⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE Kubernetes Observability & CLI Tooling Core Diagnostics

Q: How do you check Kubernetes pod logs and events?

Practical command toolkit for inspecting Kubernetes pod logs and cluster events: previous container crashes, multi-container pods, real-time log streaming with Stern, and filtering events with JSONPath.

#Kubernetes #kubectl logs #kubectl events #Debugging #Stern #CLI
🎙️ Candidate Opening & Architectural Context
"Checking logs and events is fundamental, but in large-scale production with multi-container pods, crashing containers, and thousands of events, using standard 'kubectl logs' alone is insufficient."
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Mastering Pod Logs (Crashing, Multi-Container, Live Stream)

Essential commands for container log inspection:

  • kubectl logs <pod-name> -f: Real-time stream (follow) of container stdout/stderr.
  • kubectl logs <pod-name> --previous: The crashed container command — inspects logs of the container instance that just crashed before restarting.
  • kubectl logs <pod-name> -c <container-name>: Explicitly targets a container in multi-container pods (e.g. Istio sidecar vs app container).
  • kubectl logs deployment/<app> --all-containers=true --tail=50: Triage all pods in a deployment simultaneously.
  • stern <app-prefix> -n prod --since 15m: Cross-pod color-coded log aggregator that tails all pods matching a regex even as pods restart.
2️⃣

Mastering Cluster Events (Sorting, Filtering & Warning Triage)

Events explain WHY pods are failing, evicted, or unschedulable:

  • kubectl get events -n <ns> --sort-by='.metadata.creationTimestamp': Chronological event timeline of recent cluster occurrences.
  • kubectl get events --field-selector type=Warning -n <ns>: Filters noise to show only warnings (FailedScheduling, Unhealthy, FailedMount, BackOff).
  • kubectl events -n <ns>: Modern K8s 1.23+ dedicated command with clean human-readable table formatting.
  • kubectl get events --field-selector involvedObject.name=<pod-name>: Filters events tied strictly to a specific pod.
3️⃣

Deep Debugging: Ephemeral Containers & Node Logs

When container logs are silent or container won't run:

  • kubectl debug -it <pod-name> --image=nicolaka/netshoot --target=<app>: Attaches an ephemeral container with tcpdump, curl, and dig sharing the pod's network and process namespace.
  • Node kubelet logs: If the node itself is unresponsive: journalctl -u kubelet -e on the host.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Always use '--previous' to catch the smoking gun of a crashed container. Filter events by 'type=Warning' to eliminate noise, and leverage 'stern' for multi-pod regex log streaming across autoscaling pods."
⚡ 60-Second Elevator Pitch Talking Points
  • Current logs: 'kubectl logs <pod> -f' (add -c for specific container).
  • Crashed logs: 'kubectl logs <pod> --previous' to see crash stack trace.
  • Multi-pod streaming: Use 'stern <app-pattern>' for live tailing across all replicas.
  • Events: 'kubectl get events -n <ns> --sort-by=.metadata.creationTimestamp' and filter by 'type=Warning'.
  • Zero-downtime debugging: 'kubectl debug' to attach ephemeral netshoot container with diagnostics tools.
Advertisement
Want more Kubernetes scenarios?
Explore our complete collection of scenario-based Kubernetes interview runbooks.
Browse All Kubernetes Questions →

📚 Related Production Scenarios in Kubernetes