Monitoring of OpenShift, Kubernetes & Docker by Outcold

Combine all metrics and logs in Splunk®. With NetDescribe and Outcold Solutions.

Alex Hauptner | Outcold expert at NetDescribe

The Challenge

Monitoring all applications at both the development and system level has become overly complex and unproductive. How can you reduce the effort required for log aggregation, log management, and the collection of diverse metrics while increasing the efficiency of your performance monitoring?
With Outcold Solutions, NetDescribe provides the perfect enhancement for Splunk Enterprise or Splunk Cloud.

Outcold Solutions Features

With Outcold Solutions, you can centrally monitor containerized environments such as Docker, Kubernetes, and OpenShift in Splunk Enterprise and Splunk Cloud. This container-native solution enables efficient collection, processing, and management of logs, metrics, and network data.

Centralized Log Processing and Control
Filter, transform, and control log data streams in real time to forward only relevant information to Splunk and reduce data volumes in a targeted manner.

Flexible Data Processing and Forwarding
Dynamically identify, structure, and route logs with powerful features for adapting to individual requirements and architectures.

Comprehensive Metrics Collection
Collect system and container metrics as well as telemetry data from hosts, containers, and Kubernetes clusters for holistic analysis.

Insights into the Orchestration Layer
Collect metrics from the Kubernetes and OpenShift control planes to precisely monitor the health and performance of your clusters.

Network traffic transparency
Gain visibility into network activity between containers and services to analyze dependencies and communication patterns.

Integrated protection of sensitive data
Mask or remove confidential information directly from log data before it is forwarded or stored.

Outcold Solutions Performance Features

Container Logs

Optimized log collection for containers
Based on the JSON logging driver, you can collect container logs in a structured and reliable manner for further processing in Splunk.

Support for complex log formats
Process multi-line log entries correctly and preserve the full context of events.

Flexible Data Structuring
Define individual sources and extract specific user-defined fields for precise analysis.

Host Logs

Centralized collection of host logs
Collect and analyze system-critical logs, such as Docker daemon and syslog data, centrally in Splunk.

Preconfigured fields and extractions
Take advantage of ready-to-use field definitions for rapid analysis without additional configuration effort.

Monitoring of Cluster Components
Monitor key Kubernetes and OpenShift components with pre-built dashboards and keep an eye on the health of your cluster.

Metrics

Comprehensive metric collection
Collect CPU, memory, network, and storage metrics at the host, pod, and container levels for comprehensive analysis.

Detailed process metrics
Gain deep insights by analyzing process data directly from the proc filesystem.

Correlation of logs and metrics
Link metrics with log data to identify root causes faster and resolve issues efficiently.

Diagnostics

Detection of security-critical configurations
Identify containers with elevated privileges or root access and reduce potential security risks.

Resource and capacity analysis
Monitor resource requirements, limits, and allocations to detect bottlenecks early and optimize cluster utilization.

Outcold Solutions – Rapid Implementation

Ready to use in minutes: With Outcold Solutions, you can implement a comprehensive monitoring solution for your container environment with minimal effort. Logs, system and performance metrics, and telemetry data from the Kubernetes control plane are automatically collected and centrally delivered to Splunk.

Preconfigured dashboards provide immediate insights into network activity and cluster status, while built-in alerting features proactively notify you of performance issues and critical events.

Outcold Solutions Business Benefits

Transparency into Applications and Containers

Gain comprehensive insights into the performance and health of your containerized applications. Detailed metrics from containers, processes, and services enable in-depth analysis, complemented by native support for Prometheus metrics and preconfigured Splunk dashboards.

Efficient Log Processing and Cost Control

Centralize logs from containers, applications, and hosts, and automatically enrich them with container metadata. Through targeted filtering, transformation, and masking of sensitive data (including PII), you forward only relevant information to Splunk.

This reduces data volume, lowers licensing and storage costs, and simultaneously improves the quality of your analyses.

Stable and High-Performance Cluster Operations

Continuously monitor the health of your Kubernetes and OpenShift clusters. Analyze historical events, identify bottlenecks early, and optimize resource allocation and capacity.

Preconfigured alerts help you proactively detect critical conditions and respond quickly.

Security and compliance in the container environment

Enhance the security of your environment with detailed insights into network activity and access structures. Identify containers with elevated privileges and monitor changes to deployments via audit logs.

Granular access controls enable precise management of data access down to the cluster, namespace, or container level.

Reduced Complexity and Increased Productivity

Consolidate log and metric collection into a single, centralized solution to simplify your observability architecture. Developers and platform teams receive exactly the data they need—flexibly controlled via annotations and configurations.

This reduces manual effort, accelerates error analysis, and sustainably increases operational efficiency.

Blog

Interesting Facts from the IT World