Replies: 1 comment
-
By default, td-agent is customized to output to /var/log/td-agent.log, not journal log. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Could be specific to my hardening... When I block access to splunk, td-agent does recognize this and begins to placed [warn] messages in td-agent.log. I'd like to use journalctl (and the time bounding features) to report on the same log messages but those haven't been observed via journalctl for me. If some one could possibly confirm if it is the same for others, before I report an issue, please. To block splunk access I simply made a /etc/hosts entry for my splunk server set to 127.0.0.1 for a time....
Beta Was this translation helpful? Give feedback.
All reactions