Outcold Solutions is sponsoring Splunk .conf26 - see you there!

# Monitoring OpenShift

## Forward OpenShift logs, metrics, and events to Splunk.

Stream container logs, metadata-enriched metrics, audit logs, and OpenShift events from any cluster. Red Hat–certified images included.

[Install in 5 minutes](/content/docs/monitoring-openshift/installation/index.html) [Read concepts](/content/docs/monitoring-openshift/concepts/index.html) [Troubleshooting](/content/docs/monitoring-openshift/troubleshooting/index.html)

### Installation

Set up Splunk app, HEC, and deploy collectord

→ [Installation](/content/docs/monitoring-openshift/installation/index.html)  
### Concepts

What Collectord does, the data model, and how configuration layers

→ [Concepts](/content/docs/monitoring-openshift/concepts/index.html)  
### Configuration

Deployment files for docker.io and RHEL images

→ [Configuration](/content/docs/monitoring-openshift/configuration/index.html)  
### Annotations

Control index routing, log discovery, and forwarding per pod

→ [Annotations](/content/docs/monitoring-openshift/annotations/index.html)  
### Annotations reference

Full list of every annotation grouped by datatype

→ [Annotations reference](/content/docs/monitoring-openshift/annotations-reference/index.html)  
### Audit logs

Enable and forward OpenShift audit logs

→ [Audit logs](/content/docs/monitoring-openshift/audit/index.html)  
### Prometheus metrics

Scrape metrics from control plane and applications

→ [Prometheus metrics](/content/docs/monitoring-openshift/prometheus/index.html)  
### Splunk indexes

Split logs and metrics into separate Splunk indexes

→ [Splunk indexes](/content/docs/monitoring-openshift/splunk-indexes/index.html)  
### Splunk field extraction

Define search-time field extraction rules for container logs

→ [Splunk field extraction](/content/docs/monitoring-openshift/splunk-fields-extraction/index.html)  
### Splunk HTTP Event Collector

Configure SSL and connection settings for Splunk HEC

→ [Splunk HTTP Event Collector](/content/docs/monitoring-openshift/splunk-output/index.html)  
### Multiple clusters

Identify and differentiate multiple clusters in Splunk

→ [Multiple clusters](/content/docs/monitoring-openshift/clusters/index.html)  
### Object streaming

Stream live OpenShift object changes to Splunk

→ [Object streaming](/content/docs/monitoring-openshift/objects/index.html)  
### License server

Distribute license keys across clusters from a central URL

→ [License server](/content/docs/monitoring-openshift/license-server/index.html)  
### GPU monitoring

Collect Nvidia GPU metrics via nvidia-smi DaemonSet

→ [GPU monitoring](/content/docs/monitoring-openshift/gpu/index.html)  
### Alerts

Predefined alerts for license, health, restarts, and OOM kills

→ [Alerts](/content/docs/monitoring-openshift/alerts/index.html)  
### Troubleshooting

Verify configuration, check pod status, and diagnose issues

→ [Troubleshooting](/content/docs/monitoring-openshift/troubleshooting/index.html)  
### Release history

Changelog of all collectord and Splunk app releases

→ [Release history](/content/docs/monitoring-openshift/release-history/index.html)  
### Upgrade

Step-by-step version upgrade instructions

→ [Upgrade](/content/docs/monitoring-openshift/upgrade/index.html)  
### Security

Image security, container privileges, and RBAC access model

→ [Security](/content/docs/monitoring-openshift/security/index.html)  
### Configuration reference

→ [Configuration reference](/content/docs/monitoring-openshift/reference/index.html)  
### Configuration reference (RHEL)

→ [Configuration reference (RHEL)](/content/docs/monitoring-openshift/reference-rhel/index.html)
