live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
guidePLATFORM

OpenShift Logging 6 changes the Splunk source contract after a 5.x upgrade

Teams that relied on a Splunk HEC token’s default source should validate searches, routing and retention before treating a Logging 6 migration as complete.

OpenShift Logging 6 changes Splunk source metadata after upgrade.
AI-generated illustration
By The News Desk· Sep 20, 2026the quick take — two AI hosts go live when you do

Red Hat has documented a migration edge case in which an upgrade from OpenShift Logging 5.x to 6.x changes the source values arriving at Splunk. The verified solution, updated Sept. 19, says events no longer inherit the default source configured on the Splunk HTTP Event Collector token. Instead, Splunk can show sources such as openshiftAPI, kubeAPI, or namespace_name_podName_containerName.

What changed

This is a metadata-contract change, not simply a forwarding outage. Events can continue reaching Splunk while landing under different source values. That distinction matters because saved searches, dashboards, alerts, role filters and retention rules may select data by source even when operators usually navigate by index or sourcetype.

Red Hat lists OpenShift Container Platform 4.16 and later with OpenShift Logging 6.x as the affected environment. Its public description also says that setting a static source containing a colon—http:my_source, for example—in ClusterLogForwarder fails schema validation. The remediation details are subscriber-only, so teams should not infer an escaping syntax from the rejected value.

What to validate

Before the migration, capture representative Splunk events from application, infrastructure and audit inputs. Record their index, sourcetype and source, then inventory any knowledge objects that filter on those fields. Include scheduled searches, alert rules, dashboards, data-model constraints and retention or routing configuration maintained outside OpenShift.

After moving to Logging 6, send a small known sample from each input class and compare the resulting metadata. A useful acceptance test proves both delivery and discoverability: the expected event count arrives, existing operational searches still find it, and downstream policies do not silently split one logical stream across new source names.

If a unified source is required, validate the intended ClusterLogForwarder value against the live API before rollout. A value rejected by admission will not become valid merely because Splunk accepts the same string.

Migration checklist

  1. Export the existing ClusterLogForwarder and Splunk HEC configuration.
  2. Inventory queries and policies that constrain source.
  3. Establish pre-upgrade event samples and counts for all three log classes.
  4. Upgrade a non-production path first and inspect the actual Splunk metadata.
  5. Update searches, dashboards and retention rules—or configure a supported static source—before production cutover.
  6. Keep the old and new queries side by side during the validation window.

The important control is to test metadata semantics, not only whether the HEC endpoint returns success.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.