Outcold Solutions LLC

Forwarding Kubernetes logs to QRadar - Version 5

Configuration

collectorforkubernetes-syslog.yaml

To find server version of your Kubernetes cluster use

$ kubectl version

Match the server version with one of the links below. If you are using version, which is not in this list you can try the closest version.

If you are using version, which is not on the list, please email us contact@outcoldsolutions.com

Created Kubernetes Objects

Configuration file collectorforkubernetes-syslog.yaml creates several Kubernetes Objects.

  • Namespace collectorforkubernetes-syslog.
  • ClusterRole collectorforkubernetes-syslog with limited capabilities to get, list and watch deployed objects. Collector uses this information to enrich logs and stats with kubernetes specific metadata.
  • ServiceAccount collectorforkubernetes-syslog is used to connect to Kubernetes API.
  • ClusterRoleBinding collectorforkubernetes-syslog to bind service account to cluster role.
  • ConfigMap collectorforkubernetes-syslog delivers configuration files for collector.
  • DaemonSet collectorforkubernetes-syslog allows to deploy collector on none-master nodes.
  • DaemonSet collectorforkubernetes-syslog-master allows to deploy collector on master nodes.
  • Deployment collectorforkubernetes-syslog-addon is a single collector, that needs to forward data from the whole cluster once.

Read commentaries in collectorforkubernetes-syslog.yaml file to get more deep details on all configurations and source of the logs and metrics.


About Outcold Solutions

Outcold Solutions provides solutions for monitoring Kubernetes, OpenShift and Docker clusters in Splunk Enterprise and Splunk Cloud. We offer certified Splunk applications, which give you insights across all containers environments. We are helping businesses reduce complexity related to logging and monitoring by providing easy-to-use and deploy solutions for Linux and Windows containers. We deliver applications, which help developers monitor their applications and operators to keep their clusters healthy. With the power of Splunk Enterprise and Splunk Cloud, we offer one solution to help you keep all the metrics and logs in one place, allowing you to quickly address complex questions on container performance.