Disclaimer: The LogSource LM LogicModule is currently in open Beta.
LogSource is a LogicModule that provides templates to help you enable LM Logs and configure log data collection and forwarding. LogSource contains details about which logs to get and where to get them, and which fields should be considered for parsing. LogSource is available for common sources of log data.
The Kubernetes Event Logging LogSource type uses the LM Collector. When using the LM Collector with LogSource, the LM Collectors installed in your infrastructure must be version EA 31.200 or later. For information on how to upgrade a collector, see Managing Collectors.
The following describes configuration details specific to the Kubernetes Event Logging type of LogSource. For general information on how to add a LogSource, see Configuring a LogSource.
You can add filters to include resources of certain types, for example an application. The output matching the filter criteria will be forwarded to the log ingestion process.
|Attributes||Comparison operator||Value example||Description|
|Message||Equal, NotEqual, Contain, NotContain, RegexMatch, RegexNotMatch.|
|Reason||Equal, NotEqual, Contain, NotContain, RegexMatch, RegexNotMatch.||Free text possible as list is too long. See the Kubernetes documentation for examples of event reasons.|
|Type||Equal, NotEqual.||Normal, Warning.||Options are “Normal” and “Warning”. See the Kubernetes documentation for valid event types. A missing “Type” filter means including both “Normal” and “Warning” types.|
You can configure Log Fields (tags) to send additional metadata with the logs.
|Method||Key example||Value example||Description|
|Dynamic(REGEX)||“Host”||“host=*”||The query will run on the message field.|
|Kubernetes Attribute||Type, Reason.|
Configuration example for a Kubernetes Event Logging type of LogSource.
- Name: Kubernetes_Events
- Description: Data collection for event logs from monitored Kubernetes clusters.
- AppliesTo (custom query): system.devicetype == “8”
- Type: LM Logs: Kubernetes Event Logging
- Group: Kubernetes