Monitoring Kubernetes

Forward Kubernetes logs, metrics, and events to Splunk.

Stream container logs, metadata-enriched metrics, audit logs, and Kubernetes events from any cluster - straight into Splunk dashboards and alerts.

Install in 5 minutes Read concepts Troubleshooting Browse dashboards

Installation

Set up Splunk app, HEC, and deploy collectord
Installation

Concepts

What Collectord does, the data model, and how configuration layers
Concepts

Configuration

Deployment file structure and collectord settings
Configuration

Annotations

Control index routing, log discovery, multiline, and field extraction per pod
Annotations

Annotations reference

Full list of every annotation grouped by datatype
Annotations reference

Audit logs

Enable and forward Kubernetes API audit logs
Audit logs

Prometheus metrics

Scrape metrics from control plane and applications
Prometheus metrics

Splunk indexes

Split logs and metrics into separate Splunk indexes
Splunk indexes

Splunk field extraction

Define search-time field extraction rules for container logs
Splunk field extraction

Splunk HTTP Event Collector

Configure SSL and connection settings for Splunk HEC
Splunk HTTP Event Collector

Multiple clusters

Identify and differentiate multiple clusters in Splunk
Multiple clusters

Object streaming

Stream live Kubernetes object changes to Splunk
Object streaming

License server

Distribute license keys across clusters from a central URL
License server

GPU monitoring

Collect Nvidia GPU metrics via nvidia-smi DaemonSet
GPU monitoring

Alerts

Predefined alerts for license, health, restarts, and OOM kills
Alerts

Troubleshooting

Verify configuration, check pod status, and diagnose issues
Troubleshooting

Release history

Changelog of all collectord and Splunk app releases
Release history

Upgrade

Step-by-step version upgrade instructions
Upgrade

Security

Image security, container privileges, and RBAC access model
Security

Configuration reference

Configuration reference