Edit

Supported logs for microsoft.kubernetes/connectedClusters

The following table lists the types of logs available for the microsoft.kubernetes/connectedClusters resource type.

For a list of supported metrics, see Supported metrics - microsoft.kubernetes/connectedClusters

Category Costs to export Log table Supports basic log plan Supports ingestion-time transformation Example queries
Kubernetes Cloud Controller Manager Yes No No
Kubernetes Cluster Autoscaler Yes No No
csi-aksarcdisk-controller Yes No No
csi-aksarcnfs-controller Yes No No
csi-aksarcsmb-controller Yes No No
guard Yes No No
Kubernetes API Server Yes ArcK8sControlPlane

Contains diagnostic logs for the Kubernetes API Server, Controller Manager, Scheduler, Cluster Autoscaler, Cloud Controller Manager, Guard, and the Azure CSI storage drivers. These diagnostic logs have distinct Category entries corresponding their diagnostic log setting (e.g. kube-apiserver, kube-audit-admin). Requires Diagnostic Settings to use the Resource Specific destination table.

Yes Yes
Kubernetes Audit Yes ArcK8sAudit

Contains all Kubernetes API Server audit logs including events with the get and list verbs. These events are useful for monitoring all of the interactions with the Kubernetes API. To limit the scope to modifying operations see the ArcK8sAuditAdmin table. Requires Diagnostic Settings to use the Resource Specific destination table.

Yes Yes
Kubernetes Audit Admin Logs Yes ArcK8sAuditAdmin

Contains Kubernetes API Server audit logs excluding events with the get and list verbs. These events are useful for monitoring resource modification requests made to the Kubernetes API. To see all modifying and non-modifying operations see the ArcK8sAudit table. Requires Diagnostic Settings to use the Resource Specific destination table.

Yes Yes
Kubernetes Controller Manager Yes No No
Kubernetes Scheduler Yes No No

Next Steps