Monitoring Kubernetes
Forward Kubernetes logs, metrics, and events to Splunk.
Stream container logs, metadata-enriched metrics, audit logs, and Kubernetes events from any cluster - straight into Splunk dashboards and alerts.
Install in 5 minutes Read concepts Troubleshooting Browse dashboards
Installation
Set up Splunk app, HEC, and deploy collectord
→ Installation
Concepts
What Collectord does, the data model, and how configuration layers
→ Concepts
Configuration
Deployment file structure and collectord settings
→ Configuration
Annotations
Control index routing, log discovery, multiline, and field extraction per pod
→ Annotations
Annotations reference
Full list of every annotation grouped by datatype
→ Annotations reference
Audit logs
Enable and forward Kubernetes API audit logs
→ Audit logs
Prometheus metrics
Scrape metrics from control plane and applications
→ Prometheus metrics
Splunk indexes
Split logs and metrics into separate Splunk indexes
→ Splunk indexes
Splunk field extraction
Define search-time field extraction rules for container logs
→ Splunk field extraction
Splunk HTTP Event Collector
Configure SSL and connection settings for Splunk HEC
→ Splunk HTTP Event Collector
Multiple clusters
Identify and differentiate multiple clusters in Splunk
→ Multiple clusters
Object streaming
Stream live Kubernetes object changes to Splunk
→ Object streaming
License server
Distribute license keys across clusters from a central URL
→ License server
GPU monitoring
Collect Nvidia GPU metrics via nvidia-smi DaemonSet
→ GPU monitoring
Alerts
Predefined alerts for license, health, restarts, and OOM kills
→ Alerts
Troubleshooting
Verify configuration, check pod status, and diagnose issues
→ Troubleshooting
Release history
Changelog of all collectord and Splunk app releases
→ Release history
Upgrade
Step-by-step version upgrade instructions
→ Upgrade
Security
Image security, container privileges, and RBAC access model
→ Security