A company is implementing a new microservices architecture on AWS, using Amazon EKS for container orchestration. They need to monitor container logs and performance metrics to detect anomalies and potential security threats. The solution must be able to collect logs from multiple containers, forward them to a centralized logging system, and allow for real-time analysis. Which approach effectively addresses these requirements?
- ADeploy a Fluent Bit DaemonSet in the EKS cluster to send logs to CloudWatch Logs, and use CloudWatch Container Insights for performance metrics.
- BImplement a custom logging agent on each EC2 instance running EKS nodes to scrape logs and push them to Amazon Kinesis Data Streams for processing.
- CConfigure each container to write logs to an Amazon S3 bucket directly, and use S3 Event Notifications to trigger a Lambda function for analysis.
- DUtilize AWS CloudTrail to monitor EKS control plane logs and set up alarms for suspicious API calls related to containers.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploy a Fluent Bit DaemonSet in the EKS cluster to send logs to CloudWatch Logs, and use CloudWatch Container Insights for performance metrics.
Deploying Fluent Bit as a DaemonSet in EKS is a common and effective pattern for collecting container logs. Fluent Bit is lightweight and can forward logs to CloudWatch Logs. CloudWatch Container Insights specifically provides performance monitoring and diagnostic data for containerized applications, including EKS, offering a comprehensive monitoring solution.
Why the other options are wrong
- B. Implementing a custom logging agent on each EC2 instance is less managed and more burdensome than using a DaemonSet within EKS for container-specific logs. Kinesis Data Streams is for general streaming, but Fluent Bit + CloudWatch Logs/Container Insights is more tailored for EKS logs and metrics.
- C. Directly writing logs to S3 from each container is inefficient and complex to manage at scale, lacking real-time stream processing and performance metrics for containers.
- D. CloudTrail monitors EKS control plane API calls, which is important for security, but it does not collect container-level application logs or performance metrics from within the containers themselves.
EKS Container Logging & Monitoring
Using Fluent Bit DaemonSet for log collection and CloudWatch Logs/Container Insights for centralized logging and performance metrics for Amazon EKS.
- Fluent Bit is a lightweight log processor.
- DaemonSet ensures Fluent Bit runs on every EKS node.
- CloudWatch Logs provides centralized log storage and analysis.
- CloudWatch Container Insights offers specialized metrics for EKS.
Memory trick: Fluent Bit gathers container's chatter, CloudWatch Insights shows what truly matters.