# Collect Logs and Metrics from EKS control plane

**URL:** <https://discuss.elastic.co/t/collect-logs-and-metrics-from-eks-control-plane/246000>\
**Category:** Elastic Observability\
**Created:** [August 22, 2020, 10:52pm UTC](https://discuss.elastic.co/t/collect-logs-and-metrics-from-eks-control-plane/246000 "2020-08-22T22:52:39Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jinkim59](https://avatars.discourse-cdn.com/v4/letter/j/3ab097/32.png) [@jinkim59](https://discuss.elastic.co/u/jinkim59)\
**Post date:** [August 22, 2020, 10:52pm UTC](https://discuss.elastic.co/t/collect-logs-and-metrics-from-eks-control-plane/246000/1 "2020-08-22T22:52:39Z")

</div>

As EKS is a managed AWS Kubernetes service, we can NOT install Elastic agents (FileBeat, MetricBeat, etc.) on a EKS control pane.  
Would you help me for the best way to collect control plane logging and metrics, and index them into Elasticsearch?

I know Amazon EKS control plane logging provides audit and diagnostic logs directly from the Amazon EKS control plane to CloudWatch Logs in my AWS account.  
I guess we can pull logs from CloudWatch into Elasticsearch. But I don't think this is the best approach because the index may not compliant with Elastic Common Schema (ECS) . Also, there are additional cost in utilizing CloudWatch logging.

Therefore, I wonder if there is a better way to directly collect control plane logging and metrics from Kubernetes system to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:11am UTC](https://discuss.elastic.co/t/collect-logs-and-metrics-from-eks-control-plane/246000/2 "2022-11-04T08:11:03Z")

</div>


