Have you jumped on the Kubernetes train and are now thinking about your logging strategy? Or are you considering migrating your application to a microservices architecture like Docker and want to proactively plan your logging strategy? The data capture methods and data format can be significantly different from what you used in the past. Additionally, multi-line events need to be accounted for. There are a few different ways to ingest this data into Splunk. For example, Splunk 'Kubernetes Connect' leverages Fluentd behind the scenes. There also is a Splunk logging plugin for docker, and a syslog logging plugin. The Splunk Universal Forwarder also can be deployed on a sidecar. What the pros and cons with so many choices? This session will help you sort it all out.
Slides PDF link - https://conf.splunk.com/files/2019/slides/IT2091.pdf?podcast=1577146211