Q: How do you check Kubernetes pod logs and events?
Practical command toolkit for inspecting Kubernetes pod logs and cluster events: previous container crashes, multi-container pods, real-time log streaming with Stern, and filtering events with JSONPath.
#Kubernetes #kubectl logs #kubectl events #Debugging #Stern #CLI
🎙️ Candidate Opening & Architectural Context
"Checking logs and events is fundamental, but in large-scale production with multi-container pods, crashing containers, and thousands of events, using standard 'kubectl logs' alone is insufficient."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Mastering Pod Logs (Crashing, Multi-Container, Live Stream)
Essential commands for container log inspection:
kubectl logs <pod-name> -f: Real-time stream (follow) of container stdout/stderr.kubectl logs <pod-name> --previous: The crashed container command — inspects logs of the container instance that just crashed before restarting.kubectl logs <pod-name> -c <container-name>: Explicitly targets a container in multi-container pods (e.g. Istio sidecar vs app container).kubectl logs deployment/<app> --all-containers=true --tail=50: Triage all pods in a deployment simultaneously.stern <app-prefix> -n prod --since 15m: Cross-pod color-coded log aggregator that tails all pods matching a regex even as pods restart.
2️⃣
Mastering Cluster Events (Sorting, Filtering & Warning Triage)
Events explain WHY pods are failing, evicted, or unschedulable:
kubectl get events -n <ns> --sort-by='.metadata.creationTimestamp': Chronological event timeline of recent cluster occurrences.kubectl get events --field-selector type=Warning -n <ns>: Filters noise to show only warnings (FailedScheduling, Unhealthy, FailedMount, BackOff).kubectl events -n <ns>: Modern K8s 1.23+ dedicated command with clean human-readable table formatting.kubectl get events --field-selector involvedObject.name=<pod-name>: Filters events tied strictly to a specific pod.
3️⃣
Deep Debugging: Ephemeral Containers & Node Logs
When container logs are silent or container won't run:
kubectl debug -it <pod-name> --image=nicolaka/netshoot --target=<app>: Attaches an ephemeral container with tcpdump, curl, and dig sharing the pod's network and process namespace.- Node kubelet logs: If the node itself is unresponsive:
journalctl -u kubelet -eon the host.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Always use '--previous' to catch the smoking gun of a crashed container. Filter events by 'type=Warning' to eliminate noise, and leverage 'stern' for multi-pod regex log streaming across autoscaling pods."
⚡ 60-Second Elevator Pitch Talking Points
- Current logs: 'kubectl logs <pod> -f' (add -c for specific container).
- Crashed logs: 'kubectl logs <pod> --previous' to see crash stack trace.
- Multi-pod streaming: Use 'stern <app-pattern>' for live tailing across all replicas.
- Events: 'kubectl get events -n <ns> --sort-by=.metadata.creationTimestamp' and filter by 'type=Warning'.
- Zero-downtime debugging: 'kubectl debug' to attach ephemeral netshoot container with diagnostics tools.
Advertisement