Outcold Solutions is sponsoring Splunk .conf26 - see you there!

Monitoring OpenShift

Forward OpenShift logs, metrics, and events to Splunk.

Stream container logs, metadata-enriched metrics, audit logs, and OpenShift events from any cluster. Red Hat–certified images included.

Install in 5 minutes Read concepts Troubleshooting

Installation

Set up Splunk app, HEC, and deploy collectord

Installation

Concepts

What Collectord does, the data model, and how configuration layers

Concepts

Configuration

Deployment files for docker.io and RHEL images

Configuration

Annotations

Control index routing, log discovery, and forwarding per pod

Annotations

Annotations reference

Full list of every annotation grouped by datatype

Annotations reference

Audit logs

Enable and forward OpenShift audit logs

Audit logs

Prometheus metrics

Scrape metrics from control plane and applications

Prometheus metrics

Splunk indexes

Split logs and metrics into separate Splunk indexes

Splunk indexes

Splunk field extraction

Define search-time field extraction rules for container logs

Splunk field extraction

Splunk HTTP Event Collector

Configure SSL and connection settings for Splunk HEC

Splunk HTTP Event Collector

Multiple clusters

Identify and differentiate multiple clusters in Splunk

Multiple clusters

Object streaming

Stream live OpenShift object changes to Splunk

Object streaming

License server

Distribute license keys across clusters from a central URL

License server

GPU monitoring

Collect Nvidia GPU metrics via nvidia-smi DaemonSet

GPU monitoring

Alerts

Predefined alerts for license, health, restarts, and OOM kills

Alerts

Troubleshooting

Verify configuration, check pod status, and diagnose issues

Troubleshooting

Release history

Changelog of all collectord and Splunk app releases

Release history

Upgrade

Step-by-step version upgrade instructions

Upgrade

Security

Image security, container privileges, and RBAC access model

Security

Configuration reference

Configuration reference

Configuration reference (RHEL)

Configuration reference (RHEL)