<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365305#M66507</link>
    <description>&lt;P&gt;We feel the Splunk Forwarder is more for host/node level data collection and that's not the way we were planning to log our Kubernetes infrastructure. If one were to want to write all logs back to the host/node level, then yes the Splunk Forwarder would work fine and we use it in the cloud at that level significantly already for many other workloads. In our opinion, the Splunk HEC is much more well suited to the task of collecting logs from something like Kubernetes/Docker which should be more directly from the logging driver or container engine level. &lt;/P&gt;

&lt;P&gt;The official &lt;A href="https://kubernetes.io/docs/concepts/cluster-administration/logging/"&gt;k8s logging documentation&lt;/A&gt; mentions several different logging approaches, with node-level and cluster-level being the two main parent categories. Cluster-level is the one that we believe is the better approach and why we're looking for a different solution than the Splunk Forwarder in this space.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Oct 2017 00:32:56 GMT</pubDate>
    <dc:creator>mcluver</dc:creator>
    <dc:date>2017-10-04T00:32:56Z</dc:date>
    <item>
      <title>Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365303#M66505</link>
      <description>&lt;P&gt;We’re looking to get our Kubernetes logs into Splunk and it appears the best (most cloud native) way to do that is to forward the logs from Fluentd to Splunk HEC (HTTP Event Collector). With that being said, we see where there are a number of plugins that people have developed for Fluentd for this use-case, see: &lt;A href="https://www.fluentd.org/plugins"&gt;Fluentd Plugins&lt;/A&gt; Could you guys please tell us if any of these were developed by Splunk employees or are officially vetted/supported?&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="Fluentd Plugins for Splunk"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/3574i74FBFCE0EBA62157/image-size/large?v=v2&amp;amp;px=999" role="button" title="Fluentd Plugins for Splunk" alt="Fluentd Plugins for Splunk" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Does Splunk have another cloud native solution that they recommend instead? Don’t say the UF (Splunk Universal Forwarder). I also found &lt;A href="https://answers.splunk.com/answers/525617/how-can-we-log-and-containerize-the-logs-using-kub.html"&gt;this&lt;/A&gt; Splunk Answers post regarding the same topic for a bit of background on what others were doing cloud natively. Thanks for any assistance with this question.&lt;/P&gt;

&lt;P&gt;Thanks &amp;amp; Best regards,&lt;BR /&gt;
Matt&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 17:54:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365303#M66505</guid>
      <dc:creator>mcluver</dc:creator>
      <dc:date>2017-10-03T17:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365304#M66506</link>
      <description>&lt;P&gt;Why are you dismissing the Universal Forwarder? It is as "cloud native" as anything else you might find?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2017 23:36:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365304#M66506</guid>
      <dc:creator>sduff_splunk</dc:creator>
      <dc:date>2017-10-03T23:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365305#M66507</link>
      <description>&lt;P&gt;We feel the Splunk Forwarder is more for host/node level data collection and that's not the way we were planning to log our Kubernetes infrastructure. If one were to want to write all logs back to the host/node level, then yes the Splunk Forwarder would work fine and we use it in the cloud at that level significantly already for many other workloads. In our opinion, the Splunk HEC is much more well suited to the task of collecting logs from something like Kubernetes/Docker which should be more directly from the logging driver or container engine level. &lt;/P&gt;

&lt;P&gt;The official &lt;A href="https://kubernetes.io/docs/concepts/cluster-administration/logging/"&gt;k8s logging documentation&lt;/A&gt; mentions several different logging approaches, with node-level and cluster-level being the two main parent categories. Cluster-level is the one that we believe is the better approach and why we're looking for a different solution than the Splunk Forwarder in this space.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 00:32:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365305#M66507</guid>
      <dc:creator>mcluver</dc:creator>
      <dc:date>2017-10-04T00:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365306#M66508</link>
      <description>&lt;P&gt;One solution to monitor Kubernetes and collect all logs is to use our collector &lt;/P&gt;

&lt;P&gt;SplunkBase: &lt;A href="https://splunkbase.splunk.com/app/3743/"&gt;https://splunkbase.splunk.com/app/3743/&lt;/A&gt;&lt;BR /&gt;
Youtube Demo &lt;A href="https://www.youtube.com/watch?v=C2zOO2XX5TI"&gt;https://www.youtube.com/watch?v=C2zOO2XX5TI&lt;/A&gt;&lt;BR /&gt;
Installation/configuration instructions &lt;A href="https://github.com/outcoldsolutions/collector/tree/master/kubernetes"&gt;https://github.com/outcoldsolutions/collector/tree/master/kubernetes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;With provided configuration it will automatically pick up all logs, enrich them with kubernetes metadata and ship it to Splunk. &lt;/P&gt;

&lt;P&gt;Let me know if you will have any questions.&lt;/P&gt;

&lt;P&gt;Edited (2017-10-05): posted link to published application on splunkbase&lt;/P&gt;</description>
      <pubDate>Wed, 04 Oct 2017 03:20:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365306#M66508</guid>
      <dc:creator>outcoldman</dc:creator>
      <dc:date>2017-10-04T03:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365307#M66509</link>
      <description>&lt;P&gt;That looks like a really nice solution for Kubernetes logging and metrics. Probably the best solution to date for Splunk I've seen. Is Splunk not planning on releasing their own TA for this platform at some point?&lt;/P&gt;

&lt;P&gt;Being a Splunk Enterprise Security customer I think we'd be interesting in the collection being CIM compliant as well. &lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 16:23:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365307#M66509</guid>
      <dc:creator>mcluver</dc:creator>
      <dc:date>2017-10-05T16:23:53Z</dc:date>
    </item>
    <item>
      <title>Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365308#M66510</link>
      <description>&lt;P&gt;CIM compliant is on our radar for "Monitoring Kubernetes" and "Collector for Kubernetes". &lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2017 16:46:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365308#M66510</guid>
      <dc:creator>outcoldman</dc:creator>
      <dc:date>2017-10-05T16:46:12Z</dc:date>
    </item>
    <item>
      <title>Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365309#M66511</link>
      <description>&lt;P&gt;To monitor Kubernetes please go here and follow the steps: &lt;A href="https://github.com/splunk/splunk-connect-for-kubernetes"&gt;https://github.com/splunk/splunk-connect-for-kubernetes&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jul 2018 12:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365309#M66511</guid>
      <dc:creator>epeterfi_splunk</dc:creator>
      <dc:date>2018-07-04T12:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Are any Fluentd apps Splunk vetted/supported? Or is there a preferred cloud-native solution for logging Kubernetes logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365310#M66512</link>
      <description>&lt;P&gt;See below my comment. Connect for K8 was launched months ago and works great. Also comes with an app.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 11:12:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-any-Fluentd-apps-Splunk-vetted-supported-Or-is-there-a/m-p/365310#M66512</guid>
      <dc:creator>epeterfi_splunk</dc:creator>
      <dc:date>2018-10-05T11:12:08Z</dc:date>
    </item>
  </channel>
</rss>

