# Azure Cloud collect k8s logs

**URL:** <https://discuss.elastic.co/t/azure-cloud-collect-k8s-logs/385512>\
**Category:** Elasticsearch\
**Created:** [March 18, 2026, 10:07pm UTC](https://discuss.elastic.co/t/azure-cloud-collect-k8s-logs/385512 "2026-03-18T22:07:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nnikushkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nnikushkin/32/122950_2.png) [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Post date:** [March 18, 2026, 10:07pm UTC](https://discuss.elastic.co/t/azure-cloud-collect-k8s-logs/385512/1 "2026-03-18T22:07:31Z")

</div>

Hey guys!

What is the recommended way to collect logs from Azure Cloud AKS and deliver them to the desired Elastic instance deployed outside Azure Cloud?

I have already checked this page:

> **[Elastic integrations](https://www.elastic.co/integrations/data-integrations?solution=all-solutions&category=azure)**
>
> Stream in logs, metrics, traces, content, and more from your apps, endpoints, infrastructure, cloud, network, workplace tools, and every other common source in your ecosystem. Send alerts to your noti...

and corresponding integration documentation pages, but did not find the direct answer

Specifically, this page: [Azure Logs Integration | Elastic integrations](https://www.elastic.co/docs/reference/integrations/azure)

I see 2 scenarios:

1. Enable logs collection for containers with redirect to Event Hub on Azure side and setup function to deliver events from Event Hub to my Elastic. It already works this way for AKS metrics collection and the only thing I am missing is container logs
2. Deploy Elastic Agent on Azure Cloud AKS to directly deliver logs to my Elastic instance

Can you please give a hint here to make it more optimal?

Thanks!

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [March 18, 2026, 11:04pm UTC](https://discuss.elastic.co/t/azure-cloud-collect-k8s-logs/385512/2 "2026-03-18T23:04:45Z")

</div>

Hey @nnikushkin

I was actually working on this.  
So when it comes to AKS, you will want to deploy Elastic Agent and leverage the Kubernetes Integration.

In the documentation, [Run Elastic Agent on Azure AKS managed by Fleet | Elastic Docs](https://www.elastic.co/docs/reference/fleet/running-on-aks-managed-by-fleet):

It automatically does collect container logs:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/0/4077bbf5583a12fed5c9bdfa69b7613a5aeec44b.png)

It mentions that you can't capture Audit logs from AKS automatically but you can configure it to send audit logs to an event hub and then set it up via the same K8s integration.

If you see within the integration:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/9/390e62db08d8030337e536259cb79b80976899f0.png)

Best approach is to leverage the elastic agent as much as you can, as it will parse expected fields and works with the dashboards provided.

---

<div class="post-metadata">

**Author:** ![nnikushkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nnikushkin/32/122950_2.png) [@nnikushkin](https://discuss.elastic.co/u/nnikushkin)\
**Post date:** [March 19, 2026, 10:23pm UTC](https://discuss.elastic.co/t/azure-cloud-collect-k8s-logs/385512/3 "2026-03-19T22:23:47Z")

</div>

Hey @erikg !

Thank you for the detailed response!

Indeed, I did not find this nice documentation about using Elastic Agent on AKS + Fleet Server

Gonna give it a try!
