# Add on: fluentd

**URL:** <https://discuss.kubernetes.io/t/add-on-fluentd/11262>\
**Category:** microk8s\
**Tags:** docs\
**Created:** [June 4, 2020, 3:12pm UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262 "2020-06-04T15:12:20Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![evilnick](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/evilnick/32/3481_2.png) [@evilnick](https://discuss.kubernetes.io/u/evilnick)\
**Post date:** [June 4, 2020, 3:12pm UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/1 "2020-06-04T15:12:20Z")

</div>

Homepage: **[https://www.fluentd.org/](https://www.fluentd.org/)**  
Supported arch: **amd64**

Enabling this addon will add Elasticsearch, Fluentd and Kibana (the EFK stack) to MicroK8s. The components will be installed and connected together.

To enable the addon:

```bash
microk8s enable fluentd

```

To access the Kibana dashboard on a `v1.21` or newer cluster, point your browser at [http://127.0.0.1:8181](http://127.0.0.1:8181) after forwarding the kibana-logging port:

```bash
microk8s.kubectl port-forward -n kube-system service/kibana-logging 8181:5601

```

On a cluster prior to `v1.21` you should first start the kube proxy service:

```bash
microk8s kubectl proxy

```

The dashboard should be available at:  
[http://127.0.0.1:8001/api/v1/namespaces/kube-system/services/kibana-logging/proxy/app/kibana](http://127.0.0.1:8001/api/v1/namespaces/kube-system/services/kibana-logging/proxy/app/kibana)

Note that you will still need to set up Kibana to track whatever you are  
interested in. For more details see the [official Kibana documentation](https://www.elastic.co/guide/en/kibana/current/discover.html).

The addon can be disabled at any time with the command:

```bash
microk8s disable fluentd

```

---

<div class="post-metadata">

**Author:** ![kirin\_nee](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/kirin_nee/32/6830_2.png) [@kirin\_nee](https://discuss.kubernetes.io/u/kirin_nee)\
**Post date:** [February 1, 2021, 3:45pm UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/2 "2021-02-01T15:45:10Z")

</div>

Hello, How can I configure the fluentd? how can my app access it?

---

<div class="post-metadata">

**Author:** ![gildas](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gildas/32/3770_2.png) [@gildas](https://discuss.kubernetes.io/u/gildas)\
**Post date:** [April 7, 2021, 9:02am UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/3 "2021-04-07T09:02:18Z")

</div>

The proper way to access kibana is actually to do this:

```auto
$ microk8s kubectl cluster-info
Kubernetes control plane is running at https://192.168.1.1:16443
...
Kibana is running at https://192.168.116.50:16443/api/v1/namespaces/kube-system/services/kibana-logging/proxy

To further debug and diagnose cluster problems, use 'kubectl cluster-info dump'.

```

Open the link mentioned in the reply of `cluster-info`.

For this to work, you fist need to modify Kibana’s deployment as the microk8s add-on is wrongly configured:

```auto
$ microk8s kubectl set env deployments.apps kibana-logging \
  SERVER_BASEPATH=/api/v1/namespaces/kube-system/services/kibana-logging/proxy

```

I am not sure if I should modify the wiki or if someone else is responsible for that. Please advise.

---

<div class="post-metadata">

**Author:** ![evilnick](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/evilnick/32/3481_2.png) [@evilnick](https://discuss.kubernetes.io/u/evilnick)\
**Post date:** [April 7, 2021, 9:58am UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/4 "2021-04-07T09:58:30Z")

</div>

@gildas it is published as a wiki so anyone can contribute if you want to. I do check over the additions 🙂  
however, if there is a bug in the deployment we should probably fix that rather than document it @kjackal ?

---

<div class="post-metadata">

**Author:** ![balchua1](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/balchua1/32/5372_2.png) [@balchua1](https://discuss.kubernetes.io/u/balchua1)\
**Post date:** [April 7, 2021, 11:21am UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/5 "2021-04-07T11:21:22Z")

</div>

I use `port-forward` instead.

---

<div class="post-metadata">

**Author:** ![gildas](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gildas/32/3770_2.png) [@gildas](https://discuss.kubernetes.io/u/gildas)\
**Post date:** [April 7, 2021, 3:50pm UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/6 "2021-04-07T15:50:37Z")

</div>

@evilnick, sure, but I don’t want to overstep and break things that were done other ways before (as @balchua1 mentions).

That said, I installed a brand new microk8s and enabled fluentd. The `kubectl proxy` mentioned in the wiki didn’t work. I could see in the web console the pages trying to get js/css resources using the wrong path.  
That’s why I decided to explore the `kubectl cluster-info` method and realized the kibana deployment was just an environment variable away from working.

IMHO, I kind of like the `cluster-info` as I don’t have to remember to run a `kubectl proxy` or `kubectl port-forward` in another shell. Plus, as it is deployed today, the add-on adds kibana in the `cluster-info`, so best to use it.  
The drawback of `cluster-info` lies in the self-signed certificate that modern browsers really do not like.

---

<div class="post-metadata">

**Author:** ![gildas](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/gildas/32/3770_2.png) [@gildas](https://discuss.kubernetes.io/u/gildas)\
**Post date:** [April 7, 2021, 3:52pm UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/7 "2021-04-07T15:52:12Z")

</div>

FYI, we are getting a `404 Not found` atm for [https://microk8s.io/docs/addon-fluentd](https://microk8s.io/docs/addon-fluentd) or even other add-ons.

---

<div class="post-metadata">

**Author:** ![horvatic](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/horvatic/32/7332_2.png) [@horvatic](https://discuss.kubernetes.io/u/horvatic)\
**Post date:** [April 29, 2021, 1:42am UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/8 "2021-04-29T01:42:47Z")

</div>

How heavy is the fluentd stack? Will my pi’s be able to run this load?

---

<div class="post-metadata">

**Author:** ![balchua1](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/balchua1/32/5372_2.png) [@balchua1](https://discuss.kubernetes.io/u/balchua1)\
**Post date:** [April 29, 2021, 2:36am UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/9 "2021-04-29T02:36:43Z")

</div>

Its elastic which is going to be kindda heavy. Whats your rpi specs?

---

<div class="post-metadata">

**Author:** ![horvatic](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/horvatic/32/7332_2.png) [@horvatic](https://discuss.kubernetes.io/u/horvatic)\
**Post date:** [April 29, 2021, 5:06am UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/10 "2021-04-29T05:06:47Z")

</div>

(3x) raspberry pi’s 4, each with 4gb of ram, and 64 gb of space

---

<div class="post-metadata">

**Author:** ![balchua1](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/balchua1/32/5372_2.png) [@balchua1](https://discuss.kubernetes.io/u/balchua1)\
**Post date:** [April 29, 2021, 5:16am UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/11 "2021-04-29T05:16:50Z")

</div>

If you’re not going to index too many logs(few MBs), the default settings configured for elasticsearch seems ok to me.

Here’s what i notice about elasticsearch, it uses a good amount of memory and IO if you’re indexing lots of your logs. Fluentd isn’t that of a resource hog.

In many cases I’ve seen, elastic is often allocated to its own dedicated node. But these are heavily used elastics.

Another option that i tend to use lately is [Loki](https://grafana.com/oss/loki/) The logging stuffs from grafana. A bit less storage needs but also less features unlike a full text search engine like elastic.

---

<div class="post-metadata">

**Author:** ![miah0x41](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/miah0x41/32/12630_2.png) [@miah0x41](https://discuss.kubernetes.io/u/miah0x41)\
**Post date:** [May 28, 2023, 7:09pm UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/12 "2023-05-28T19:09:54Z")

</div>

The link for the following is broken:

> [upstream docs on EFK](https://v1-18.docs.kubernetes.io/docs/tasks/debug-application-cluster/logging-elasticsearch-kibana/)

Is it possible to update?

---

<div class="post-metadata">

**Author:** ![evilnick](https://sea2.discourse-cdn.com/flex016/user_avatar/discuss.kubernetes.io/evilnick/32/3481_2.png) [@evilnick](https://discuss.kubernetes.io/u/evilnick)\
**Post date:** [May 28, 2023, 7:59pm UTC](https://discuss.kubernetes.io/t/add-on-fluentd/11262/13 "2023-05-28T19:59:44Z")

</div>

Thanks for the report @miah0x41 - it seems the upstream docs have had a clearout and no longer document Kibana, so I removed the link. The official docs are still good and there are loads of tutorials for kibana if you do a quick search.
