BriefingInformationCybersecurityIT

Check every Fluent Bit collector before enabling pod log-exclusion annotations

Can a pod annotation intended for Container Insights also stop another log collector?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseBriefing · 2 min read
Executive summary

What you need to know

Can a pod annotation intended for Container Insights also stop another log collector?

Potentially affected

Supported ConfigMap-based Container Insights deployments sharing pods with another Fluent Bit collection solution.

DSE recommendation

Inventory all collectors that honor the pod's exclusion annotations before using them to reduce one pipeline's output.

Source facts

Container Insights supports Fluent Bit-based pod annotations that exclude container output after annotation filtering is enabled in its ConfigMap. Microsoft warns that an independent Fluent Bit solution using the Kubernetes plugin filter and annotation-based exclusion also stops collecting the annotated logs. The setting is therefore not necessarily exclusive to Container Insights. AKS Automatic clusters with managed system node pools do not support this ConfigMap configuration path. Microsoft Learn.

Applicability

Review supported clusters where more than one collector observes the same workload. Identify which solutions actually honor the annotations rather than assuming that every collector does, or that only the intended one does.

DSE recommendation

Inventory all collectors that honor the pod’s exclusion annotations before using them to reduce one pipeline’s output. Ask each destination owner whether losing those records is acceptable. If one pipeline must retain the data, resolve that requirement with the collector owners before deploying the annotation. Keep the workload manifest and collection configuration in the same review so an application change does not silently remove another team’s evidence.

Verification

Use a test pod with recognizable benign stdout and stderr messages. Inspect the intended destination and every other relevant destination before and after the approved annotation change. Record each collector’s configuration and observed result. Accept the change only when the resulting exclusions match the agreed collection design; reduced volume in Container Insights alone does not verify the other pipeline’s required continuity.

Official references

Microsoft Learn: Container log ConfigMap configuration. Source reviewed September 9, 2026.

Primary reference

Review the official source

Configure container log collection with ConfigMap - Azure Monitor | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE