Container runtime log integration

更新时间:
复制 MD 格式

Integrate container runtime logs into CloudMonitor to monitor file access and process activities in your containers.

Prerequisites

Billing

Data integration

  1. Log on to the CloudMonitor 2.0 console, select a target workspace, and in the left-side navigation pane, click Integration Center. Then, click Container Runtime Log.

  2. Select an integration object from the drop-down list.

  3. Configure the integration parameters and click OK:

    • Integration Name: Must be unique within the same integration policy.

    • Enable Collection of Container Runtime Logs: Turn on to start collecting container runtime logs.

    • Collect Runtime - Process: Turn on to collect process activity logs from the container runtime.

    • Collect Runtime - File: Turn on to collect file access logs from the container runtime.

    • Storage Destination: The destination where logs are stored.

  4. Container runtime logs are collected by using extended Berkeley Packet Filter (eBPF) to capture real-time information such as file access and process activities. After the integration, you can view the integrated entities and their observability data in Entity Explorer.

Storage policy

CloudMonitor automatically creates an SLS Logstore and a Prometheus instance to store observability data.

Type

Default location

Notes

Metrics

Prometheus instance: RegionShare:{{workspaceName}}:{{regionId}}

None

Logs

SLS Project: K8s-log-{cluster ID}

SLS Logstore: runtime_security

You can customize the storage target.

Modify or delete an integration policy

To modify or delete an integration policy, go to Integration Center > Integration Management. Find the policy, and click Edit or Delete.