Calico Flow Log Requirements for Pod-Level Traffic Visibility in VMware Aria Operations for Networks (vRNI)
search cancel

Calico Flow Log Requirements for Pod-Level Traffic Visibility in VMware Aria Operations for Networks (vRNI)

book

Article ID: 418962

calendar_today

Updated On:

Products

VMware Telco Cloud Platform

Issue/Introduction

Users may inquire whether it is necessary to enable Calico network flow logs to achieve visibility into pod-to-pod traffic flows within a Kubernetes cluster. Specifically, administrators may seek confirmation on:

  • Whether Calico flow logs can be enabled to capture pod-level traffic.
  • Whether VMware Aria Operations for Networks (formerly vRealize Network Insight / vRNI) requires these specific logs to analyze and visualize Kubernetes traffic.
  • The configuration steps to enable Calico flow logs if they are required for this integration.

Environment

TCA 3.2
TKG 2.5.2
vRNI 6.10.0.1692934256

Cause

There is often confusion regarding the data sources VMware Aria Operations for Networks utilizes for Kubernetes visibility. While Calico is a common CNI that generates its own flow logs, Aria Operations for Networks relies on its own collectors (such as the K8s Collector or IPFIX flows from the underlying infrastructure) rather than ingesting third-party CNI-specific log formats.

Resolution

  1. Enabling Calico flow logs is not necessary for VMware Aria Operations for Networks to analyze and visualize pod-to-pod traffic.
  2. VMware Aria Operations for Networks does not rely on Calico flow logs for traffic analysis.
  3. Aria Operations for Networks does not currently support the ingestion or processing of native Calico flow logs.
  4. It is recommended to rely on the standard data collection methods provided by the Aria Operations for Networks Kubernetes Collector for traffic visibility.

Additional Information

For details refer to the VMware Aria Operations for Networks Installation and Configuration Guide.