Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

How to Integrate Docker Kubernetes POD's Logs with Chronicle

Hello Team,

Requesting your kind support to help us to understand on How to Integrate Docker Kubernetes POD's Logs with Chronicle SIEM, (Not GKE Logs)

kindly help with Base line document on the same, how can we enable Configuration on Kubernetes side to enable logs and how can we pull or configured API or else to get logs into Google Chronicle.

Thanks in advance!

Regards,

Parvez Gadkari

Solved Solved
0 2 349
1 ACCEPTED SOLUTION

Hello @pagadkari

Thank you for contacting Google Cloud Community.

I understand that you would like to know a way to export Kubernetes Pod Logs to Google Chronicle. Please correct me, if I misunderstood.

This functionality could be achieved with Fluent Bit. The steps involved in this process are : 

  1. Setting up Fluent Bit
  2. Configuring Fluent Bit
  3. Deploying Fluent Bit to Kubernetes
  4. Verifying the logs in Google Chronicle

For more information, please refer to :

  1. Fluent Bit Kuberentes Logging
  2. Fluent Bit Inputs
  3. Fluent Bit Outputs 

I hope the above information is helpful. 

Thanks & Regards,
Manish Bavireddy.

 

View solution in original post

2 REPLIES 2

Hello @pagadkari

Thank you for contacting Google Cloud Community.

I understand that you would like to know a way to export Kubernetes Pod Logs to Google Chronicle. Please correct me, if I misunderstood.

This functionality could be achieved with Fluent Bit. The steps involved in this process are : 

  1. Setting up Fluent Bit
  2. Configuring Fluent Bit
  3. Deploying Fluent Bit to Kubernetes
  4. Verifying the logs in Google Chronicle

For more information, please refer to :

  1. Fluent Bit Kuberentes Logging
  2. Fluent Bit Inputs
  3. Fluent Bit Outputs 

I hope the above information is helpful. 

Thanks & Regards,
Manish Bavireddy.

 

@Manish_B  Is there a Parser available that can support these logs and does it work with all the K8 in all platform ?

Top Labels in this Space