Outcold Solutions is sponsoring Splunk .conf26 - see you there!

# Forward Kubernetes and OpenShift logs over syslog.

Stream container logs, host logs, syslog, journald, and Kubernetes events from any cluster over RFC 5424 syslog - to QRadar, Microsoft Sentinel, or any syslog-compatible SIEM.

[Install in 5 minutes](/content/docs/syslog-kubernetes/installation/index.html) [Read concepts](/content/docs/syslog-kubernetes/concepts/index.html) [Troubleshooting](/content/docs/syslog-kubernetes/troubleshooting/index.html)

## Installation  
Forward logs to QRadar via syslog  
→ [Installation](/content/docs/syslog-kubernetes/installation/index.html)

## Concepts  
What Collectord does, the data model, and how configuration layers  
→ [Concepts](/content/docs/syslog-kubernetes/concepts/index.html)

## Configuration  
Kubernetes deployment YAML for syslog output  
→ [Configuration](/content/docs/syslog-kubernetes/configuration-kubernetes/index.html)

## Annotations  
Control output routing, log discovery, multiline, and field extraction per pod  
→ [Annotations](/content/docs/syslog-kubernetes/annotations/index.html)

## OpenShift Configuration  
OpenShift deployment files for syslog output  
→ [Configuration](/content/docs/syslog-kubernetes/configuration-openshift/index.html)

## Annotations reference  
Full list of every annotation grouped by datatype  
→ [Annotations reference](/content/docs/syslog-kubernetes/annotations-reference/index.html)

## Troubleshooting  
Verify configuration and diagnose deployment issues  
→ [Troubleshooting](/content/docs/syslog-kubernetes/troubleshooting/index.html)

## License server  
Distribute license keys across clusters from a central URL  
→ [License server](/content/docs/syslog-kubernetes/license-server/index.html)

## Release history  
Changelog of Collectord releases for the syslog forwarder  
→ [Release history](/content/docs/syslog-kubernetes/release-history/index.html)

## Upgrade  
Step-by-step version upgrade instructions  
→ [Upgrade](/content/docs/syslog-kubernetes/upgrade/index.html)

## Security  
Image security, container privileges, and RBAC access model  
→ [Security](/content/docs/syslog-kubernetes/security/index.html)
