Troubleshooting
No Container Logs
Check that the app emits logs and annotation is present
Check index name and provided api_key are correct
Check logstash pod logs
kubectl -n <namespace> logs <logstash_pod_name> --tail=200
No Audit Logs
Ensure query is correct, referring to the fields reference for kubernetes audit logs
Check index name and provided api_key are correct
kubectl -n <namespace> logs <logstash_pod_name> --tail=200
Logstash Pod Issues
Describe pod for errors:
kubectl -n <namespace> describe pod <logstash_pod_name>
Check cluster events
kubectl -n <namespace> get events --sort-by=.metadata.creationTimestamp
Notes
Export logs: Use logstash to export logs to your existing platform.
Log retention: By default, logs are retained for 30 days or 50 GB (whichever comes first).
Collect both audit & container logs: Yes, enable container logs as described above. Audit logs enabled by default.
Support: Open a ticket in the Service Portal AI.
Last updated