Outcold Solutions is sponsoring Splunk .conf26 - see you there!

Forward Kubernetes and OpenShift logs over syslog.

Stream container logs, host logs, syslog, journald, and Kubernetes events from any cluster over RFC 5424 syslog - to QRadar, Microsoft Sentinel, or any syslog-compatible SIEM.

Install in 5 minutes Read concepts Troubleshooting

Installation

Forward logs to QRadar via syslog
Installation

Concepts

What Collectord does, the data model, and how configuration layers
Concepts

Configuration

Kubernetes deployment YAML for syslog output
Configuration

Annotations

Control output routing, log discovery, multiline, and field extraction per pod
Annotations

OpenShift Configuration

OpenShift deployment files for syslog output
Configuration

Annotations reference

Full list of every annotation grouped by datatype
Annotations reference

Troubleshooting

Verify configuration and diagnose deployment issues
Troubleshooting

License server

Distribute license keys across clusters from a central URL
License server

Release history

Changelog of Collectord releases for the syslog forwarder
Release history

Upgrade

Step-by-step version upgrade instructions
Upgrade

Security

Image security, container privileges, and RBAC access model
Security