Integrate container runtime logs into CloudMonitor to monitor file access and process activities in your containers.
Prerequisites
-
You have created an ACK managed cluster.
-
You have activated Managed Service for Prometheus.
-
If you use a RAM user for the integration, you must grant the
AliyunCloudMonitorFullAccesssystem policy to that user.
Billing
-
Metric integration incurs real-time data export from Enterprise Cloud Monitor fees and Managed Service for Prometheus fees.
-
Log integration is billed based on Log Service (SLS) pricing.
Data integration
-
Log on to the CloudMonitor 2.0 console, select a target workspace, and in the left-side navigation pane, click Integration Center. Then, click Container Runtime Log.
-
Select an integration object from the drop-down list.
-
Configure the integration parameters and click OK:
-
Integration Name: Must be unique within the same integration policy.
-
Enable Collection of Container Runtime Logs: Turn on to start collecting container runtime logs.
-
Collect Runtime - Process: Turn on to collect process activity logs from the container runtime.
-
Collect Runtime - File: Turn on to collect file access logs from the container runtime.
-
Storage Destination: The destination where logs are stored.
-
-
Container runtime logs are collected by using extended Berkeley Packet Filter (eBPF) to capture real-time information such as file access and process activities. After the integration, you can view the integrated entities and their observability data in Entity Explorer.
Storage policy
CloudMonitor automatically creates an SLS Logstore and a Prometheus instance to store observability data.
|
Type |
Default location |
Notes |
|
Metrics |
Prometheus instance: RegionShare:{{workspaceName}}:{{regionId}} |
None |
|
Logs |
SLS Project: K8s-log-{cluster ID} SLS Logstore: runtime_security |
You can customize the storage target. |
Modify or delete an integration policy
To modify or delete an integration policy, go to Integration Center > Integration Management. Find the policy, and click Edit or Delete.