> |
9505 | | - |
9506 | | - <li class="md-nav__item"> |
9507 | | - <a href="#issue-you-are-missing-raw-bsd-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9508 | | - <span class="md-ellipsis"> |
9509 | | - Issue: You are missing RAW BSD logs that are not RFC compliant |
9510 | | - </span> |
9511 | | - </a> |
9512 | | - |
9513 | | -</li> |
9514 | | - |
9515 | | - <li class="md-nav__item"> |
9516 | | - <a href="#issue-you-are-missing-raw-xml-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9517 | | - <span class="md-ellipsis"> |
9518 | | - Issue: You are missing RAW XML logs that are not RFC compliant |
9519 | | - </span> |
9520 | | - </a> |
9521 | | - |
9522 | | -</li> |
9523 | | - |
9524 | | - <li class="md-nav__item"> |
9525 | | - <a href="#issue-you-are-missing-hpe-jetdirect-logs-that-are-not-rfc-compliant" class="md-nav__link"> |
9526 | | - <span class="md-ellipsis"> |
9527 | | - Issue: You are missing HPE JETDIRECT logs that are not RFC compliant |
9528 | | - </span> |
9529 | | - </a> |
9530 | | - |
9531 | | -</li> |
9532 | | - |
9533 | | - </ul> |
9534 | | - </nav> |
9535 | | - |
9536 | 9380 | </li> |
9537 | 9381 |
|
9538 | 9382 | </ul> |
@@ -9662,91 +9506,7 @@ <h2 id="issue-unable-to-retrieve-logs-from-non-rfc-5424-compliant-sources">Issue |
9662 | 9506 | PROGRAM: syslog-ng |
9663 | 9507 | } |
9664 | 9508 | </code></pre></div> |
9665 | | -<p>In this example the error can be seen in the snippet <code>statefulset.kubernetes.io/pod-n>@<ame</code>. The error states that the “SD-NAME” (the left-hand side of the name=value pairs) cannot be longer than 32 printable ASCII characters, and the indicated name exceeds that. Ideally you should address this issue with the vendor, however, you can add an exception to the SC4S filter log path or an alternative workaround log path created for the data source.</p> |
9666 | | -<p>In this example, the reason <code>RAWMSG</code> is not shown in the fields above is because this error message is coming from syslog-ng itself. In messages of the type <code>Error processing log message:</code> where the PROGRAM is shown as <code>syslog-ng</code>, your incoming message is not RFC-5424 compliant.</p> |
9667 | | -<h3 id="issue-terminal-is-overwhelmed-by-metrics-and-internal-processing-messages-in-a-custom-environment-configuration">Issue: Terminal is overwhelmed by metrics and internal processing messages in a custom environment configuration<a class="headerlink" href="#issue-terminal-is-overwhelmed-by-metrics-and-internal-processing-messages-in-a-custom-environment-configuration" title="Permanent link">¶</a></h3> |
9668 | | -<p>In non-containerized SC4S deployments, if you try to start the SC4S service, the terminal may be overwhelmed by the internal and metrics logs. Example of the issue can be found here: <a href="https://github.com/splunk/splunk-connect-for-syslog/issues/1954">Github Terminal abuse issue</a></p> |
9669 | | -<p>To resolve this, set following property in <code>env_file</code>: |
9670 | | -<div class="highlight"><pre><span></span><code>SC4S_SEND_METRICS_TERMINAL=no |
9671 | | -</code></pre></div></p> |
9672 | | -<p>Restart SC4S. </p> |
9673 | | -<ul> |
9674 | | -<li>NOTE: This symptom will recur if <code>SC4S_DEBUG_CONTAINER</code> is set to “yes”. Use the CLI <code>podman</code> or <code>docker</code> commands directly to start/stop SC4S.</li> |
9675 | | -</ul> |
9676 | | -<h3 id="issue-you-are-missing-cef-logs-that-are-not-rfc-compliant">Issue: You are missing CEF logs that are not RFC compliant<a class="headerlink" href="#issue-you-are-missing-cef-logs-that-are-not-rfc-compliant" title="Permanent link">¶</a></h3> |
9677 | | -<ol> |
9678 | | -<li> |
9679 | | -<p>To resolve this, set following property in <code>env_file</code>: |
9680 | | -<div class="highlight"><pre><span></span><code>SC4S_DISABLE_DROP_INVALID_CEF=yes |
9681 | | -</code></pre></div></p> |
9682 | | -</li> |
9683 | | -<li> |
9684 | | -<p>Restart SC4S.</p> |
9685 | | -</li> |
9686 | | -</ol> |
9687 | | -<h3 id="issue-you-are-missing-vmware-cb-protect-logs-that-are-not-rfc-compliant">Issue: You are missing VMWARE CB-PROTECT logs that are not RFC compliant<a class="headerlink" href="#issue-you-are-missing-vmware-cb-protect-logs-that-are-not-rfc-compliant" title="Permanent link">¶</a></h3> |
9688 | | -<ol> |
9689 | | -<li> |
9690 | | -<p>To resolve this, set following property in <code>env_file</code>: |
9691 | | -<div class="highlight"><pre><span></span><code>SC4S_DISABLE_DROP_INVALID_VMWARE_CB_PROTECT=yes |
9692 | | -</code></pre></div></p> |
9693 | | -</li> |
9694 | | -<li> |
9695 | | -<p>Restart SC4S.</p> |
9696 | | -</li> |
9697 | | -</ol> |
9698 | | -<h3 id="issue-you-are-missing-cisco-ios-logs-that-are-not-rfc-compliant">Issue: You are missing CISCO IOS logs that are not RFC compliant<a class="headerlink" href="#issue-you-are-missing-cisco-ios-logs-that-are-not-rfc-compliant" title="Permanent link">¶</a></h3> |
9699 | | -<ol> |
9700 | | -<li>To resolve this, set following property in <code>env_file</code>: |
9701 | | -<div class="highlight"><pre><span></span><code>SC4S_DISABLE_DROP_INVALID_CISCO=yes |
9702 | | -</code></pre></div></li> |
9703 | | -<li>Restart SC4S.</li> |
9704 | | -</ol> |
9705 | | -<h3 id="issue-you-are-missing-vmware-vsphere-logs-that-are-not-rfc-compliant">Issue: You are missing VMWARE VSPHERE logs that are not RFC compliant<a class="headerlink" href="#issue-you-are-missing-vmware-vsphere-logs-that-are-not-rfc-compliant" title="Permanent link">¶</a></h3> |
9706 | | -<ol> |
9707 | | -<li> |
9708 | | -<p>To resolve this, set following property in <code>env_file</code>: |
9709 | | -<div class="highlight"><pre><span></span><code>SC4S_DISABLE_DROP_INVALID_VMWARE_VSPHERE=yes |
9710 | | -</code></pre></div></p> |
9711 | | -</li> |
9712 | | -<li> |
9713 | | -<p>Restart SC4S.</p> |
9714 | | -</li> |
9715 | | -</ol> |
9716 | | -<h3 id="issue-you-are-missing-raw-bsd-logs-that-are-not-rfc-compliant">Issue: You are missing RAW BSD logs that are not RFC compliant<a class="headerlink" href="#issue-you-are-missing-raw-bsd-logs-that-are-not-rfc-compliant" title="Permanent link">¶</a></h3> |
9717 | | -<ol> |
9718 | | -<li> |
9719 | | -<p>To resolve this, set following property in <code>env_file</code>: |
9720 | | -<div class="highlight"><pre><span></span><code>SC4S_DISABLE_DROP_INVALID_RAW_BSD=yes |
9721 | | -</code></pre></div></p> |
9722 | | -</li> |
9723 | | -<li> |
9724 | | -<p>Restart SC4S.</p> |
9725 | | -</li> |
9726 | | -</ol> |
9727 | | -<h3 id="issue-you-are-missing-raw-xml-logs-that-are-not-rfc-compliant">Issue: You are missing RAW XML logs that are not RFC compliant<a class="headerlink" href="#issue-you-are-missing-raw-xml-logs-that-are-not-rfc-compliant" title="Permanent link">¶</a></h3> |
9728 | | -<ol> |
9729 | | -<li> |
9730 | | -<p>To resolve this, set following property in <code>env_file</code>: |
9731 | | -<div class="highlight"><pre><span></span><code>SC4S_DISABLE_DROP_INVALID_XML=yes |
9732 | | -</code></pre></div></p> |
9733 | | -</li> |
9734 | | -<li> |
9735 | | -<p>Restart SC4S.</p> |
9736 | | -</li> |
9737 | | -</ol> |
9738 | | -<h3 id="issue-you-are-missing-hpe-jetdirect-logs-that-are-not-rfc-compliant">Issue: You are missing HPE JETDIRECT logs that are not RFC compliant<a class="headerlink" href="#issue-you-are-missing-hpe-jetdirect-logs-that-are-not-rfc-compliant" title="Permanent link">¶</a></h3> |
9739 | | -<ol> |
9740 | | -<li> |
9741 | | -<p>To resolve this, set following property in <code>env_file</code>: |
9742 | | -<div class="highlight"><pre><span></span><code>SC4S_DISABLE_DROP_INVALID_HPE=yes |
9743 | | -</code></pre></div></p> |
9744 | | -</li> |
9745 | | -<li> |
9746 | | -<p>Restart SC4S and it will not drop any invalid HPE JETDIRECT format.</p> |
9747 | | -</li> |
9748 | | -</ol> |
9749 | | -<p>NOTE: Please use only in this case of exception and this is splunk-unsupported feature. Also this setting might impact SC4S performance.</p> |
| 9509 | +<p>In this example the error can be seen in the snippet `statefulset.kubernetes.io/pod-n>@</p> |
9750 | 9510 |
|
9751 | 9511 |
|
9752 | 9512 |
|
|
0 commit comments