All Apps and Add-ons

Best parctice to monitor Kubernetes cluster with Splunk enterprise

alexgohberg
Explorer

Hey all
Im recently started to work with GCP using K8s cluster, as im new in the field of K8s I will want to ask the big community here what is the best practices\ways to monitor the pods\nodes in the cluster with Splunk.
I already created a VM that running Splunk 7.1 at my environment.

Thanks in advance

Tags (1)
0 Karma

dipeshmitthalal
New Member

We used Splunk connect for Kubernetes https://github.com/splunk/splunk-connect-for-kubernetes. This enabled us to get all data in Splunk. Then we can build dashboards we want. Also, Once can use Metrics / Analysis workspacehttps://splunkbase.splunk.com/app/4192/ to visualize metrics in easy way.

0 Karma

outcoldman
Communicator

Our company provides a complete solution for Monitoring Kubernetes in Splunk https://www.outcoldsolutions.com/. We are Splunk Alliance Technology partners.

You can download our certified application at https://splunkbase.splunk.com/app/3743/ and follow instructions on how to get our kubernetes native collector to be installed in your cluster https://www.outcoldsolutions.com/docs/monitoring-kubernetes/

Our solution forwards application logs, host logs, metrics from the hosts, pods, containers and the processes. We are working on the next version of our solution, that will include monitoring capabilities for the control plane, including etcd cluster, controller manager, kubelets, scheduler, and providing capabilities to explore audit logs.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...