Kubernetes and Cloud Native Associate (KCNA)Cloud Native ObservabilityEasy

A development team is deploying a new microservices application to a Kubernetes cluster. They want to ensure that they can collect structured logs from all their application pods and forward them to a centralized logging system. Which of the following components is primarily responsible for collecting and processing logs from various sources within a Kubernetes cluster before sending them to a storage backend?

  1. ALog shipper (e.g., Fluent Bit)
  2. BKube-proxy
  3. CEtcd
  4. DKubelet
Show answer & explanation

Correct answer: A. Log shipper (e.g., Fluent Bit)

A log shipper like Fluent Bit is specifically designed to collect, parse, and forward logs from various sources, including application containers, within a Kubernetes cluster to a centralized logging system. Kubelet manages pods, Kube-proxy handles network proxying, and Etcd is a distributed key-value store.

Why the other options are wrong

  • B. Kube-proxy maintains network rules and performs service discovery, not log collection.
  • C. Etcd is a distributed key-value store used for Kubernetes cluster state, not for log handling.
  • D. Kubelet is an agent that runs on each node and manages pods, not primarily a log collector.

Log Shipper

A software agent that collects, parses, transforms, and forwards log data from various sources to a centralized logging system for storage and analysis.

  • Runs as a daemonset or sidecar in Kubernetes.
  • Handles log collection from container stdout/stderr, files, etc.
  • Often performs filtering, parsing, and enrichment before forwarding.

Memory trick: Logs from containers need a ship to the cloud.

More Cloud Native Observability questions