Splunk Enterprise

Seeking Guidance on Configuring Kubernetes Logs with Splunk Enterprise

spodda01da
Path Finder

Hi All,

I've been exploring various documentation and tutorials, but I'd love to hear from those who have hands-on experience. What are the best practices and recommended steps for configuring Kubernetes logs to seamlessly integrate with Splunk Enterprise? Are there any specific considerations or challenges I should be aware of during the setup process?

Thanks in advance for sharing your expertise!

mattymo
Splunk Employee
Splunk Employee

The way to go is with the OpenTelemetry Helm Chart. Wrote a lil quickstart here

https://github.com/matthewmodestino/otel-quickstart/blob/main/kubernetes/0-quickstart-home.md#kubern...

See docs and validated architecture for more!

https://docs.splunk.com/Documentation/Splunk/9.1.2/Data/OtelCollectorKubernetes

https://docs.splunk.com/Documentation/SVA/current/Architectures/OTelKubernetes

If you run into issues reach out to your SE, we have workshops or jump into the community slack channel splk.it/slack!

holler at me in the kubernetes channel, or opentelemetry channels, (mattymo)

- MattyMo
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...