Discover, share, and install apps and add-ons with the Splunk community on Splunkbase. Publish your own or add others to your Splunk platform instance.
Streamline your security operations with a SOAR system that integrates orchestration, playbook automation, and case management to enhance threat response.
Access and share apps and add-ons with the Splunk community on Splunkbase. Publish your own apps, or download and install others on your Splunk platform instance.
You can experience the enhanced UI for Clusters and also use alerting for Kubernetes Entities.
To view the Enhanced UI and use Kubernetes Alerting, enable these features in the Controller. See Enable New UI and Kubernetes Alerting. After you enable the feature, you can experience the following updates:
After the customer support enables this feature, you can view the following updates:
The Entity Map pane: When you navigate to the cluster dashboard for a specific cluster, the Entity Map pane lists the related entities in a hierarchy. This helps in understanding the total number of entities that are part of that cluster along with the details of how many of those are healthy.
Figure 1. Entity Map
Monitor node: When you click Nodes on the Entity Map, you can view the list of namespaces that are part of the cluster. Use the segmented control (Unhealthy, Normal, All) to filter the list by health status.
Figure 2. Nodes List View
When you select a specific node and click Details, it displays the dashboard for the selected node along with the events that are part of the node. Also, you can view the details of the related pods on the right pane.
Figure 3. Nodes Detail View
Monitor namespace: When you click Namespaces on the Entity Map, you can view the list of namespaces that are part of the cluster. Use the segmented control (Unhealthy, Normal, All) to filter the list by health status.
Figure 4. Namespace Detail View
When you select a specific namespace and click Details, it displays the dashboard for the selected namespace along with the events that are part of the namespace. Also, you can view the details of the related entities on the right pane.
Figure 5. Namespace Dashboard
Monitor Workload: When you click Workloads on the Entity Map, you can view the list of workloads that are part of the cluster. Use the segmented control (Unhealthy, Normal, All) to filter the list by health status.
Figure 6. Workload Details View
If you want to view the details of workloads that are part of a specific namespace, navigate to the namespace dashboard, then click Workloads. The left arrow signifies that the filter is applied to view the entity details in a hierarchical way. You can click on the left arrow to remove the filter.
Figure 7. Workload that is Part of a Specific Namespace
When you select a specific workload and click Details, it displays the dashboard for the selected workload along with the events that are part of the workload.
Figure 8. Workload Dashboard
K8s Metric Explorer: The new metrics are available after you enable the feature. These metrics are displayed on the K8s Metric Explorer. You can select the required entity and the metric to visualize the metric data. For details about the metrics, see Kubernetes Metrics.
Figure 9. K8s Metric Explorer
Kubernetes Alerting
You can create a health rule for Kubernetes entities, such as Clusters, Namespaces, Workloads, and Pods. These rules help in detecting and troubleshooting any health rule violation. For more information, see Kubernetes Health Rules and Alerting.