signalfx/splunk-otel-collector-chart

Exclude events from k8sObjects inside clusterReceiver

ProboticsX opened this issue · 3 comments

Describe the issue you're reporting

Hi,

I needed to know if there's any way to exclude a certain type of events to be sent to Splunk?
For eg: I want to exclude logs with k8s.event.reason=PolicyViolation or k8s.event.reason=PolicyApplied to be sent to Splunk, so how should I modify the values.yaml file?

This is how the values file currently looks like:

clusterReceiver:
  eventsEnabled: true
  k8sObjects:
    - name: events
      mode: watch
      group: events.k8s.io

Hey, currently there's not such option - full documentation of the receiver is HERE.
However, I think you can experiment with the pipelines to filter and drop events with k8s.event.reason=PolicyApplied? This is one of the possible solutions.

Alright, I'll take a look at it. Thanks!

This issue has been inactive for 60 days. It will be closed in 60 days if there is no activity. If this issue is still relevant, please leave a comment explaining why it is still relevant. Otherwise, please close it.