Currently, we are using Splunk universal forwarder where following parameters are set in props.conf:
props.conf
[json]
TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3NZ
TIME_PREFIX = \"time\"\:\"
INDEXED_EXTRACTIONS = JSON
SHOULD_LINEMERGE = false
I am working on using docker swarm as our infrastructure orchestration platform and started using docker splunk-log driver with it. I am not able to find proper log-options to be used with driver using which I can achieve similar effect as was achieved by using above props.conf file with Splunk universal forwarder. How can I set above props.conf options with docker log driver?
Thanks,
Navdeep
↧