apiVersion: v1 kind: ConfigMap metadata: name: fluent-bit-config namespace: fluentbit-system labels: app.kubernetes.io/name: fluent-bit-system data: fluent-bit.conf: | [SERVICE] Flush 1 Log_Level info Daemon off Parsers_File parsers.conf HTTP_Server On HTTP_Listen 0.0.0.0 HTTP_Port 2020 @INCLUDE input-fluentbit.conf @INCLUDE filter-kubernetes.conf @INCLUDE output-splunk.conf @INCLUDE output-elasticsearch.conf input-fluentbit.conf: | [INPUT] Name tail Tag kube.* Path /var/log/containers/*.log DB /var/log/flb_kube.db Parser docker Docker_Mode On Mem_Buf_Limit 50MB Skip_Long_Lines On Refresh_Interval 10 filter-kubernetes.conf: | [FILTER] Name kubernetes Match kube.* Kube_URL https://kubernetes.default.svc.cluster.local:443 Kube_CA_File /var/run/secrets/kubernetes.io/serviceaccount/ca.crt Kube_Token_File /var/run/secrets/kubernetes.io/serviceaccount/token Merge_Log On Buffer_Size 0 Use_Kubelet true Kubelet_Port 10250 output-splunk.conf: | [OUTPUT] Name splunk Match * Host ip-172-23-1-31.ec2.internal Port 8088 TLS On TLS.Verify Off Splunk_Token 57327d3a-5fe4-4089-a1a5-3be1d5ea8dee output-elasticsearch.conf: | [OUTPUT] Name es Match * Host search-emreksanon-3mw7zb2yyuuwlktw4davtyav3u.us-east-1.es.amazonaws.com/ Port 443 TLS On AWS_Auth Off AWS_Region us-east-1 HTTP_User fluentbit HTTP_Passwd EmrLogs123? Retry_Limit 6 parsers.conf: | [PARSER] Name apache Format regex Regex ^(?[^ ]*) [^ ]* (?[^ ]*) \[(?