SAP Cloud Logging - Kyma Runtime Ingestion Reference
Source: https://github.com/SAP-docs/btp-cloud-logging/blob/main/docs/ingest-via-kyma-runtime-612c7b9.md Last Updated: 2025-11-22
Overview
Kyma's Telemetry module enables shipping observability signals (logs, metrics, traces) to SAP Cloud Logging instances. Each signal type can be configured independently.
Prerequisites
SAP BTP Kyma Runtime with the following modules enabled:
telemetrymodulebtp-operatormodule
Kubernetes CLI (kubectl) version 1.23 or higher
SAP Cloud Logging Instance with OpenTelemetry API enabled (for distributed traces):
{ "ingest_otlp": { "enabled": true } }
Security Notice
Review SAP BTP Security Recommendation BTP-CLS-0003 for Kyma runtime security configuration.
Recommended Setup
Create the Cloud Logging instance using SAP BTP Service Operator for automatic Secret creation and rotation.
Step 1: Create Namespace
kubectl create namespace sap-cloud-logging-integrationStep 2: Deploy ServiceInstance
# cls-instance.yaml
apiVersion: services.cloud.sap.com/v1
kind: ServiceInstance
metadata:
name: cloud-logging-instance
namespace: sap-cloud-logging-integration
spec:
serviceOfferingName: cloud-logging
servicePlanName: standard
externalName: my-cls-instance
parameters:
retentionPeriod: 14
ingest_otlp:
enabled: truekubectl apply -n sap-cloud-logging-integration -f cls-instance.yamlStep 3: Deploy ServiceBinding
# cls-binding.yaml
apiVersion: services.cloud.sap.com/v1
kind: ServiceBinding
metadata:
name: cls-binding
namespace: sap-cloud-logging-integration
spec:
serviceInstanceName: cloud-logging-instance
secretName: sap-cloud-loggingkubectl apply -n sap-cloud-logging-integration -f cls-binding.yamlStep 4: Verify Deployment
# Check ServiceInstance status
kubectl get serviceinstance -n sap-cloud-logging-integration
# Check ServiceBinding status
kubectl get servicebinding -n sap-cloud-logging-integration
# Verify secret creation
kubectl get secret sap-cloud-logging -n sap-cloud-logging-integrationConfigure Telemetry Module
Follow Kyma documentation for shipping from Kyma to SAP Cloud Logging:
LogPipeline Configuration
apiVersion: telemetry.kyma-project.io/v1alpha1
kind: LogPipeline
metadata:
name: cls-logs
spec:
output:
http:
host:
valueFrom:
secretKeyRef:
name: sap-cloud-logging
namespace: sap-cloud-logging-integration
key: ingest-endpoint
tls:
cert:
valueFrom:
secretKeyRef:
name: sap-cloud-logging
namespace: sap-cloud-logging-integration
key: ingest-mtls-cert
key:
valueFrom:
secretKeyRef:
name: sap-cloud-logging
namespace: sap-cloud-logging-integration
key: ingest-mtls-keyTracePipeline Configuration
apiVersion: telemetry.kyma-project.io/v1alpha1
kind: TracePipeline
metadata:
name: cls-traces
spec:
output:
otlp:
endpoint:
valueFrom:
secretKeyRef:
name: sap-cloud-logging
namespace: sap-cloud-logging-integration
key: ingest-otlp-endpoint
tls:
cert:
valueFrom:
secretKeyRef:
name: sap-cloud-logging
namespace: sap-cloud-logging-integration
key: ingest-otlp-cert
key:
valueFrom:
secretKeyRef:
name: sap-cloud-logging
namespace: sap-cloud-logging-integration
key: ingest-otlp-keyIndex Patterns
| Data Type | Index Pattern |
|---|---|
| Istio Access Logs | logs-json-istio-envoy-kyma* |
| Application Logs | logs-json-kyma* |
| OTLP Logs | logs-otel-v1-* |
| OTLP Metrics | metrics-otel-v1-* |
| OTLP Traces | otel-v1-apm-span-* |
Credential Sharing Across Clusters
If you need to share Cloud Logging credentials across multiple Kyma/Kubernetes clusters:
Step 1: Extract Credentials
# Get all credentials from service binding secret
kubectl get secret sap-cloud-logging -n sap-cloud-logging-integration -o yamlStep 2: Create Secret in Target Cluster
apiVersion: v1
kind: Secret
metadata:
name: sap-cloud-logging
namespace: sap-cloud-logging-integration
type: Opaque
data:
# Copy all keys from source secret
ingest-endpoint: <base64-encoded>
ingest-mtls-cert: <base64-encoded>
ingest-mtls-key: <base64-encoded>
ingest-otlp-endpoint: <base64-encoded>
ingest-otlp-cert: <base64-encoded>
ingest-otlp-key: <base64-encoded>
server-ca: <base64-encoded>Important: When sharing credentials:
- Credential rotation is your responsibility
- Rotate credentials more frequently than every 24 hours is not recommended
- Monitor certificate expiration dates
Credential Rotation
When using BTP Service Operator, credential rotation can be automated:
apiVersion: services.cloud.sap.com/v1
kind: ServiceBinding
metadata:
name: cls-binding
namespace: sap-cloud-logging-integration
spec:
serviceInstanceName: cloud-logging-instance
secretName: sap-cloud-logging
credentialsRotationPolicy:
enabled: true
rotationFrequency: "720h" # 30 daysTroubleshooting
Logs Not Appearing
Check LogPipeline status:
kubectl get logpipeline cls-logs -o yamlVerify Telemetry module is running:
kubectl get pods -n kyma-system | grep telemetryCheck secret references are correct
Traces Not Appearing
- Ensure
ingest_otlp.enabled: truein Cloud Logging instance - Check TracePipeline status
- Verify application is instrumented for tracing
Certificate Errors
- Check certificate validity in secret
- Verify
server-cais included if required - Consider rotating credentials
Maintenance
Parameter Updates
Modify YAML and reapply:
kubectl apply -n sap-cloud-logging-integration -f cls-instance.yamlInstance Limitation
Important: Instances created with SAP BTP Operator can only be managed from SAP BTP Operator. You cannot manage these instances via BTP Cockpit or CLI.
Documentation Links
- Source: https://raw.githubusercontent.com/SAP-docs/btp-cloud-logging/main/docs/ingest-via-kyma-runtime-612c7b9.md
- Kyma Telemetry Module: https://kyma-project.io/#/telemetry-manager/user/README
- BTP Service Operator: https://github.com/SAP/sap-btp-service-operator
- Security Recommendations: https://help.sap.com/docs/btp/sap-btp-security-recommendations-c8a9bb59fe624f0981efa0eff2497d7d/sap-btp-security-recommendations