AWS EKS
Scanner supports AWS EKS container logs and control plane logs. These logs can be generated by a few sources, including the containers running your application and the various Kubernetes control plane components of your cluster (eg. api
, audit
, authenticator
, controllerManager
, and scheduler
).
In order for Scanner to see your EKS logs, you can configure EKS to publish logs to CloudWatch, then configure the CloudWatch log groups to forward logs to a Kinesis Data Firehose, which can then write the logs into an S3 bucket that Scanner is linked to.
Step 1: Configure EKS to publish logs to CloudWatch
You can follow AWS documentation to publish your EKS logs to one or more CloudWatch log groups.
For container logs (eg. your application logs), see: Send logs to CloudWatch Logs.
For control plane logs, see: Send control plane logs to CloudWatch Logs.
Step 2: Set up CloudWatch to push to Kinesis Data Firehose
You can follow the AWS documentation to configure your CloudWatch log groups to push their logs to a Kinesis Data Firehose. See: Send CloudWatch Logs to Firehose.
Step 3: Configure the Kinesis Data Firehose to write logs to S3
A Kinesis Data Firehose can push logs to various destinations. We want to push to an S3 bucket that Scanner is linked to. You can follow the AWS documentation to configure the Firehose to write to an S3 bucket. See: Understand data delivery in Amazon Data Firehose.
Step 4: Ingest via Scanner Collect
Last updated
Was this helpful?