Getting Data In

i am using openshift 4.16.32 and i used helm for splunk-otel-collector and i get this error in the pods

tawfiq15
New Member

2025-05-06T13:50:00.857Z error helper/transformer.go:118 Failed to process entry {"otelcol.component.id": "filelog", "otelcol.component.kind": "receiver", "otelcol.signal": "logs", "operator_id": "move", "operator_type": "move", "error": "move: field does not exist: attributes.uid", "action": "send", "entry.timestamp": "2025-05-06T13:49:09.153Z", "time": "2025-05-06T13:49:09.153467683+00:00", "log.file.path": "/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log", "stream": "stderr", "logtag": "F", "log": "2025-05-06T13:49:09.153Z\terror\thelper/transformer.go:118\tFailed to process entry\t{\"otelcol.component.id\": \"filelog\", \"otelcol.component.kind\": \"receiver\", \"otelcol.signal\": \"logs\", \"operator_id\": \"add\", \"operator_type\": \"add\", \"error\": \"evaluate value_expr: invalid operation: string + <nil> (1:18)\\n | \\\"kube:container:\\\"+resource[\\\"k8s.container.name\\\"]\\n | .................^\", \"action\": \"send\", \"entry.timestamp\": \"2025-05-06T13:48:59.854Z\", \"log.file.path\": \"/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log\", \"stream\": \"stderr\", \"logtag\": \"F\", \"log\": \"github.com/open-telemetry/opentelemetry-collector-contrib/pkg/stanza/operator/transformer/move.(*Transformer).Process\", \"time\": \"2025-05-06T13:48:59.854

Labels (2)
0 Karma

livehybrid
Super Champion

Hi @tawfiq15 

Are you able to share your helm chart so I can check over it and compare to the log, please?

Below is the formatted version of the log to make it easier to read:

timestamp: 2025-05-06T13:50:00.857Z
level: error
file: helper/transformer.go:118
message: Failed to process entry
fields:
  otelcol.component.id: "filelog"
  otelcol.component.kind: "receiver"
  otelcol.signal: "logs"
  operator_id: "move"
  operator_type: "move"
  error: "move: field does not exist: attributes.uid"
  action: "send"
  entry.timestamp: "2025-05-06T13:49:09.153Z"
  time: "2025-05-06T13:49:09.153467683+00:00"
  log.file.path: "/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log"
  stream: "stderr"
  logtag: "F"
  log: |
    2025-05-06T13:49:09.153Z error helper/transformer.go:118 Failed to process entry
    {
      "otelcol.component.id": "filelog",
      "otelcol.component.kind": "receiver",
      "otelcol.signal": "logs",
      "operator_id": "add",
      "operator_type": "add",
      "error": "evaluate value_expr: invalid operation: string + <nil> (1:18)\n | \"kube:container:\"+resource[\"k8s.container.name\"]\n | .................^",
      "action": "send",
      "entry.timestamp": "2025-05-06T13:48:59.854Z",
      "log.file.path": "/var/log/containers/splunk-otel-collector-agent-46r6g_openshift-logging_otel-collector-1eb5729e9591a5a6b6b3142b8cbbd754b24f8239fad4d2df28c268cf8158e61e.log",
      "stream": "stderr",
      "logtag": "F",
      "log": "github.com/open-telemetry/opentelemetry-collector-contrib/pkg/stanza/operator/transformer/move.(*Transformer).Process",
      "time": "2025-05-06T13:48:59.854
    }

 

Thanks

0 Karma
Get Updates on the Splunk Community!

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco &#43; Splunk! We’ve ...

Enterprise Security Content Update (ESCU) | New Releases

In April, the Splunk Threat Research Team had 2 releases of new security content via the Enterprise Security ...

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...
OSZAR »