Decorative background with logos of Flunetd, Fluent Bit, and Trace

Tracee Now Natively Supports Fluent Bit and Fluentd

Written by Erik Bledsoe in NewsFluent Biton March 14, 2023

Tracee Now Natively Supports Fluent Bit and Fluentd

Easily add eBPF data to your telemetry pipeline

The newest version of Aquasec’s Tracee tool (v0.12.0) now supports sending all events directly to Fluent Bit or Fluentd via the Fluent Forward receiver. This enables Tracee users to take advantage of the Fluent projects’ powerful in-stream processing and filtering capabilities before forwarding the output to any of the dozens of backends supported by the projects. Users familiar with the Fluentd logging driver for Docker will recognize a similar approach.

Last summer, we demonstrated a way to integrate Tracee and Fluent Bit, but that process required us to output the eBPF from Tracee as JSON and forward it to a log file that the Fluent Bit service could then read. With support for the Fluent Forward receiver now native with Tracee, the millions of Fluent users can now easily add eBPF data into their observability efforts, allowing kernel layer insights. You could, for example, send eBPF data through Fluent Bit to Grafana Loki, or even Loki, Elasticsearch, and Splunk all at the same time.

The support for Fluent Forward receiver was made possible by a PR from Calyptia’s senior software engineer Patrick Stephens (@patrick-stephens).

For information on how to configure Tracee to send data to Fluent, check out the Tracee docs. Be aware that Tracee v0.12 includes some breaking changes, so exercise appropriate caution as you begin to explore this new feature.

You might also like

Fluent Bit

Statement on CVE-2024-4323 and its fix

We'd like to make sure you’re aware of a security vulnerability (known as CVE-2024-4323) that impacts Fluent Bit versions 2.0.7 through 3.0.3. The latest version of Fluent Bit, version 3.0.4, fixes this issue.

Continue reading
Fluent Bit

Explaining the Fluent Bit processor

Fluent Bit 2.1.2 introduced customization logic for input and output plugins called Processors (not to be confused with the Stream Processor). Here's an example of its use.

Continue reading
Fluent Bit or Fluentd

Fluent Bit and Fluentd – a child or a successor?

Fluent Bit may have started as a sibling to Fluentd, but it is fair to say that it has now grown up and is Fluentd's equal. Learn which is right for your needs and how they can be used together.

Continue reading