Decorative background with logos of Flunetd, Fluent Bit, and Trace

Tracee Now Natively Supports Fluent Bit and Fluentd

Written by Erik Bledsoe in NewsFluent Biton March 14, 2023

Tracee Now Natively Supports Fluent Bit and Fluentd

Easily add eBPF data to your telemetry pipeline

The newest version of Aquasec’s Tracee tool (v0.12.0) now supports sending all events directly to Fluent Bit or Fluentd via the Fluent Forward receiver. This enables Tracee users to take advantage of the Fluent projects’ powerful in-stream processing and filtering capabilities before forwarding the output to any of the dozens of backends supported by the projects. Users familiar with the Fluentd logging driver for Docker will recognize a similar approach.

Last summer, we demonstrated a way to integrate Tracee and Fluent Bit, but that process required us to output the eBPF from Tracee as JSON and forward it to a log file that the Fluent Bit service could then read. With support for the Fluent Forward receiver now native with Tracee, the millions of Fluent users can now easily add eBPF data into their observability efforts, allowing kernel layer insights. You could, for example, send eBPF data through Fluent Bit to Grafana Loki, or even Loki, Elasticsearch, and Splunk all at the same time.

The support for Fluent Forward receiver was made possible by a PR from Calyptia’s senior software engineer Patrick Stephens (@patrick-stephens).

For information on how to configure Tracee to send data to Fluent, check out the Tracee docs. Be aware that Tracee v0.12 includes some breaking changes, so exercise appropriate caution as you begin to explore this new feature.

You might also like

Illustration including logos of Fluent Bit, Slack, and Elastic

Enforcing structured logging across applications using Fluent Bit

In this article, we will leverage Fluent Bit’s log processing capabilities to ensure consistent structured logging across applications using two different methods. In addition, we demonstrate how to send alerts to Slack when the logs are not properly formatted.

Continue reading
Fluent Bit: Alerting via Slack when log destination is unreachable

Fluent Bit: Alerting via Slack when the log destination is unreachable

Learn how to use Fluent Bit to identify irregularities in the data pipeline as they occur and send alerts to Slack

Continue reading
Abstract design

Scaling ARM builds with Actuated

Calyptia fixed its failing Arm builds for open-source Fluent Bit and accelerated our commercial development by adopting Actuated and bare-metal runners.

Continue reading