Source types for the Splunk Add-on for Kubernetes
The Splunk Add-on for Kubernetes provides the following source types by default. Source types and the extent to which you can configure them depend on the sources configured in Splunk Connect for Kubernetes.
Data source | Collection method | Source type |
---|---|---|
Kubernetes system component logs | HEC (through Splunk Connect for Kubernetes) | kube:*
|
Kubernetes container logs | HEC (through Splunk Connect for Kubernetes) | kube:container:*
|
Kubernetes objects collected using pull | HEC (through Splunk Connect for Kubernetes) | kube:objects:*
|
Kubernetes objects collected using watch | HEC (through Splunk Connect for Kubernetes) | kube:objects:*:watch
|
Fluentd plugin monitoring logs | HEC (through Splunk Connect for Kubernetes) | fluentd:monitor-agent
|
Heapster container logs | HEC (through Splunk Connect for Kubernetes) | kube:container:splunk-heapster
|
Fluentd container logs | HEC (through Splunk Connect for Kubernetes) | kube:container:splunk-fluentd*
|
About the Splunk Add-on for Kubernetes | Release notes for the Splunk Add-on for Kubernetes |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!