Getting Data In

Nginx Logs from Kubernertes Containers

stuartcooney
Loves-to-Learn

hi guys,

forgive the n00bness of this question as im sure its fairly straightforward and/or been answered before.

So im just in the process of rolling out Splunk to the business. One of the key requirements is parsing our Nginx logs. Now im able to do this easily from a standard Linux box using a deployment server. However, all our websites are moving to Kubernetes so im wondering what's the best way that i can get the data from the nginx containers/pods to Splunk. Obviously adding the UF to the docker image for every microservice would be overkill as i want to keep the images as lean as possible. Am i right thats not the best way to do this?

 

Thanks!

Labels (1)
Tags (2)
0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...