Skip to main content
Calico Enterprise 3.19 (latest) documentation

Observability and troubleshooting

See what's going on in your cluster with network observability tools and detailed logging.

Getting started

Manager UI tutorial

Tour the main features of Manager UI.

Manage alerts

Manage alerts and events for Calico Enterprise features.

Kibana dashboards and logs

Learn the basics of using Elasticsearch logs and Kibana to gain visibility and troubleshoot.

Packet capture

Capture live traffic for debugging microservices and application interaction.

Network visualization

Learn the power of network sets.

Getting started with logs

Overview

Summary of the out-of-box features for Calico Enterprise logs.

Configure data retention

Configure how long to retain logs and compliance reports.

Archive logs

Archive logs to Syslog, Splunk, or Amazon S3 for maintaining compliance data.

Overview

Summary of the out-of-box features for Calico Enterprise logs.

Configure RBAC for Elasticsearch logs and events

Configure RBAC to control access to Elasticsearch logs and events.

BGP logs

Key/value pairs of BGP activity logs and how to construct queries.

Audit logs

Calico Enterprise audit logs provide data on changes to resources.

Flow logs

Flow log data types

Data that Calico Enterprise sends to Elasticsearch.

Filter flow logs

Filter Calico Enterprise flow logs.

Configure flow log aggregation

Configure flow log aggregation to reduce log volume and costs.

Enable HostEndpoint reporting in flow logs

Enable hostendpoint reporting in flow logs.

Enable process-level information in flow logs

Get visibility into process-level network activity in flow logs.

Enabling TCP socket stats in flow logs

Enabling TCP socket stats information in flow logs

DNS logs

Configure DNS logs

Key/value pairs of DNS activity logs and how to construct queries.

Filter DNS logs

Suppress DNS logs of low significance using filters.

L7 logs

Configure L7 logs

Configure and aggregate L7 logs.

L7 log data types

L7 data that Calico Enterprise sends to Elasticsearch.