View live data with Container insights - Azure Monitor (2023)

  • Article

The Live Data feature in Container insights gives you direct access to your Azure Kubernetes Service (AKS) container logs (stdout/stderror), events, and pod metrics. It exposes direct access to kubectl logs -c, kubectl get events, and kubectl top pods. A console pane shows the logs, events, and metrics generated by the container engine to help with troubleshooting issues in real time.

Note

AKS uses Kubernetes cluster-level logging architectures. You can use tools such as Fluentd or Fluent Bit to collect logs.

This article provides an overview of this feature and helps you understand how to use it.

For help with setting up or troubleshooting the Live Data feature, see the Setup guide. This feature directly accesses the Kubernetes API. For more information about the authentication model, see The Kubernetes API.

View AKS resource live logs

To view the live logs for pods, deployments, replica sets, stateful sets, daemon sets, and jobs with or without Container insights from the AKS resource view:

  1. In the Azure portal, browse to the AKS cluster resource group and select your AKS resource.

  2. Select Workloads in the Kubernetes resources section of the menu.

  3. Select a pod, deployment, replica set, stateful set, daemon set, or job from the respective tab.

  4. Select Live Logs from the resource's menu.

  5. Select a pod to start collecting the live data.

View logs

You can view real-time log data as it's generated by the container engine on the Nodes, Controllers, or Containers view. To view log data:

  1. In the Azure portal, browse to the AKS cluster resource group and select your AKS resource.

  2. On the AKS cluster dashboard, under Monitoring on the left side, select Insights.

  3. Select the Nodes, Controllers, or Containers tab.

  4. Select an object from the performance grid. In the Properties pane on the right side, select the Live Logs tab. If the AKS cluster is configured with single sign-on by using Azure Active Directory (Azure AD), you're prompted to authenticate on first use during that browser session. Select your account and finish authentication with Azure.

    Note

    To view the data from your Log Analytics workspace, select View in Log analytics in the Properties pane. The log search results potentially show Nodes, Daemon Sets, Replica Sets, Stateful Sets, Jobs, Cron Jobs, Pods, and Containers. These logs might no longer exist. The log search results for Stateful Sets shows the data for the pods in a stateful set. Attempting to search logs for a container that isn't available in kubectl will also fail here. To learn more about viewing historical logs, events, and metrics, see How to query logs from Container insights.

After successful authentication, if data can be retrieved, it begins streaming to the Live Logs tab. You can view log data here in a continuous stream.

View events

You can view real-time event data as it's generated by the container engine on the Nodes, Controllers, Containers, or Deployments view when a container, pod, node, ReplicaSet, StatefulSet, DaemonSet, job, CronJob, or Deployment is selected. To view events:

  1. In the Azure portal, browse to the AKS cluster resource group and select your AKS resource.

  2. On the AKS cluster dashboard, under Monitoring on the left side, select Insights.

  3. Select the Nodes, Controllers, Containers, or Deployments tab.

  4. Select an object from the performance grid. In the Properties pane on the right side, select the Live Events tab. If the AKS cluster is configured with single sign-on by using Azure AD, you're prompted to authenticate on first use during that browser session. Select your account and finish authentication with Azure.

    Note

    To view the data from your Log Analytics workspace, select View in Log Analytics in the Properties pane. The log search results potentially show Nodes, Daemon Sets, Replica Sets, Stateful Sets, Jobs, Cron Jobs, Pods, and Containers. These logs might no longer exist. The log search results for Stateful Sets shows the data for the pods in a stateful set. Attempting to search logs for a container that isn't available in kubectl will also fail here. To learn more about viewing historical logs, events, and metrics, see How to query logs from Container insights.

After successful authentication, if data can be retrieved, it begins streaming to the Live Events tab.

Filter events

While you view events, you can also limit the results by using the Filter pill found below the search bar. Depending on the resource you select, the pill lists a node, pod, namespace, or cluster to choose from.

View metrics

You can view real-time metric data as it's generated by the container engine from the Nodes or Controllers view only when a Pod is selected. To view metrics:

  1. In the Azure portal, browse to the AKS cluster resource group and select your AKS resource.

  2. On the AKS cluster dashboard, under Monitoring on the left side, select Insights.

  3. Select either the Nodes or Controllers tab.

  4. Select a Pod object from the performance grid. In the Properties pane on the right side, select the Live Metrics tab. If the AKS cluster is configured with single sign-on by using Azure AD, you're prompted to authenticate on first use during that browser session. Select your account and finish authentication with Azure.

    Note

    To view the data from your Log Analytics workspace, select the View in Log Analytics option in the Properties pane. The log search results potentially show Nodes, Daemon Sets, Replica Sets, Stateful Sets, Jobs, Cron Jobs, Pods, and Containers. These logs might no longer exist. The log search results for Stateful Sets shows the data for the pods in a stateful set. Attempting to search logs for a container that isn't available in kubectl will also fail here. To learn more about viewing historical logs, events, and metrics, see How to query logs from Container insights.

After successful authentication, metric data is retrieved and begins streaming to the Live Metrics tab for presentation in the two charts.

Use live data views

The following sections describe functionality that you can use in the different live data views.

Search

The Live Data feature includes search functionality. In the Search box, you can filter results by entering a keyword or term. Any matching results are highlighted to allow quick review. While you view the events, you can also limit the results by using the Filter feature below the search bar. Depending on what resource you've selected, you can choose from a node, pod, namespace, or cluster.

Scroll lock and pause

To suspend autoscroll and control the behavior of the tab so that you can manually scroll through the new data read, select the Scroll option. To re-enable autoscroll, select Scroll again. You can also pause retrieval of log or event data by selecting the Pause option. When you're ready to resume, select Play.

Suspend or pause autoscroll for only a short period of time while you're troubleshooting an issue. These requests might affect the availability and throttling of the Kubernetes API on your cluster.

Important

No data is stored permanently during the operation of this feature. All information captured during the session is deleted when you close your browser or navigate away from it. Data only remains present for visualization inside the five-minute window of the metrics feature. Any metrics older than five minutes are also deleted. The Live Data buffer queries within reasonable memory usage limits.

Next steps

  • To continue learning how to use Azure Monitor and monitor other aspects of your AKS cluster, see View Azure Kubernetes Service health.
  • To see predefined queries and examples to create alerts and visualizations or perform further analysis of your clusters, see How to query logs from Container insights.
Top Articles
Latest Posts
Article information

Author: Lakeisha Bayer VM

Last Updated: 02/10/2023

Views: 5537

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Lakeisha Bayer VM

Birthday: 1997-10-17

Address: Suite 835 34136 Adrian Mountains, Floydton, UT 81036

Phone: +3571527672278

Job: Manufacturing Agent

Hobby: Skimboarding, Photography, Roller skating, Knife making, Paintball, Embroidery, Gunsmithing

Introduction: My name is Lakeisha Bayer VM, I am a brainy, kind, enchanting, healthy, lovely, clean, witty person who loves writing and wants to share my knowledge and understanding with you.