docker-logging-plugin icon indicating copy to clipboard operation
docker-logging-plugin copied to clipboard

Support Fields

Open sylvanaar opened this issue 5 years ago • 3 comments

HEC supports passing additional fields that are not directly part of the event data. This is useful for example to provide additional metadata about the events beyond just the sourcename.

https://docs.splunk.com/Documentation/Splunk/7.2.1/Data/IFXandHEC

sylvanaar avatar Dec 19 '18 16:12 sylvanaar

Agreed - we'll look to add this functionality

dtregonning avatar Apr 12 '19 20:04 dtregonning

Meta-Data support for Docker - assigning to self

dtregonning avatar Aug 20 '19 17:08 dtregonning

Hi @dtregonning This feature would meet our use case perfectly. We want to be able to specify the Splunk index from within the application logs, and unfortunately there is no simple way of doing this with the current version of the Splunk docker logging driver. I note this issue has been open for 3 years, I'm surprised there isn't more interest. Do you know if there is a plan to include this at all? Thanks

stephenwood4-nhs avatar Aug 04 '22 16:08 stephenwood4-nhs