All Apps and Add-ons

How to Capture Kubernetes Interactive Exec Logging

joeldavideng
Path Finder

I am using Splunk Connect for Kubernetes on EKS which seems to capture most logs right out of the box. What it doesn't capture are interactive commands run from within containers. For example, if I "exec" into a container and run commands, none of that seems to be logged. Has anyone configured that level of auditing before or am I missing something in the default set up that should be capturing that?

0 Karma
Get Updates on the Splunk Community!

Index This | What did the zero say to the eight?

June 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

Splunk Observability Cloud's AI Assistant in Action Series: Onboarding New Hires & ...

This is the fifth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Now Playing: Splunk Education Summer Learning Premieres

It’s premiere season, and Splunk Education is rolling out new releases you won’t want to miss. Whether you’re ...