How to send logs to splunk from Openshift

Solution Verified - Updated -


  • Openshift Container Platform
    • 3.3
    • 3.4
    • 3.5


How to use rsyslog to send logs from Openshift to Splunk.


For 3.4 and up , see this document link :

Specifically the section titled :

Configuring Fluentd to Send Logs to an External Log Aggregator

Splunk integration with Flunetd could be achieved with something like :

Root Cause

For versions earlier then 3.4
We do not support integration for openshift logging into Splunk. It would require some additional plugin. We have an existing RFE on which Engineering team is working.

This solution is part of Red Hat’s fast-track publication program, providing a huge library of solutions that Red Hat engineers have created while supporting our customers. To give you the knowledge you need the instant it becomes available, these articles may be presented in a raw and unedited form.


Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.