Syslog (QRadar)

Collectord configuration for Kubernetes

Download

collectorforkubernetes-syslog.yaml

CURL

bash
1curl -O https://www.outcoldsolutions.com/docs/syslog-kubernetes/collectorforkubernetes-syslog.yaml

WGET

bash
1wget https://www.outcoldsolutions.com/docs/syslog-kubernetes/collectorforkubernetes-syslog.yaml

collectorforkubernetes-syslog.yaml

   1apiVersion: v1
   2kind: Namespace
   3metadata:
   4  labels:
   5    app: collectorforkubernetes-syslog
   6  name: collectorforkubernetes-syslog
   7---
   8apiVersion: apiextensions.k8s.io/v1beta1
   9kind: CustomResourceDefinition
  10metadata:
  11  name: configurations.collectord.io
  12spec:
  13  group: collectord.io
  14  versions:
  15    - name: v1
  16      served: true
  17      storage: true
  18  scope: Cluster
  19  names:
  20    plural: configurations
  21    singular: configuration
  22    kind: Configuration
  23---
  24apiVersion: v1
  25kind: ServiceAccount
  26metadata:
  27  labels:
  28    app: collectorforkubernetes-syslog
  29  name: collectorforkubernetes-syslog
  30  namespace: collectorforkubernetes-syslog
  31---
  32apiVersion: scheduling.k8s.io/v1
  33kind: PriorityClass
  34metadata:
  35  name: collectorforkubernetes-syslog-critical
  36value: 1000000000
  37---
  38apiVersion: rbac.authorization.k8s.io/v1
  39kind: ClusterRole
  40metadata:
  41  labels:
  42    app: collectorforkubernetes-syslog
  43  name: collectorforkubernetes-syslog
  44rules:
  45- apiGroups: ['extensions']
  46  resources: ['podsecuritypolicies']
  47  verbs:     ['use']
  48  resourceNames:
  49  - privileged
  50- apiGroups:
  51  - '*'
  52  resources:
  53  - '*'
  54  verbs:
  55  - get
  56  - list
  57  - watch
  58---
  59apiVersion: rbac.authorization.k8s.io/v1
  60kind: ClusterRoleBinding
  61metadata:
  62  labels:
  63    app: collectorforkubernetes-syslog
  64  name: collectorforkubernetes-syslog
  65  namespace: collectorforkubernetes-syslog
  66roleRef:
  67  apiGroup: rbac.authorization.k8s.io
  68  kind: ClusterRole
  69  name: collectorforkubernetes-syslog
  70subjects:
  71  - kind: ServiceAccount
  72    name: collectorforkubernetes-syslog
  73    namespace: collectorforkubernetes-syslog
  74---
  75apiVersion: v1
  76kind: ConfigMap
  77metadata:
  78  name: collectorforkubernetes-syslog
  79  namespace: collectorforkubernetes-syslog
  80  labels:
  81    app: collectorforkubernetes-syslog
  82data:
  83  001-general.conf: |
  84    # The general configuration is used for all deployments
  85    #
  86    # Run collectord with the flag -conf and specify location of the configuration files.
  87    #
  88    # You can override all the values using environment variables with the format like
  89    #   COLLECTOR__<ANYNAME>=<section>__<key>=<value>
  90    # As an example you can set dataPath in [general] section as
  91    #   COLLECTOR__DATAPATH=general__dataPath=C:\\some\\path\\data.db
  92    # This parameter can be configured using -env-override, set it to empty string to disable this feature
  93
  94    [general]
  95
  96    # Review License https://www.outcoldsolutions.com/legal/license-agreement/
  97    # and accept License by changing the value to *true*
  98    acceptLicense = false
  99
 100    # Location for the database
 101    # Collectord stores positions of the files and internal state
 102    dataPath = ./data/
 103
 104    # log level (accepted values are trace, debug, info, warn, error, fatal)
 105    logLevel = info
 106
 107    # http server gives access to two endpoints
 108    # /healthz
 109    # /metrics
 110    httpServerBinding =
 111
 112    # telemetry report endpoint, set it to empty string to disable telemetry
 113    telemetryEndpoint = https://license.outcold.solutions/telemetry/
 114
 115    # license check endpoint
 116    licenseEndpoint = https://license.outcold.solutions/license/
 117
 118    # license server through proxy
 119    licenseServerProxyUrl =
 120
 121    # authentication with basic authorization (user:password)
 122    licenseServerProxyBasicAuth =
 123
 124    # license key
 125    license =
 126
 127    # Environment variable $KUBERNETES_NODENAME is used by default to setup hostname
 128    # Use value below to override specific name
 129    hostname =
 130
 131    # Default output for events, logs and metrics
 132    # valid values: syslog and devnull
 133    # Use devnull by default if you don't want to redirect data
 134    defaultOutput = syslog
 135
 136    # Buffer size for file reads. 8k matches the common filesystem block size and
 137    # cuts the number of read syscalls substantially versus the historical 256b.
 138    fileInputBufferSize = 8k
 139
 140    # Maximum size of one line the file reader can read
 141    fileInputLineMaxSize = 1mb
 142
 143    # Include custom fields to attach to every event, in example below every event sent to Syslog will have
 144    # indexed field my_environment=dev. Fields names should match to ^[a-z][_a-z0-9]*$
 145    # Better way to configure that is to specify labels for Kubernetes Nodes.
 146    # ; fields.my_environment = dev
 147    # Identify the cluster if you are planning to monitor multiple clusters
 148    fields.cluster = -
 149
 150    # Include EC2 Metadata (see list of possible fields https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html)
 151    # Should be in format ec2Metadata.{desired_field_name} = {url path to read the value}
 152    # ec2Metadata.ec2_instance_id = /latest/meta-data/instance-id
 153    # ec2Metadata.ec2_instance_type = /latest/meta-data/instance-type
 154
 155    # subdomain for the annotations added to the pods, workloads, namespaces or containers, like syslog.collectord.io/..
 156    annotationsSubdomain = syslog
 157
 158    # Configure acknowledgement database.
 159    # - force fsync on every write to Write-Ahead-Log
 160    db.fsync = false
 161    # - maximum size of the Write-Ahead-Log
 162    db.compactAt = 1M
 163
 164    # configure global thruput per second for forwarded logs (metrics are not included)
 165    # for example if you set `thruputPerSecond = 512Kb`, that will limit amount of logs forwarded
 166    # from the single Collectord instance to 512Kb per second.
 167    # You can configure thruput individually for the logs (including specific for container logs) below
 168    thruputPerSecond =
 169
 170    # Configure events that are too old to be forwarded, for example 168h (7 days) - that will drop all events
 171    # older than 7 days
 172    tooOldEvents =
 173
 174    # Configure events that are too new to be forwarded, for example 1h - that will drop all events that are 1h in future
 175    tooNewEvents =
 176    
 177    # Multi-output async publishing. When enabled (default), events routed to
 178    # non-default outputs are published asynchronously so that a slow or down
 179    # output does not block events destined for other outputs.
 180    ; multioutput.async = true
 181    # Buffer size for the async proxy (default 100). Absorbs transient bursts.
 182    # When this buffer and the output's own queue are both full, events are
 183    # dropped immediately without blocking the pipeline.
 184    ; multioutput.asyncBufferSize = 100
 185
 186    # connection to kubernetes api
 187    [general.kubernetes]
 188
 189    # Environment variable $KUBERNETES_NODENAME is used by default to setup nodeName
 190    # Use it only when you need to override it
 191    nodeName =
 192
 193    # Configuration to access the API server,
 194    # see https://kubernetes.io/docs/tasks/access-application-cluster/access-cluster/#accessing-the-api-from-a-pod
 195    # for details
 196    tokenPath = /var/run/secrets/kubernetes.io/serviceaccount/token
 197    certPath = /var/run/secrets/kubernetes.io/serviceaccount/ca.crt
 198
 199    # Default timeout for http responses. The streaming/watch requests depend on this timeout.
 200    timeout = 30m
 201
 202    # (obsolete) In case if pod metadata was not retrievied. how often collectord should retry to reload the pod metadata
 203    # metadataFetchRetry = 5s
 204
 205    # (obsolete) In case if event is recent, how long pipeline should wait for the metadata to be available in Kubernetes API
 206    # metadataFetchWait = 30s
 207
 208    # How long to keep the cache for the recent calls to API server (to limit number of calls when collectord discovers new pods)
 209    metadataTTL = 30s
 210
 211    # regex to find pods
 212    podsCgroupFilter = ^/([^/\s]+/)*kubepods(\.slice)?/((kubepods-)?(burstable|besteffort)(\.slice)?/)?([^/]*)pod([0-9a-f]{32}|[0-9a-f\-_]{36})(\.slice)?$
 213
 214    # regex to find containers in the pods
 215    containersCgroupFilter = ^/([^/\s]+/)*kubepods(\.slice)?/((kubepods-)?(burstable|besteffort)(\.slice)?/)?([^/]*)pod([0-9a-f]{32}|[0-9a-f\-_]{36})(\.slice)?/(docker-|crio-)?[0-9a-f]{64}(\.scope)?(\/.+)?$
 216
 217    # path to the kubelet root location (use it to discover application logs for emptyDir)
 218    # the expected format is `pods/{pod-id}/volumes/kubernetes.io~empty-dir/{volume-name}/_data/`
 219    volumesRootDir = /rootfs/var/lib/kubelet/
 220
 221    # You can attach annotations as a metadata, using the format
 222    #   includeAnnotations.{key} = {regexp}
 223    # For example if you want to include all annotations that starts with `prometheus.io` or `example.com` you can include
 224    # the following format:
 225    #   includeAnnotations.1 = ^prometheus\.io.*
 226    #   includeAnnotations.2 = ^example\.com.*
 227
 228    # watch for changes (annotations) in the objects
 229    watch.namespaces = v1/namespace
 230    watch.deployments = apps/v1/deployment
 231    watch.configurations = apis/v1/collectord.io/configuration
 232
 233
 234    # Syslog output
 235    [output.syslog]
 236
 237    # tcp or udp
 238    network = tcp
 239    # syslog destination
 240    address =
 241
 242  002-daemonset.conf: |
 243    # DaemonSet configuration is used for Nodes and Masters.
 244
 245    # Connection to the docker host
 246    [general.docker]
 247
 248    # url for docker API, only unix socket is supported
 249    url = unix:///rootfs/var/run/docker.sock
 250
 251    # path to docker root folder (can fallback to use folder structure to read docker metadata)
 252    dockerRootFolder = /rootfs/var/lib/docker/
 253
 254    # (obsolete) In case if pod metadata was not retrievied. how often collectord should retry to reload the pod metadata
 255    # metadataFetchRetry = 5s
 256
 257    # (obsolete) In case if event is recent, how long pipeline should wait for the metadata to be available in Kubernetes API
 258    # metadataFetchWait = 30s
 259
 260    # (obsolete) In case if collectord does not see new events for specific container and with the last metadata refresh
 261    # We have not found this container - fow how long we should keep this metadata in cache.
 262    # metadataTTL = 5s
 263
 264    # Timeout for http responses to docker client. The streaming requests depend on this timeout.
 265    timeout = 1m
 266
 267    # in case of Kubernetes/OpenShift if you schedule some containers with Docker, but not with the Kubernetes
 268    # that allows us to find them (by default finding all containers with name not starting with k8s_)
 269    containersNameFilter = ^(([^k])|(k[^8])|(k8[^s])|(k8s[^_])).*$
 270
 271    # regex to find docker container cgroups (helps excluding other cgroups with matched ID)
 272    containersCgroupFilter = ^(/([^/\s]+/)*(docker-|docker/)[0-9a-f]{64}(\.scope)?)$
 273
 274
 275    // connection to CRIO
 276    [general.cri-o]
 277
 278    # url for CRIO API, only unix socket is supported
 279    url = unix:///rootfs/var/run/crio/crio.sock
 280
 281    # Timeout for http responses to docker client. The streaming requests depend on this timeout.
 282    timeout = 1m
 283
 284
 285    [general.containerd]
 286
 287    runtimePath = /rootfs/var/run/containerd
 288    namespace = k8s.io
 289
 290
 291    # Container Log files
 292    [input.files]
 293
 294    # disable container logs monitoring
 295    disabled = false
 296
 297    # root location of docker log files
 298    # logs are expected in standard docker format like {containerID}/{containerID}-json.log
 299    # rotated files
 300    path = /rootfs/var/lib/docker/containers/
 301    # root location of CRI-O files
 302    # logs are expected in Kubernetes format, like {podID}/{containerName}/0.log
 303    crioPath = /rootfs/var/log/pods/
 304
 305    # (obsolete) glob matching pattern for log files
 306    # glob = */*-json.log*
 307
 308    # files are read using polling schema, when reach the EOF how often to check if files got updated
 309    pollingInterval = 250ms
 310
 311    # how often to look for the new files under logs path
 312    walkingInterval = 5s
 313
 314    # include verbose fields in events (file offset)
 315    verboseFields = false
 316
 317    # docker splits events when they are larger than 10-100k (depends on the docker version)
 318    # we join them together by default and forward to Syslog as one event
 319    joinPartialEvents = true
 320
 321    # In case if your containers report messages with terminal colors or other escape sequences
 322    # you can enable strip for all the containers in one place.
 323    # Better is to enable it only for required container with the label collectord.io/strip-terminal-escape-sequences=true
 324    stripTerminalEscapeSequences = false
 325    # Regexp used for stripping terminal colors, it does not stip all the escape sequences
 326    # Read https://man7.org/linux/man-pages/man4/console_codes.4.html for more information
 327    stripTerminalEscapeSequencesRegex = (\x1b\[\d{1,3}(;\d{1,3})*m)|(\x07)|(\x1b]\d+(\s\d)?;[^\x07]+\x07)|(.*\x1b\[K)
 328
 329    # set output (syslog or devnull, default is [general]defaultOutput)
 330    output =
 331
 332    # configure default thruput per second for for each container log
 333    # for example if you set `thruputPerSecond = 128Kb`, that will limit amount of logs forwarded
 334    # from the single container to 128Kb per second.
 335    thruputPerSecond =
 336
 337    # Configure events that are too old to be forwarded, for example 168h (7 days) - that will drop all events
 338    # older than 7 days
 339    tooOldEvents =
 340
 341    # Configure events that are too new to be forwarded, for example 1h - that will drop all events that are 1h in future
 342    tooNewEvents =
 343
 344    # Syslog format
 345    type = k8s_logs
 346    syslog.format = {type}|{timestamp::format(2006-01-02T15:04:05.999999999Z07:00)}|{cluster}|{host}|{namespace}|{pod_id}|{pod_name}|{container_name}|{stream}|{message}
 347
 348
 349    # Application Logs
 350    [input.app_logs]
 351
 352    # disable container application logs monitoring
 353    disabled = false
 354
 355    # root location of mounts (applies to hostPath mounts only), if the hostPath differs inside container from the path on host
 356    root = /rootfs/
 357
 358    # how often to review list of available volumes
 359    syncInterval = 5s
 360
 361    # glob matching pattern for log files
 362    glob = *.log*
 363
 364    # files are read using polling schema, when reach the EOF how often to check if files got updated
 365    pollingInterval = 250ms
 366
 367    # how often to look for the new files under logs path
 368    walkingInterval = 5s
 369
 370    # include verbose fields in events (file offset)
 371    verboseFields = false
 372
 373    # we split files using new line character, with this configuration you can specify what defines the new event
 374    # after new line
 375    eventPatternRegex = ^[^\s]
 376    # Maximum interval of messages in pipeline
 377    eventPatternMaxInterval = 100ms
 378    # Maximum time to wait for the messages in pipeline
 379    eventPatternMaxWait = 1s
 380    # Maximum message size
 381    eventPatternMaxSize = 1MB
 382
 383    # set output (syslog or devnull, default is [general]defaultOutput)
 384    output =
 385
 386    # configure default thruput per second for for each container log
 387    # for example if you set `thruputPerSecond = 128Kb`, that will limit amount of logs forwarded
 388    # from the single container to 128Kb per second.
 389    thruputPerSecond =
 390
 391    # Configure events that are too old to be forwarded, for example 168h (7 days) - that will drop all events
 392    # older than 7 days
 393    tooOldEvents =
 394
 395    # Configure events that are too new to be forwarded, for example 1h - that will drop all events that are 1h in future
 396    tooNewEvents =
 397
 398    # syslog format
 399    type = k8s_logs
 400    syslog.format = {type}|{timestamp::format(2006-01-02T15:04:05.999999999Z07:00)}|{cluster}|{host}|{namespace}|{pod_id}|{pod_name}|{container_name}|{file_name}|{message}
 401
 402
 403    # Host logs. Input syslog(.\d+)? files
 404    [input.files::syslog]
 405
 406    # disable host level logs
 407    disabled = false
 408
 409    # root location of docker files
 410    path = /rootfs/var/log/
 411
 412    # regex matching pattern
 413    match = ^(syslog|messages)(.\d+)?$
 414
 415    # limit search only on one level
 416    recursive = false
 417
 418    # files are read using polling schema, when reach the EOF how often to check if files got updated
 419    pollingInterval = 250ms
 420
 421    # how often o look for the new files under logs path
 422    walkingInterval = 5s
 423
 424    # include verbose fields in events (file offset)
 425    verboseFields = false
 426
 427    # field extraction
 428    extraction = ^(?P<timestamp>[A-Za-z]+\s+\d+\s\d+:\d+:\d+)\s(?P<syslog_hostname>[^\s]+)\s(?P<syslog_component>[^:\[]+)(\[(?P<syslog_pid>\d+)\])?: (.+)$
 429    # extractionMessageField =
 430
 431    # timestamp field
 432    timestampField = timestamp
 433
 434    # format for timestamp
 435    # the layout defines the format by showing how the reference time, defined to be `Mon Jan 2 15:04:05 -0700 MST 2006`
 436    timestampFormat = Jan 2 15:04:05
 437
 438    # Adjust date, if month/day aren't set in format
 439    timestampSetMonth = false
 440    timestampSetDay = false
 441
 442    # timestamp location (if not defined by format)
 443    timestampLocation = Local
 444
 445    # sample output (-1 does not sample, 20 - only 20% of the logs should be forwarded)
 446    samplingPercent = -1
 447
 448    # sampling key for hash based sampling (should be regexp with the named match pattern `key`)
 449    samplingKey =
 450
 451    # set output (syslog or devnull, default is [general]defaultOutput)
 452    output =
 453
 454    # configure default thruput per second for this files group
 455    # for example if you set `thruputPerSecond = 128Kb`, that will limit amount of logs forwarded
 456    # from the files in this group to 128Kb per second.
 457    thruputPerSecond =
 458
 459    # Configure events that are too old to be forwarded, for example 168h (7 days) - that will drop all events
 460    # older than 7 days
 461    tooOldEvents =
 462
 463    # Configure events that are too new to be forwarded, for example 1h - that will drop all events that are 1h in future
 464    tooNewEvents =
 465
 466    # syslog format
 467    type = k8s_host_logs
 468    syslog.format = {type}|{timestamp::format(2006-01-02T15:04:05.999999999Z07:00)}|{cluster}|{host}|{file_name}|{message}
 469
 470
 471    # Host logs. Input all *.log(.\d+)? files
 472    [input.files::logs]
 473
 474    # disable host level logs
 475    disabled = false
 476
 477    # root location of log files
 478    path = /rootfs/var/log/
 479
 480    # regex matching pattern
 481    match = ^(([\w\-.]+\.log(.[\d\-]+)?)|(docker))$
 482
 483    # files are read using polling schema, when reach the EOF how often to check if files got updated
 484    pollingInterval = 250ms
 485
 486    # how often o look for the new files under logs path
 487    walkingInterval = 5s
 488
 489    # include verbose fields in events (file offset)
 490    verboseFields = false
 491
 492    # field extraction
 493    extraction =
 494    # extractionMessageField =
 495
 496    # timestamp field
 497    timestampField =
 498
 499    # format for timestamp
 500    # the layout defines the format by showing how the reference time, defined to be `Mon Jan 2 15:04:05 -0700 MST 2006`
 501    timestampFormat =
 502
 503    # timestamp location (if not defined by format)
 504    timestampLocation =
 505
 506    # sample output (-1 does not sample, 20 - only 20% of the logs should be forwarded)
 507    samplingPercent = -1
 508
 509    # sampling key for hash based sampling (should be regexp with the named match pattern `key`)
 510    samplingKey =
 511
 512    # set output (syslog or devnull, default is [general]defaultOutput)
 513    output =
 514
 515    # configure default thruput per second for this files group
 516    # for example if you set `thruputPerSecond = 128Kb`, that will limit amount of logs forwarded
 517    # from the files in this group to 128Kb per second.
 518    thruputPerSecond =
 519
 520    # Configure events that are too old to be forwarded, for example 168h (7 days) - that will drop all events
 521    # older than 7 days
 522    tooOldEvents =
 523
 524    # Configure events that are too new to be forwarded, for example 1h - that will drop all events that are 1h in future
 525    tooNewEvents =
 526
 527    # syslog format
 528    type = k8s_host_logs
 529    syslog.format = {type}|{timestamp::format(2006-01-02T15:04:05.999999999Z07:00)}|{cluster}|{host}|{file_name}|{message}
 530
 531
 532    [input.journald]
 533
 534    # disable host level logs
 535    disabled = false
 536
 537    # root location of log files
 538    path.persistent = /rootfs/var/log/journal/
 539    path.volatile = /rootfs/run/log/journal/
 540
 541    # when reach end of journald, how often to pull
 542    pollingInterval = 250ms
 543
 544    # if you don't want to forward journald from the beginning,
 545    # set the oldest event in relative value, like -14h or -30m or -30s (h/m/s supported)
 546    startFromRel =
 547
 548    # sample output (-1 does not sample, 20 - only 20% of the logs should be forwarded)
 549    samplingPercent = -1
 550
 551    # sampling key (should be regexp with the named match pattern `key`)
 552    samplingKey =
 553
 554    # how often to reopen the journald to free old files
 555    reopenInterval = 1h
 556
 557    # set output (syslog or devnull, default is [general]defaultOutput)
 558    output =
 559
 560    # configure default thruput per second for this files group
 561    # for example if you set `thruputPerSecond = 128Kb`, that will limit amount of logs forwarded
 562    # from the files in this group to 128Kb per second.
 563    thruputPerSecond =
 564
 565    # Configure events that are too old to be forwarded, for example 168h (7 days) - that will drop all events
 566    # older than 7 days
 567    tooOldEvents =
 568
 569    # Configure events that are too new to be forwarded, for example 1h - that will drop all events that are 1h in future
 570    tooNewEvents =
 571
 572    # syslog format
 573    type = k8s_host_logs
 574    syslog.format = {type}|{timestamp::format(2006-01-02T15:04:05.999999999Z07:00)}|{cluster}|{host}|journald|{message}
 575
 576
 577    # Pipe to join events (container logs only)
 578    [pipe.join]
 579
 580    # disable joining event
 581    disabled = false
 582
 583    # Maximum interval of messages in pipeline
 584    maxInterval = 100ms
 585
 586    # Maximum time to wait for the messages in pipeline
 587    maxWait = 1s
 588
 589    # Maximum message size
 590    maxSize = 1MB
 591
 592    # Default pattern to indicate new message (should start not from space)
 593    patternRegex = ^[^\s]
 594
 595
 596  003-daemonset-master.conf: |
 597
 598
 599  004-addon.conf: |
 600    [general]
 601
 602    # addons can be run in parallel with agents
 603    addon = true
 604
 605    [input.kubernetes_events]
 606
 607    # disable events
 608    disabled = false
 609
 610    # (obsolete, depends on kubernetes timeout)
 611    # Set the timeout for how long request to watch events going to hang reading.
 612    # eventsWatchTimeout = 30m
 613
 614    # (obsolete, depends on kubernetes timeout)
 615    # Ignore events last seen later that this duration.
 616    # eventsTTL = 12h
 617
 618    # set output (syslog or devnull, default is [general]defaultOutput)
 619    output =
 620
 621    # syslog format
 622    type = k8s_events
 623    syslog.format = {type}|{timestamp::format(2006-01-02T15:04:05.999999999Z07:00)}|{cluster}|{message}
 624
 625
 626---
 627apiVersion: apps/v1
 628kind: DaemonSet
 629metadata:
 630  name: collectorforkubernetes-syslog
 631  namespace: collectorforkubernetes-syslog
 632  labels:
 633    app: collectorforkubernetes-syslog
 634spec:
 635  # Default updateStrategy is OnDelete. For collectord RollingUpdate is suitable
 636  # When you update configuration
 637  updateStrategy:
 638    type: RollingUpdate
 639  selector:
 640    matchLabels:
 641      daemon: collectorforkubernetes-syslog
 642  template:
 643    metadata:
 644      name: collectorforkubernetes-syslog
 645      labels:
 646        daemon: collectorforkubernetes-syslog
 647    spec:
 648      priorityClassName: collectorforkubernetes-syslog-critical
 649      dnsPolicy: ClusterFirstWithHostNet
 650      hostNetwork: true
 651      serviceAccountName: collectorforkubernetes-syslog
 652      # We run this DaemonSet only for Non-Masters
 653      affinity:
 654        nodeAffinity:
 655          requiredDuringSchedulingIgnoredDuringExecution:
 656            nodeSelectorTerms:
 657            - matchExpressions:
 658              - key: node-role.kubernetes.io/master
 659                operator: DoesNotExist
 660      tolerations:
 661      - operator: "Exists"
 662        effect: "NoSchedule"
 663      - operator: "Exists"
 664        effect: "NoExecute"
 665      containers:
 666      - name: collectorforkubernetes-syslog
 667        # Collectord version
 668        image: docker.io/outcoldsolutions/collectorforkubernetes:26.04.4
 669        imagePullPolicy: Always
 670        securityContext:
 671          runAsUser: 0
 672          privileged: true
 673        # Define your resources if you need. Defaults should be fine for most.
 674        # You can lower or increase based on your hosts.
 675        resources:
 676          limits:
 677            cpu: 2
 678            memory: 512Mi
 679          requests:
 680            cpu: 200m
 681            memory: 192Mi
 682        env:
 683        - name: KUBERNETES_NODENAME
 684          valueFrom:
 685            fieldRef:
 686              fieldPath: spec.nodeName
 687        - name: POD_NAME
 688          valueFrom:
 689            fieldRef:
 690              fieldPath: metadata.name
 691        volumeMounts:
 692        # We store state in /data folder (file positions)
 693        - name: collectorforkubernetes-syslog-state
 694          mountPath: /data
 695        # Configuration file deployed with ConfigMap
 696        - name: collectorforkubernetes-syslog-config
 697          mountPath: /config/
 698          readOnly: true
 699        # Cgroup filesystem to get metrics
 700        - name: cgroup
 701          mountPath: /rootfs/sys/fs/cgroup
 702          readOnly: true
 703          # Proc filesystem to get metrics
 704        - name: proc
 705          mountPath: /rootfs/proc
 706          readOnly: true
 707        # Location of docker root (for container logs and metadata)
 708        - name: docker-root
 709          mountPath: /rootfs/var/lib/docker/
 710          readOnly: true
 711          mountPropagation: HostToContainer
 712        # Docker socket
 713        - name: docker-unix-socket
 714          mountPath: /rootfs/var/run/docker.sock
 715          readOnly: true
 716        # CRI-O socket (if using CRI-O runtime)
 717        - name: crio-unix-socket
 718          mountPath: /rootfs/var/run/crio/
 719          readOnly: true
 720        # Containerd socket (if using containerd runtime)
 721        - name: containerd-unix-socket
 722          mountPath: /rootfs/var/run/containerd/
 723          readOnly: true
 724        # Host logs location (including CRI-O logs)
 725        - name: logs
 726          mountPath: /rootfs/var/log/
 727          readOnly: true
 728        - name: run-logs
 729          mountPath: /rootfs/run/log/
 730          readOnly: true
 731        # Application logs
 732        - name: volumes-root
 733          mountPath: /rootfs/var/lib/kubelet/
 734          readOnly: true
 735          mountPropagation: HostToContainer
 736        # correct timezone
 737        - name: localtime
 738          mountPath: /etc/localtime
 739          readOnly: true
 740      volumes:
 741      # We store state directly on host, change this location, if
 742      # your persistent volume is somewhere else
 743      - name: collectorforkubernetes-syslog-state
 744        hostPath:
 745          path: /var/lib/collectorforkubernetes-syslog/data/
 746      # Location of docker root (for container logs and metadata)
 747      - name: docker-root
 748        hostPath:
 749          path: /var/lib/docker/
 750      # Location of cgroups file system
 751      - name: cgroup
 752        hostPath:
 753          path: /sys/fs/cgroup
 754      # Location of proc file system
 755      - name: proc
 756        hostPath:
 757          path: /proc
 758      # Host logs location (including CRI-O logs)
 759      - name: logs
 760        hostPath:
 761          path: /var/log
 762      - name: run-logs
 763        hostPath:
 764          path: /run/log
 765      # Docker socket
 766      - name: docker-unix-socket
 767        hostPath:
 768          path: /var/run/docker.sock
 769      # CRI-O socket (if using CRI-O runtime)
 770      - name: crio-unix-socket
 771        hostPath:
 772          path: /var/run/crio/
 773      # containerd socket (if using containerd runtime)
 774      - name: containerd-unix-socket
 775        hostPath:
 776          path: /var/run/containerd/
 777      # Location for kubelet mounts, to autodiscover application logs
 778      - name: volumes-root
 779        hostPath:
 780          path: /var/lib/kubelet/
 781      # correct timezone
 782      - name: localtime
 783        hostPath:
 784          path: /etc/localtime
 785      # configuration from ConfigMap
 786      - name: collectorforkubernetes-syslog-config
 787        configMap:
 788          name: collectorforkubernetes-syslog
 789          items:
 790          - key: 001-general.conf
 791            path: 001-general.conf
 792          - key: 002-daemonset.conf
 793            path: 002-daemonset.conf
 794---
 795apiVersion: apps/v1
 796kind: DaemonSet
 797metadata:
 798  name: collectorforkubernetes-syslog-master
 799  namespace: collectorforkubernetes-syslog
 800  labels:
 801    app: collectorforkubernetes-syslog
 802spec:
 803  updateStrategy:
 804    type: RollingUpdate
 805  selector:
 806    matchLabels:
 807      daemon: collectorforkubernetes-syslog
 808  template:
 809    metadata:
 810      name: collectorforkubernetes-syslog-master
 811      labels:
 812        daemon: collectorforkubernetes-syslog
 813    spec:
 814      priorityClassName: collectorforkubernetes-syslog-critical
 815      dnsPolicy: ClusterFirstWithHostNet
 816      hostNetwork: true
 817      serviceAccountName: collectorforkubernetes-syslog
 818      affinity:
 819        nodeAffinity:
 820          requiredDuringSchedulingIgnoredDuringExecution:
 821            nodeSelectorTerms:
 822            - matchExpressions:
 823              - key: node-role.kubernetes.io/master
 824                operator: Exists
 825      tolerations:
 826      - operator: "Exists"
 827        effect: "NoSchedule"
 828      - operator: "Exists"
 829        effect: "NoExecute"
 830      containers:
 831      - name: collectorforkubernetes-syslog
 832        image: docker.io/outcoldsolutions/collectorforkubernetes:26.04.4
 833        imagePullPolicy: Always
 834        securityContext:
 835          runAsUser: 0
 836          privileged: true
 837        resources:
 838          limits:
 839            cpu: 2
 840            memory: 512Mi
 841          requests:
 842            cpu: 200m
 843            memory: 192Mi
 844        env:
 845        - name: KUBERNETES_NODENAME
 846          valueFrom:
 847            fieldRef:
 848              fieldPath: spec.nodeName
 849        - name: POD_NAME
 850          valueFrom:
 851            fieldRef:
 852              fieldPath: metadata.name
 853        volumeMounts:
 854        - name: collectorforkubernetes-syslog-state
 855          mountPath: /data
 856        - name: collectorforkubernetes-syslog-config
 857          mountPath: /config/
 858          readOnly: true
 859        - name: cgroup
 860          mountPath: /rootfs/sys/fs/cgroup
 861          readOnly: true
 862        - name: proc
 863          mountPath: /rootfs/proc
 864          readOnly: true
 865        - name: docker-logs
 866          mountPath: /rootfs/var/lib/docker/
 867          readOnly: true
 868          mountPropagation: HostToContainer
 869        - name: docker-unix-socket
 870          mountPath: /rootfs/var/run/docker.sock
 871          readOnly: true
 872        - name: crio-unix-socket
 873          mountPath: /rootfs/var/run/crio/
 874          readOnly: true
 875        - name: containerd-unix-socket
 876          mountPath: /rootfs/var/run/containerd/
 877          readOnly: true
 878        - name: logs
 879          mountPath: /rootfs/var/log/
 880          readOnly: true
 881        - name: run-logs
 882          mountPath: /rootfs/run/log/
 883          readOnly: true
 884        - name: k8s-certs
 885          mountPath: /rootfs/etc/kubernetes/pki/
 886          readOnly: true
 887        - name: kubelet-root
 888          mountPath: /rootfs/var/lib/kubelet/
 889          readOnly: true
 890          mountPropagation: HostToContainer
 891        - name: localtime
 892          mountPath: /etc/localtime
 893          readOnly: true
 894      volumes:
 895      - name: collectorforkubernetes-syslog-state
 896        hostPath:
 897          path: /var/lib/collectorforkubernetes-syslog/data/
 898      - name: docker-logs
 899        hostPath:
 900          path: /var/lib/docker/
 901      - name: cgroup
 902        hostPath:
 903          path: /sys/fs/cgroup
 904      - name: proc
 905        hostPath:
 906          path: /proc
 907      - name: logs
 908        hostPath:
 909          path: /var/log
 910      - name: run-logs
 911        hostPath:
 912          path: /run/log
 913      - name: docker-unix-socket
 914        hostPath:
 915          path: /var/run/docker.sock
 916      - name: crio-unix-socket
 917        hostPath:
 918          path: /var/run/crio/
 919      - name: containerd-unix-socket
 920        hostPath:
 921          path: /var/run/containerd/
 922      - name: k8s-certs
 923        hostPath:
 924          path: /etc/kubernetes/pki/
 925      - name: kubelet-root
 926        hostPath:
 927          path: /var/lib/kubelet/
 928      - name: localtime
 929        hostPath:
 930          path: /etc/localtime
 931      - name: collectorforkubernetes-syslog-config
 932        configMap:
 933          name: collectorforkubernetes-syslog
 934          items:
 935          - key: 001-general.conf
 936            path: 001-general.conf
 937          - key: 002-daemonset.conf
 938            path: 002-daemonset.conf
 939          - key: 003-daemonset-master.conf
 940            path: 003-daemonset-master.conf
 941---
 942apiVersion: apps/v1
 943kind: Deployment
 944metadata:
 945  name: collectorforkubernetes-syslog-addon
 946  namespace: collectorforkubernetes-syslog
 947  labels:
 948    app: collectorforkubernetes-syslog
 949spec:
 950  replicas: 1
 951  selector:
 952    matchLabels:
 953      daemon: collectorforkubernetes-syslog
 954  template:
 955    metadata:
 956      name: collectorforkubernetes-syslog-addon
 957      labels:
 958        daemon: collectorforkubernetes-syslog
 959    spec:
 960      priorityClassName: collectorforkubernetes-syslog-critical
 961      serviceAccountName: collectorforkubernetes-syslog
 962      containers:
 963      - name: collectorforkubernetes-syslog
 964        image: docker.io/outcoldsolutions/collectorforkubernetes:26.04.4
 965        imagePullPolicy: Always
 966        securityContext:
 967          runAsUser: 0
 968          privileged: true
 969        resources:
 970          limits:
 971            cpu: 500m
 972            memory: 256Mi
 973          requests:
 974            cpu: 50m
 975            memory: 64Mi
 976        env:
 977        - name: KUBERNETES_NODENAME
 978          valueFrom:
 979            fieldRef:
 980              fieldPath: spec.nodeName
 981        - name: POD_NAME
 982          valueFrom:
 983            fieldRef:
 984              fieldPath: metadata.name
 985        volumeMounts:
 986        - name: collectorforkubernetes-syslog-state
 987          mountPath: /data
 988        - name: collectorforkubernetes-syslog-config
 989          mountPath: /config/
 990          readOnly: true
 991      volumes:
 992      - name: collectorforkubernetes-syslog-state
 993        hostPath:
 994          path: /var/lib/collectorforkubernetes-syslog/data/
 995      - name: collectorforkubernetes-syslog-config
 996        configMap:
 997          name: collectorforkubernetes-syslog
 998          items:
 999          - key: 001-general.conf
1000            path: 001-general.conf
1001          - key: 004-addon.conf
1002            path: 004-addon.conf