Professional Documents
Culture Documents
Kubernetes
Observability with
Splunk Connect for
Kubernetes (SCK)
October 2019
© 2019 SPLUNK INC.
Forward-Looking Statements
During the course of this presentation, we may make forward-looking statements regarding future events or
the expected performance of the company. We caution you that such statements reflect our current
expectations and estimates based on factors currently known to us and that actual events or results could
differ materially. For important factors that may cause actual results to differ from those contained in our
forward-looking statements, please review our filings with the SEC.
The forward-looking statements made in this presentation are being made as of the time and date of its live
presentation. If reviewed after its live presentation, this presentation may not contain current or accurate
information. We do not assume any obligation to update any forward-looking statements we may make. In
addition, any information about our roadmap outlines our general product direction and is subject to change
at any time without notice. It is for informational purposes only and shall not be incorporated into any contract
or other commitment. Splunk undertakes no obligation either to develop the features or functionality
described or to include any such feature or functionality in a future release.
Splunk, Splunk>, Listen to Your Data, The Engine for Machine Data, Splunk Cloud, Splunk Light and SPL are trademarks and registered trademarks of Splunk Inc. in
the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners. © 2019 Splunk Inc. All rights reserved.
© 2019 SPLUNK INC.
Demo
Sneak peek into today’s presentation
© 2019 SPLUNK INC.
8. Q&A
© 2019 SPLUNK INC.
▶ 3 pillars of observability
Logs
▶ Loosely tied together
Trace
Metrics
s
© 2019 SPLUNK INC.
Different Types of
Data in Splunk
▶ Metric data
▶ Event data
• Log data
• Objects metadata
© 2019 SPLUNK INC.
SCK Component
Component types
• Logs
• Metrics
• Objects
Collector agent: Fluentd
• Fluentd plugins for component
functionality
Deployment types
• K8s Deployment
• K8s Daemonset
© 2019 SPLUNK INC.
Logging Component
Deployment - daemonset
• configmap
• secret
• serviceAccount
Fluentd plugins
• in_tail
• systemd
• monitor_agent
• concat
• jq_transformer
Logs are sent to Splunk using Splunk’s
• splunk_hec
fluentd HEC plugin (splunk_hec)
© 2019 SPLUNK INC.
Metrics Component
Deployments
• daemonset
• Supporting kubernetes objects
(configmaps, secrets and
serviceAccounts)
Fluentd plugins
• kubernetes_metrics
• kubernetes_metrics_aggregator
• splunk_hec
Metrics are sent to Splunk using Splunk’s
fluentd HEC plugin (splunk_hec)
© 2019 SPLUNK INC.
Objects Component
Deployment
• configmap
• secret
• serviceAccount
Fluentd plugins
• kubernetes_objects
• splunk_hec
Objects plugin
• Cluster’s events metadata for
configured kubernetes objects (pods,
nodes, configmaps)
Collected events are sent to Splunk using
Splunk’s fluentd HEC plugin(splunk_hec)
© 2019 SPLUNK INC.
Installation and
Configuration
How to install and configure Splunk Connect for K8s
using Helm
© 2019 SPLUNK INC.
Splunk Prerequisites
What you need to get started
Kubernetes Prerequisites
What you need to get started
Demo
Splunk Connect for Kubernetes
© 2019 SPLUNK INC.
K8s Metrics
Endpoints and Splunk
Metrics Workspace.
Where we collect things and where they end up
© 2019 SPLUNK INC.
Where do we https://github.com/splunk/fluent-plugin-kubernetes-metrics/blob/develop/metrics-information.md
Advanced Splunk
Tooling with SCK
Introducing Splunk App for Infrastructure with SCK
© 2019 SPLUNK INC.
Demo
Splunk App for Infrastructure
© 2019 SPLUNK INC.
Splunk Connect
Kubernetes
Highlights and What’s
Next
Next Release – Now!
© 2019 SPLUNK INC.
Support for
PKS
Flexible
security
configurations
(PSP)
More metrics
alongside
improved
performance
Better out of
the box tracing
capability
© 2019 SPLUNK INC.
▶ Contributions -
https://github.com/splunk/splunk-connect-for-kubernetes/issues/new
© 2019 SPLUNK INC.
Thank
You!
Don’t forget to rate our session
© 2019 SPLUNK INC.
Q&A
Come visit us at the GDI booth on the main floor!!