All skills
secondsky avatar

/sap-btp-cloud-logging

@620a19a
by Eddiesecondsky/sap-skills456 stars
120

This skill provides comprehensive guidance for SAP Cloud Logging service on SAP BTP. Use when setting up Cloud Logging instances, configuring log ingestion from Cloud Foundry or Kyma runtimes, implementing OpenTelemetry observability, analyzing logs/metrics/traces in OpenSearch Dashboards, configuring SAML authentication, managing certificates, or troubleshooting ingestion issues. Covers service plans (dev/standard/large), all 4 instance creation methods (BTP Cockpit, CF CLI, BTP CLI, Service Operator), all 4 ingestion methods (Cloud Foundry, Kyma, OpenTelemetry, JSON API), and security best practices.

Use this Skill: https://skilld.dev/gh/secondsky/sap-skills/sap-btp-cloud-logging

This session only. Nothing lands on disk.

referenceskyma-ingestion.md

≈1.8k tokens on demand. Your agent reads this file only when SKILL.md points to it.

SAP Cloud Logging - Kyma Runtime Ingestion Reference

Source: https://github.com/SAP-docs/btp-cloud-logging/blob/main/docs/ingest-via-kyma-runtime-612c7b9.md Last Updated: 2025-11-22


Overview

Kyma's Telemetry module enables shipping observability signals (logs, metrics, traces) to SAP Cloud Logging instances. Each signal type can be configured independently.


Prerequisites

  1. SAP BTP Kyma Runtime with the following modules enabled:

    • telemetry module
    • btp-operator module
  2. Kubernetes CLI (kubectl) version 1.23 or higher

  3. SAP Cloud Logging Instance with OpenTelemetry API enabled (for distributed traces):

    {
      "ingest_otlp": {
        "enabled": true
      }
    }

Security Notice

Review SAP BTP Security Recommendation BTP-CLS-0003 for Kyma runtime security configuration.


Recommended Setup

Create the Cloud Logging instance using SAP BTP Service Operator for automatic Secret creation and rotation.

Step 1: Create Namespace

kubectl create namespace sap-cloud-logging-integration

Step 2: Deploy ServiceInstance

# cls-instance.yaml
apiVersion: services.cloud.sap.com/v1
kind: ServiceInstance
metadata:
  name: cloud-logging-instance
  namespace: sap-cloud-logging-integration
spec:
  serviceOfferingName: cloud-logging
  servicePlanName: standard
  externalName: my-cls-instance
  parameters:
    retentionPeriod: 14
    ingest_otlp:
      enabled: true
kubectl apply -n sap-cloud-logging-integration -f cls-instance.yaml

Step 3: Deploy ServiceBinding

# cls-binding.yaml
apiVersion: services.cloud.sap.com/v1
kind: ServiceBinding
metadata:
  name: cls-binding
  namespace: sap-cloud-logging-integration
spec:
  serviceInstanceName: cloud-logging-instance
  secretName: sap-cloud-logging
kubectl apply -n sap-cloud-logging-integration -f cls-binding.yaml

Step 4: Verify Deployment

# Check ServiceInstance status
kubectl get serviceinstance -n sap-cloud-logging-integration

# Check ServiceBinding status
kubectl get servicebinding -n sap-cloud-logging-integration

# Verify secret creation
kubectl get secret sap-cloud-logging -n sap-cloud-logging-integration

Configure Telemetry Module

Follow Kyma documentation for shipping from Kyma to SAP Cloud Logging:

LogPipeline Configuration

apiVersion: telemetry.kyma-project.io/v1alpha1
kind: LogPipeline
metadata:
  name: cls-logs
spec:
  output:
    http:
      host:
        valueFrom:
          secretKeyRef:
            name: sap-cloud-logging
            namespace: sap-cloud-logging-integration
            key: ingest-endpoint
      tls:
        cert:
          valueFrom:
            secretKeyRef:
              name: sap-cloud-logging
              namespace: sap-cloud-logging-integration
              key: ingest-mtls-cert
        key:
          valueFrom:
            secretKeyRef:
              name: sap-cloud-logging
              namespace: sap-cloud-logging-integration
              key: ingest-mtls-key

TracePipeline Configuration

apiVersion: telemetry.kyma-project.io/v1alpha1
kind: TracePipeline
metadata:
  name: cls-traces
spec:
  output:
    otlp:
      endpoint:
        valueFrom:
          secretKeyRef:
            name: sap-cloud-logging
            namespace: sap-cloud-logging-integration
            key: ingest-otlp-endpoint
      tls:
        cert:
          valueFrom:
            secretKeyRef:
              name: sap-cloud-logging
              namespace: sap-cloud-logging-integration
              key: ingest-otlp-cert
        key:
          valueFrom:
            secretKeyRef:
              name: sap-cloud-logging
              namespace: sap-cloud-logging-integration
              key: ingest-otlp-key

Index Patterns

Data Type Index Pattern
Istio Access Logs logs-json-istio-envoy-kyma*
Application Logs logs-json-kyma*
OTLP Logs logs-otel-v1-*
OTLP Metrics metrics-otel-v1-*
OTLP Traces otel-v1-apm-span-*

Credential Sharing Across Clusters

If you need to share Cloud Logging credentials across multiple Kyma/Kubernetes clusters:

Step 1: Extract Credentials

# Get all credentials from service binding secret
kubectl get secret sap-cloud-logging -n sap-cloud-logging-integration -o yaml

Step 2: Create Secret in Target Cluster

apiVersion: v1
kind: Secret
metadata:
  name: sap-cloud-logging
  namespace: sap-cloud-logging-integration
type: Opaque
data:
  # Copy all keys from source secret
  ingest-endpoint: <base64-encoded>
  ingest-mtls-cert: <base64-encoded>
  ingest-mtls-key: <base64-encoded>
  ingest-otlp-endpoint: <base64-encoded>
  ingest-otlp-cert: <base64-encoded>
  ingest-otlp-key: <base64-encoded>
  server-ca: <base64-encoded>

Important: When sharing credentials:

  • Credential rotation is your responsibility
  • Rotate credentials more frequently than every 24 hours is not recommended
  • Monitor certificate expiration dates

Credential Rotation

When using BTP Service Operator, credential rotation can be automated:

apiVersion: services.cloud.sap.com/v1
kind: ServiceBinding
metadata:
  name: cls-binding
  namespace: sap-cloud-logging-integration
spec:
  serviceInstanceName: cloud-logging-instance
  secretName: sap-cloud-logging
  credentialsRotationPolicy:
    enabled: true
    rotationFrequency: "720h"  # 30 days

Troubleshooting

Logs Not Appearing

  1. Check LogPipeline status:

    kubectl get logpipeline cls-logs -o yaml
  2. Verify Telemetry module is running:

    kubectl get pods -n kyma-system | grep telemetry
  3. Check secret references are correct

Traces Not Appearing

  1. Ensure ingest_otlp.enabled: true in Cloud Logging instance
  2. Check TracePipeline status
  3. Verify application is instrumented for tracing

Certificate Errors

  1. Check certificate validity in secret
  2. Verify server-ca is included if required
  3. Consider rotating credentials

Maintenance

Parameter Updates

Modify YAML and reapply:

kubectl apply -n sap-cloud-logging-integration -f cls-instance.yaml

Instance Limitation

Important: Instances created with SAP BTP Operator can only be managed from SAP BTP Operator. You cannot manage these instances via BTP Cockpit or CLI.


Documentation Links

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides operational guidance for SAP BTP Cloud Logging, including setup instructions, CLI commands, and telemetry configuration. It identifies an inherent surface for indirect prompt injection through the ingestion of external log data.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    8/10 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 620a19a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 weeks ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "maintainer": "Eduard Jiglau",
  "maintainer_email": "hello@sap-ai-skills.com",
  "website": "https://sap-ai-skills.com",
  "version": "2.4.1",
  "last_verified": "2025-11-27",
  "source_documentation": "https://github.com/SAP-docs/btp-cloud-logging",
  "sap_help_portal": "https://help.sap.com/docs/cloud-logging"
}

README badge

README badge for secondsky/sap-skills/sap-btp-cloud-logging