K8s Context Extractor
Enrich TenXObjects with Kubernetes context by extracting container, pod, and namespace k8s names from their enclosing text.
Example
For the event below, the log field contains raw text that is structured into a typed TenXObject.
This module extracts underlying event Kubernetes context such including container name, pod name, and namespace as named fields from a TenXObject's surrounding fullText for further processing and aggregation.
For example, for the event below this module will extract the following field values:
{
"log": "[INFO] plugin/reload: Running configuration SHA512 = f869070685748660180df1b7a47d58cdafcf2f368266578c062d1151dc2c900964aecc5975e8882e6de6fdfb6460463e30ebfaad2ec8f0c3c6436f80225b3b5b\n",
"stream": "stdout",
"docker": {
"container_id": "4c195cfdbf7e41f640631629970b9af2d8a1f40f63dcffd15edca84e2e2e497e"
},
"kubernetes": {
"container_name": "coredns",
"namespace_name": "kube-system",
"pod_name": "coredns-7db6d8ff4d-pddxj",
"container_image": "registry.k8s.io/coredns/coredns:v1.11.1",
"container_image_id": "docker-pullable://registry.k8s.io/coredns/coredns@sha256:1eeb4c7316bacb1d4c8ead65571cd92dd21e27359f0d4917f1a5822a73b75db1",
"pod_id": "38b91d65-ba47-4d0f-a689-711056955842",
"pod_ip": "10.244.0.99",
"host": "minikube",
"labels": {
"k8s-app": "kube-dns",
"pod-template-hash": "7db6d8ff4d"
}
},
"tenx_tag": "kubernetes.var.log.containers.coredns-7db6d8ff4d-pddxj_kube-system_coredns-4c195cfdbf7e41f640631629970b9af2d8a1f40f63dcffd15edca84e2e2e497e.log"
}
Configuration
To configure the k8s Context Extractor module, Edit these settings.
Below is the default configuration from: k8s/config.yaml.
ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogInN0cmluZyIKICAgIH0sCiAgICAidGVueCIgOiB7CiAgICAgICJ0eXBlIiA6ICJzdHJpbmciCiAgICB9LAogICAgIms4cyIgOiB7CiAgICAgICJ0eXBlIiA6ICJvYmplY3QiLAogICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAiZXh0cmFjdG9yTmFtZSIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTmFtZSBvZiBleHRyYWN0b3IgdG8gdXNlIGZvciBrOHMgY29udGV4dCBleHRyYWN0aW9uXG5cbkRlZmluZXMgdGhlIG5hbWUgb2YgdGhlIFtleHRyYWN0b3JdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2V4dHJhY3QvKSB0byB1c2UgZm9yIGs4cyBjb250ZXh0IGV4dHJhY3Rpb24uIFRvIGxlYXJuIG1vcmUgc2VlIFtrOHMgZXh0cmFjdG9yc10oaHR0cHM6Ly9naXRodWIuY29tL2xvZy0xMHgvbW9kdWxlcy9ibG9iL21haW4vcGlwZWxpbmVzL3J1bi9tb2R1bGVzL2luaXRpYWxpemUvazhzL3NldHRpbmdzLnlhbWwpIChEZWZhdWx0OiBmbHVlbnRLOHMpIiwKICAgICAgICAgICJkZWZhdWx0IiA6ICJmbHVlbnRLOHMiCiAgICAgICAgfSwKICAgICAgICAibmFtZXNwYWNlTmFtZUZpZWxkIiA6IHsKICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICJudWxsIgogICAgICAgICAgXSwKICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJLOHMgbmFtZXNwYWNlIHRhcmdldCBmaWVsZCBuYW1lXG5cblNwZWNpZnkgdGhlIGZpZWxkIG5hbWUgdG8gYXNzaWduIHdpdGggdGhlIGV4dHJhY3RlZCBrOHMgW25hbWVzcGFjZV0oaHR0cHM6Ly9rdWJlcm5ldGVzLmlvL2RvY3MvY29uY2VwdHMvb3ZlcnZpZXcvd29ya2luZy13aXRoLW9iamVjdHMvbmFtZXNwYWNlcy8pIChEZWZhdWx0OiBuYW1lc3BhY2UpIiwKICAgICAgICAgICJkZWZhdWx0IiA6ICJuYW1lc3BhY2UiCiAgICAgICAgfSwKICAgICAgICAiY29udGFpbmVyTmFtZUZpZWxkIiA6IHsKICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICJudWxsIgogICAgICAgICAgXSwKICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJLOHMgY29udGFpbmVyIG5hbWUgdGFyZ2V0IGZpZWxkIG5hbWVcblxuU3BlY2lmeSB0aGUgZmllbGQgbmFtZSB0byBhc3NpZ24gd2l0aCB0aGUgZXh0cmFjdGVkIGs4cyBbY29udGFpbmVyIG5hbWVdKGh0dHBzOi8va3ViZXJuZXRlcy5pby9kb2NzL2NvbmNlcHRzL2NvbnRhaW5lcnMvKSAoRGVmYXVsdDogY29udGFpbmVyKSIsCiAgICAgICAgICAiZGVmYXVsdCIgOiAiY29udGFpbmVyIgogICAgICAgIH0sCiAgICAgICAgInBvZE5hbWVGaWVsZCIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiSzhzIHBvZCBuYW1lIHRhcmdldCBmaWVsZCBuYW1lXG5cblNwZWNpZnkgdGhlIGZpZWxkIG5hbWUgdG8gYXNzaWduIHdpdGggdGhlIGV4dHJhY3RlZCBrOHMgW3BvZCBuYW1lXShodHRwczovL2t1YmVybmV0ZXMuaW8vZG9jcy9jb25jZXB0cy93b3JrbG9hZHMvcG9kcy8pIChEZWZhdWx0OiBwb2QpIiwKICAgICAgICAgICJkZWZhdWx0IiA6ICJwb2QiCiAgICAgICAgfQogICAgICB9CiAgICB9CiAgfSwKICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UKfQ==
# 🔟❎ 'run' k8s lookup configuration
# Configure a k8s field extractors to enrich TenXObjects
# To learn more see https://doc.log10x.com/run/initialize/k8s/
# Set the 10x pipeline to 'run'
tenx: run
# =============================== Dependencies ================================
include: run/modules/initialize/k8s
# ============================== Symbol Options ===============================
k8s:
# 'extractorName' specifies which extractor (e.g., fluentK8s/filebeatK8s) to use for k8s metadata extraction
extractorName: fluentK8s # extract k8s context using Fluent schema
# 'namespaceNameField' specifies the name of the field in which to assign an extracted k8 namespace name status code, if found
namespaceNameField: k8s_namespace
# 'containerNameField' specifies the name of the field in which to assign an extracted k8 container name status code, if found
containerNameField: k8s_container
# 'podNameField' specifies the name of the field in which to assign an extracted k8 pod name status code, if found
podNameField: k8s_pod
Options
Specify the options below to configure the k8s Context Extractor:
| Name | Description |
|---|---|
| k8sExtractorName | Name of extractor to use for k8s context extraction |
| k8sNamespaceNameField | K8s namespace target field name |
| k8sContainerNameField | K8s container name target field name |
| k8sPodNameField | K8s pod name target field name |
k8sExtractorName
Name of extractor to use for k8s context extraction.
| Type | Default |
|---|---|
| String | fluentK8s |
Defines the name of the extractor to use for k8s context extraction.
To learn more see k8s extractors.
k8sNamespaceNameField
K8s namespace target field name.
| Type | Default |
|---|---|
| String | namespace |
Specify the field name to assign with the extracted k8s namespace.
k8sContainerNameField
K8s container name target field name.
| Type | Default |
|---|---|
| String | container |
Specify the field name to assign with the extracted k8s container name.
k8sPodNameField
K8s pod name target field name.
| Type | Default |
|---|---|
| String | pod |
Specify the field name to assign with the extracted k8s pod name.
This module is defined in k8s/module.yaml.