PageSourceSearch

https://archive-ce-3-17.netlify.app/assets/js/02b1d1e3.76562b26.js

js archive-ce-3-17.netlify.app collected 2026-10-03 10:28:54 UTC 17,510 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["1749"],{97377:function(e,n,r){r.r(n),r.d(n,{default:()=>h,frontMatter:()=>a,metadata:()=>t,assets:()=>d,toc:()=>u,contentTitle:()=>c});var t=JSON.parse('{"id":"visibility/elastic/archive-storage","title":"Archive logs","description":"Archive logs to Syslog, Splunk, or Amazon S3 for maintaining compliance data.","source":"@site/calico-enterprise_versioned_docs/version-3.17/visibility/elastic/archive-storage.mdx","sourceDirName":"visibility/elastic","slug":"/visibility/elastic/archive-storage","permalink":"/calico-enterprise/3.17/visibility/elastic/archive-storage","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico-enterprise_versioned_docs/version-3.17/visibility/elastic/archive-storage.mdx","tags":[],"version":"3.17","frontMatter":{"description":"Archive logs to Syslog, Splunk, or Amazon S3 for maintaining compliance data."},"sidebar":"calicoEnterpriseSidebar","previous":{"title":"Configure data retention","permalink":"/calico-enterprise/3.17/visibility/elastic/retention"},"next":{"title":"Configure RBAC for Elasticsearch logs and events","permalink":"/calico-enterprise/3.17/visibility/elastic/rbac-elasticsearch"}}'),i=r("85893"),o=r("50065"),l=r("58168"),s=r("97645");let a={description:"Archive logs to Syslog, Splunk, or Amazon S3 for maintaining compliance data."},c="Archive logs",d={},u=[{value:"Big picture",id:"big-picture",level:2},{value:"Value",id:"value",level:2},{value:"Before you begin",id:"before-you-begin",level:2},{value:"How to",id:"how-to",level:2}];function p(e){let n={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,o.a)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(n.header,{children:(0,i.jsx)(n.h1,{id:"archive-logs",children:"Archive logs"})}),"\n","\n",(0,i.jsx)(n.h2,{id:"big-picture",children:"Big picture"}),"\n",(0,i.jsx)(n.p,{children:"Archive Calico Enterprise logs to SIEMs like Syslog, Splunk, or Amazon S3 to meet compliance storage requirements."}),"\n",(0,i.jsx)(n.h2,{id:"value",children:"Value"}),"\n",(0,i.jsx)(n.p,{children:"Archiving your Calico Enterprise Elasticsearch logs to storage services like Amazon S3, Syslog, or Splunk are reliable\noptions for maintaining and consolidating your compliance data long term."}),"\n",(0,i.jsx)(n.h2,{id:"before-you-begin",children:"Before you begin"}),"\n",(0,i.jsx)(n.p,{children:(0,i.jsx)(n.strong,{children:"Supported logs for export"})}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsx)(n.li,{children:"Syslog - flow, dns, idsevents, audit"}),"\n",(0,i.jsx)(n.li,{children:"Splunk - flow, audit, dns"}),"\n",(0,i.jsx)(n.li,{children:"Amazon S3 - l7, flow, dns, audit"}),"\n"]}),"\n",(0,i.jsx)(n.h2,{id:"how-to",children:"How to"}),"\n",(0,i.jsx)(n.admonition,{type:"note",children:(0,i.jsx)(n.p,{children:"Because Calico Enterprise and Kubernetes logs are integral to Calico Enterprise diagnostics, there is no mechanism to tune down the verbosity. To manage log verbosity, filter logs using your SIEM."})}),"\n",(0,i.jsxs)(l.Z,{children:[(0,i.jsx)(s.Z,{label:"Amazon S3",value:"Amazon S3-0",children:(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Create an AWS bucket to store your logs.\
1nYou will need the bucket name, region, key, secret key, and the path in the following steps."}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Create a Secret in the ",(0,i.jsx)(n.code,{children:"tigera-operator"})," namespace named ",(0,i.jsx)(n.code,{children:"log-collector-s3-credentials"})," with the fields ",(0,i.jsx)(n.code,{children:"key-id"})," and ",(0,i.jsx)(n.code,{children:"key-secret"}),".\nExample:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:" kubectl create secret generic log-collector-s3-credentials \\\n --from-literal=key-id=<AWS-access-key-id> \\\n --from-literal=key-secret=<AWS-secret-key> \\\n -n tigera-operator\n"})}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Update the ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.LogCollector",children:"LogCollector"}),"\nresource named, ",(0,i.jsx)(n.code,{children:"tigera-secure"})," to include an ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.S3StoreSpec",children:"S3 section"}),"\nwith your information noted from above.\nExample:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-yaml",children:"apiVersion: operator.tigera.io/v1\nkind: LogCollector\nmetadata:\n  name: tigera-secure\nspec:\n  additionalStores:\n    s3:\n      bucketName: <S3-bucket-name>\n      bucketPath: <path-in-S3-bucket>\n      region: <S3-bucket region>\n"})}),"\n",(0,i.jsx)(n.p,{children:"This can be done during installation by editing the custom-resources.yaml\nby applying it, or after installation by editing the resource with the command:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"kubectl edit logcollector tigera-secure\n"})}),"\n"]}),"\n"]})}),(0,i.jsxs)(s.Z,{label:"Syslog",value:"Syslog-1",children:[(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Update the ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.LogCollector",children:"LogCollector"}),"\nresource named ",(0,i.jsx)(n.code,{children:"tigera-secure"})," to include a ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.SyslogStoreSpec",children:"Syslog section"}),"\nwith your syslog information.\nExample:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-yaml",children:"apiVersion: operator.tigera.io/v1\nkind: LogCollector\nmetadata:\n  name: tigera-secure\nspec:\n  additionalStores:\n    syslog:\n      # (Required) Syslog endpoint, in the format protocol://host:port\n      endpoint: tcp://1.2.3.4:514\n      # 
1(Optional) If messages are being truncated set this field\n      packetSize: 1024\n      # (Required) Types of logs to forward to Syslog (must specify at least one option)\n      logTypes:\n      - Audit\n      - DNS\n      - Flows\n      - IDSEvents\n"})}),"\n",(0,i.jsx)(n.p,{children:"This can be done during installation by editing the custom-resources.yaml by applying it or after installation by editing the resource with the command:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"kubectl edit logcollector tigera-secure\n"})}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["You can control which types of Calico Enterprise log data you would like to send to syslog.\nThe ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.SyslogStoreSpec",children:"Syslog section"}),"\ncontains a field called ",(0,i.jsx)(n.code,{children:"logTypes"})," which allows you to list which log types you would like to include.\nThe allowable log types are:"]}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsx)(n.li,{children:"Audit"}),"\n",(0,i.jsx)(n.li,{children:"DNS"}),"\n",(0,i.jsx)(n.li,{children:"Flows"}),"\n",(0,i.jsx)(n.li,{children:"IDSEvents"}),"\n"]}),"\n",(0,i.jsxs)(n.p,{children:["Refer to the ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.SyslogStoreSpec",children:"Syslog section"})," for more details on what data each log type represents."]}),"\n",(0,i.jsx)(n.admonition,{type:"note",children:(0,i.jsxs)(n.p,{children:["The log type ",(0,i.jsx)(n.code,{children:"IDSEvents"})," is only supported for a cluster that has ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.LogStorage",children:"LogStorage"})," configured. It is because intrusion detection event data is pulled from the corresponding LogStorage datastore directly."]})}),"\n",(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"logTypes"})," field is a required, which means you must specify at least one type of log to export to syslog."]}),"\n"]}),"\n"]}),(0,i.jsx)(n.p,{children:(0,i.jsx)(n.strong,{children:"TLS configuration"})}),(0,i.jsxs)(n.ol,{start:"3",children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:['You can enable TLS option for syslog forwarding by including the "encryption" option in the ',(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.SyslogStoreSpec",children:"Syslog section"}),"."]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-yaml",children:"apiVersion: operator.tigera.io/v1\nkind: LogCollector\nmetadata:\n  name: tigera-secure\nspec:\n  additionalStores:\n    syslog:\n      # (Required) Syslog endpoint, in the format protocol://host:port\n      endpoint: tcp://1.2.3.4:514\n      # 
1(Optional) If messages are being truncated set this field\n      packetSize: 1024\n      # (Optional) To Configure TLS mode\n      encryption: TLS\n      # (Required) Types of logs to forward to Syslog (must specify at least one option)\n      logTypes:\n      - Audit\n      - DNS\n      - Flows\n      - IDSEvents\n"})}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsx)(n.p,{children:"Using the self-signed CA with the field name tls.crt, create a configmap in the tigera-operator namespace named, syslog-ca. Example:"}),"\n",(0,i.jsx)(n.admonition,{type:"note",children:(0,i.jsx)(n.p,{children:"Skip this step if publicCA bundle is good enough to verify the server certificates."})}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"kubectl create configmap syslog-ca --from-file=tls.crt -n tigera-operator\n"})}),"\n"]}),"\n"]})]}),(0,i.jsxs)(s.Z,{label:"Splunk",value:"Splunk-2",children:[(0,i.jsx)(n.p,{children:(0,i.jsx)(n.strong,{children:"Support"})}),(0,i.jsxs)(n.p,{children:["In this release, only ",(0,i.jsx)(n.a,{href:"https://www.splunk.com/en_us/products/splunk-enterprise.html",children:"Splunk Enterprise"})," is supported."]}),(0,i.jsxs)(n.p,{children:["Calico Enterprise uses Splunk's ",(0,i.jsx)(n.strong,{children:"HTTP Event Collector"})," to send data to Splunk server. To copy the flow, audit, and dns logs to Splunk, follow these steps:"]}),(0,i.jsxs)(n.ol,{children:["\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Create a HTTP Event Collector token by following the steps listed in Splunk's documentation for your specific Splunk version. Here is the link to do this for ",(0,i.jsx)(n.a,{href:"https://docs.splunk.com/Documentation/Splunk/8.0.0/Data/UsetheHTTPEventCollector",children:"Splunk version 8.0.0"}),"."]}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Create a Secret in the ",(0,i.jsx)(n.code,{children:"tigera-operator"})," namespace named ",(0,i.jsx)(n.code,{children:"logcollector-splunk-credentials"})," with the field ",(0,i.jsx)(n.code,{children:"token"}),".\nExample:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:" kubectl create secret generic logcollector-splunk-credentials \\\n --from-literal=token=<splunk-hec-token> \\\n -n tigera-operator\n"})}),"\n"]}),"\n",(0,i.jsxs)(n.li,{children:["\n",(0,i.jsxs)(n.p,{children:["Update the\n",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.LogCollector",children:"LogCollector"}),"\nresource named ",(0,i.jsx)(n.code,{children:"tigera-secure"})," to include\na ",(0,i.jsx)(n.a,{href:"/calico-enterprise/3.17/reference/installation/api#operator.tigera.io/v1.SplunkStoreSpec",children:"Splunk section"}),"\nwith your Splunk information.\nExample:"]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-yaml",children:"apiVersion: operator.tigera.io/v1\nkind: LogCollector\nmetadata:\n  name: tigera-secure\nspec:\n  additionalStores:\n    splunk:\n       # Splunk HTTP Event Collector endpoint, in the format protocol://host:port\n      endpoint: https://1.2.3.4:8088\n"})}),"\n",(0,i.jsx)(n.p,{children:"This can be done during installation by editing the custom-resources.yaml\nby applying it or after installation by editing the resource with the command:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"kubectl edit logcollector tigera-secure\n"})}),"\n"]}),"\n"]})]})]})]})}function h(e={}){let{wrapper:n}={...(0,o.a)(),...e.components};return n?(0,i.jsx)(n,{...e,children:(0,i.jsx)(p,{...e})}):p(e)}},97645:function(e,n,r){r.d(n,{Z:()=>o});var t=r("85893");r("67294");var i=r("67026");function o(e){let{children:n,hidden:r,className:o}=e;return(0,t.jsx)("div",{role:"tabpanel",className:(0,i.Z)("tabItem_Ymn6",o),hidden:r,children:n})}},58168:function(e,n,r){r.d(n,{Z:()=>y});var t=r("85893"),i=r("67294"),o=r("67026"),l=r("34718"),s=r("16550"),a=r("8714"),c=r("89207"),d=r("69413"),u=r("54510");function p(e){return i.Children.toArray(e).filter(e=>"\n"!==e).map(e=>{if(!e||i.isValidElement(e)&&function(e){let{props:n}=e;return!!n&&"object"==typeof n&&"value"in n}(e))return e;throw Error(`Docusaurus error: Bad <Tabs>
1 child <${"string"==typeof e.type?e.type:e.type.name}>: all children of the <Tabs> component should be <TabItem>, and every <TabItem> should have a unique "value" prop.`)})?.filter(Boolean)??[]}function h(e){let{value:n,tabValues:r}=e;return r.some(e=>e.value===n)}var g=r("6735");function f(e){let{className:n,block:r,selectedValue:i,selectValue:s,tabValues:a}=e,c=[],{blockElementScrollPositionUntilNextRender:d}=(0,l.o5)(),u=e=>{let n=e.currentTarget,r=a[c.indexOf(n)].value;r!==i&&(d(n),s(r))},p=e=>{let n=null;switch(e.key){case"Enter":u(e);break;case"ArrowRight":{let r=c.indexOf(e.currentTarget)+1;n=c[r]??c[0];break}case"ArrowLeft":{let r=c.indexOf(e.currentTarget)-1;n=c[r]??c[c.length-1]}}n?.focus()};return(0,t.jsx)("ul",{role:"tablist","aria-orientation":"horizontal",className:(0,o.Z)("tabs",{"tabs--block":r},n),children:a.map(e=>{let{value:n,label:r,attributes:l}=e;return(0,t.jsx)("li",{role:"tab",tabIndex:i===n?0:-1,"aria-selected":i===n,ref:e=>{c.push(e)},onKeyDown:p,onClick:u,...l,className:(0,o.Z)("tabs__item","tabItem_LNqP",l?.className,{"tabs__item--active":i===n}),children:r??n},n)})})}function m(e){let{lazy:n,children:r,selectedValue:l}=e,s=(Array.isArray(r)?r:[r]).filter(Boolean);if(n){let e=s.find(e=>e.props.value===l);return e?(0,i.cloneElement)(e,{className:(0,o.Z)("margin-top--md",e.props.className)}):null}return(0,t.jsx)("div",{className:"margin-top--md",children:s.map((e,n)=>(0,i.cloneElement)(e,{key:n,hidden:e.props.value!==l}))})}function x(e){let n=function(e){let{defaultValue:n,queryString:r=!1,groupId:t}=e,o=function(e){let{values:n,children:r}=e;return(0,i.useMemo)(()=>{let e=n??p(r).map(e=>{let{props:{value:n,label:r,attributes:t,default:i}}=e;return{value:n,label:r,attributes:t,default:i}});return!function(e){let n=(0,d.lx)(e,(e,n)=>e.value===n.value);if(n.length>0)throw Error(`Docusaurus error: Duplicate values "${n.map(e=>e.value).join(", ")}" found in <Tabs>. Every value needs to be unique.`)}(e),e},[n,r])}(e),[l,g]=(0,i.useState)(()=>(function(e){let{defaultValue:n,tabValues:r}=e;if(0===r.length)throw Error("Docusaurus error: the <Tabs> component requires at least one <TabItem> children component");if(n){if(!h({value:n,tabValues:r}))throw Error(`Docusaurus error: The <Tabs> has a defaultValue "${n}" but none of its children has the corresponding value. Available values are: ${r.map(e=>e.value).join(", ")}. If you intend to show no default tab, use defaultValue={null} instead.`);return n}let t=r.find(e=>e.default)??r[0];if(!t)throw Error("Unexpected error: 0 tabValues");return t.value})({defaultValue:n,tabValues:o})),[f,m]=function(e){let{queryString:n=!1,groupId:r}=e,t=(0,s.k6)(),o=function(e){let{queryString:n=!1,groupId:r}=e;if("string"==typeof n)return n;if(!1===n)return null;if(!0===n&&!r)throw Error('Docusaurus error: The <Tabs> component groupId prop is required if queryString=true, because this value is used as the search param name. You can also provide an explicit value such as queryString="my-search-param".');return r??null}({queryString:n,groupId:r});return[(0,c._X)(o),(0,i.useCallback)(e=>{if(!o)return;let n=new URLSearchParams(t.location.search);n.set(o,e),t.replace({...t.location,search:n.toString()})},[o,t])]}({queryString:r,groupId:t}),[x,y]=function(e){let{groupId:n}=e,r=n?`docusaurus.tab.${n}`:null,[t,o]=(0,u.Nk)(r);return[t,(0,i.useCallback)(e=>{r&&o.set(e)},[r,o])]}({groupId:t}),j=(()=>{let e=f??x;return h({value:e,tabValues:o})?e:null})();return(0,a.Z)(()=>{j&&g(j)},[j]),{selectedValue:l,selectValue:(0,i.useCallback)(e=>{if(!h({value:e,tabValues:o}))throw Error(`Can't select invalid tab value=${e}`);g(e),m(e),y(e)},[m,y,o]),tabValues:o}}(e);return(0,t.jsxs)("div",{className:(0,o.Z)("tabs-container","tabList__CuJ"),children:[(0,t.jsx)(f,{...n,...e}),(0,t.jsx)(m,{...n,...e})]})}function y(e){let n=(0,g.Z)();return(0,t.jsx)(x,{...e,children:p(e.children)},String(n))}},50065:function(e,n,r){r.d(n,{Z:function(){return s},a:function(){return l}});var t=r(67294);let i={},o=t.createContext(i);function l(e){let n=t.useContext(o);return t.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function s(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:l(e.components),t.createElement(o.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.