diff --git a/helm-chart/splunk-connect-for-kubernetes/charts/splunk-kubernetes-logging/templates/configMap.yaml b/helm-chart/splunk-connect-for-kubernetes/charts/splunk-kubernetes-logging/templates/configMap.yaml index b20741bf..366f23ad 100644 --- a/helm-chart/splunk-connect-for-kubernetes/charts/splunk-kubernetes-logging/templates/configMap.yaml +++ b/helm-chart/splunk-connect-for-kubernetes/charts/splunk-kubernetes-logging/templates/configMap.yaml @@ -309,7 +309,7 @@ data: {{- if eq .Values.containers.logFormatType "cri" }} @type jq_transformer - jq '.record | . + (.source | capture("/var/log/pods/(?[^/]+)/(?[^/]+)/(?[0-9]+).log")) | .sourcetype = ("{{ .Values.sourcetypePrefix }}:container:" + .container_name) | .splunk_index = {{ or .Values.global.splunk.hec.indexName .Values.splunk.hec.indexName | default "main" | quote }}' + jq '.record | . + (.source | capture("/var/log/pods/(?[^/]+)/(?[^/]+)/(?[0-9]+).log"))' {{- end }}