Outcold Solutions is sponsoring Splunk .conf26 - see you there!
Forward Kubernetes and OpenShift logs over syslog.
Stream container logs, host logs, syslog, journald, and Kubernetes events from any cluster over RFC 5424 syslog - to QRadar, Microsoft Sentinel, or any syslog-compatible SIEM.
Install in 5 minutes Read concepts Troubleshooting
Installation
Forward logs to QRadar via syslog
→ Installation
Concepts
What Collectord does, the data model, and how configuration layers
→ Concepts
Configuration
Kubernetes deployment YAML for syslog output
→ Configuration
Annotations
Control output routing, log discovery, multiline, and field extraction per pod
→ Annotations
OpenShift Configuration
OpenShift deployment files for syslog output
→ Configuration
Annotations reference
Full list of every annotation grouped by datatype
→ Annotations reference
Troubleshooting
Verify configuration and diagnose deployment issues
→ Troubleshooting
License server
Distribute license keys across clusters from a central URL
→ License server
Release history
Changelog of Collectord releases for the syslog forwarder
→ Release history
Upgrade
Step-by-step version upgrade instructions
→ Upgrade
Security
Image security, container privileges, and RBAC access model
→ Security