---
title: Install New Relic eBPF agent for Kubernetes
source: https://docs.newrelic.com/docs/ebpf/k8s-installation
---

You can install the New Relic eBPF agent on your Kubernetes cluster to monitor your entire system health. The eBPF agent provides deep visibility into application performance without requiring code changes or deploying language-specific agents.

## Install the New Relic eBPF agent

### Before you begin [#requirements]

You must meet the prerequisites outlined in the [eBPF compatibility and requirements](https://docs.newrelic.com/docs/ebpf/requirements#k8s) documentation for Kubernetes clusters.

### Install the eBPF agent [#install]

To install the eBPF agent:

1.  Log in to your New Relic account.

2.  Go to **[left navigation pane > + Integration & Agents > eBPF Agent](https://onenr.io/0oR8XWW36RG)**.

3.  On the Select an account screen, select the account you want to install the eBPF agent on, and click **Continue**.

4.  On the Select an installation method page, select **Kubernetes**, and click **Continue**.

5.  On the Enter your user key screen, select one of the following options, then click **Continue**:

    -   **Use an existing key**: If you already have a user key, provide the user key. For more information, refer to [User keys](https://docs.newrelic.com/docs/apis/intro-apis/new-relic-api-keys/#user-key).
    -   **Create a new key**: If you don't have a user key, click **Create a new key** to create one.

6.  On the Configure the Kubernetes integration screen:

    1.  Enter the deployment name for the Kubernetes.
    2.  (Optional) Enter the namespace for the integration. The default namespace is `newrelic`.
    3.  Click **Continue**.

    > #### 💡 TIP
    >
    > If you choose a custom namespace for your New Relic instrumentation (instead of the default `newrelic`), we recommend excluding that namespace from monitoring by adding it to the `allDataFilters.dropNamespaces` configuration parameter. This prevents the eBPF agent from monitoring the instrumentation pods themselves. For example, if you use `newrelic-mon` as your namespace, set: `allDataFilters.dropNamespaces: ["kube-system", "newrelic-mon"]`.

7.  On the Install the Kubernetes integration screen:

    1.  Copy and paste the displayed command to install the eBPF agent on your Kubernetes cluster using Helm.
    2.  (Optional) To download the `values.yaml` configuration file, click **Download**. For more on the configuration parameters, refer to [K8s configuration parameters](#config-params).
    3.  (Optional) Update the `values.yaml` file as needed and save it.
    4.  (Optional) To apply the configuration changes, run the following command:

        ```bash
            helm repo update ; helm upgrade --install nr-ebpf-agent newrelic/nr-ebpf-agent -n newrelic --values values.yaml
        ```
    5.  To verify the installation, run the following command:

        ```bash
            kubectl get pods -n newrelic
        ```

### Access the eBPF data in New Relic [#access-data]

Once the eBPF agent is installed, it automatically starts collecting data from your Linux host. You can access this data in New Relic's OpenTelemetry UI. For more information on New Relic OpenTelemetry UI, refer [OpenTelemetry APM UI](https://docs.newrelic.com/docs/opentelemetry/get-started/apm-monitoring/opentelemetry-apm-ui).

**To view the eBPF data in New Relic:**

1.  Go to **[one.newrelic.com](https://one.newrelic.com) > APM & Services**.
2.  In the search banner, set the search criteria as `instrumentation.name = nr_ebpf`:
    ![eBPF filter for eBPF data in New Relic OpenTelemetry UI](https://docs.newrelic.com/images/ebpf_filters.webp "eBPF filters")

/\*
Once your app is instrumented and configured to export data to New Relic, you should be able to find your data in the New Relic UI:

    \* Find your entity at \*\*All entities > Services - OpenTelemetry\*\*. The entity name is set to the value of the app's \`service.name\` resource attribute. For more information on how New Relic service entities are derived from OpenTelemetry resource attributes, see \[Services](/docs/opentelemetry/best-practices/opentelemetry-best-practices-resources/#services).
    \* Use \[NRQL](/docs/nrql/get-started/introduction-nrql-new-relics-query-language/) to query directly for \[traces](https&#x3A;//one.newrelic.com/launcher/nr1-core.explorer?overlay=eyJuZXJkbGV0SWQiOiJkYXRhLWV4cGxvcmF0aW9uLnF1ZXJ5LWJ1aWxkZXIiLCJpbml0aWFsQWN0aXZlSW50ZXJmYWNlIjoibnJxbEVkaXRvciIsImluaXRpYWxOcnFsVmFsdWUiOiIiLCJpbml0aWFsUXVlcmllcyI6W3sibnJxbCI6IkZST00gU3BhbiBTRUxFQ1QgY291bnQoKikgd2hlcmUgbmV3cmVsaWMuc291cmNlPSclb3RscCUnIFRJTUVTRVJJRVMifV0sImluaXRpYWxDaGFydFNldHRpbmdzIjp7ImNoYXJ0VHlwZSI6IkNIQVJUX0xJTkUiLCJsaW1pdCI6NzU0MiwibGlua2VkRW50aXR5R3VpZCI6bnVsbCwibGlua2VkRGFzaGJvYXJkSWQiOm51bGwsInlTY2FsZSI6eyJzdGF0aWMiOmZhbHNlLCJkb21haW4iOltudWxsLG51bGxdfSwieVplcm8iOnRydWV9fQo=), \[metrics](https&#x3A;//one.newrelic.com/launcher/nr1-core.explorer?overlay=eyJuZXJkbGV0SWQiOiJkYXRhLWV4cGxvcmF0aW9uLnF1ZXJ5LWJ1aWxkZXIiLCJpbml0aWFsQWN0aXZlSW50ZXJmYWNlIjoibnJxbEVkaXRvciIsImluaXRpYWxOcnFsVmFsdWUiOiIiLCJpbml0aWFsUXVlcmllcyI6W3sibnJxbCI6IkZST00gTWV0cmljIFNFTEVDVCBjb3VudCgqKSB3aGVyZSBuZXdyZWxpYy5zb3VyY2UgTElLRSAnJW90bHAlJyBUSU1FU0VSSUVTIn1dLCJpbml0aWFsQ2hhcnRTZXR0aW5ncyI6eyJjaGFydFR5cGUiOiJDSEFSVF9MSU5FIiwibGltaXQiOjc1NDIsImxpbmtlZEVudGl0eUd1aWQiOm51bGwsImxpbmtlZERhc2hib2FyZElkIjpudWxsLCJ5U2NhbGUiOnsic3RhdGljIjpmYWxzZSwiZG9tYWluIjpbbnVsbCxudWxsXX0sInlaZXJvIjp0cnVlfX0K), and \[logs](https&#x3A;//one.newrelic.com/launcher/nr1-core.explorer?overlay=eyJuZXJkbGV0SWQiOiJkYXRhLWV4cGxvcmF0aW9uLnF1ZXJ5LWJ1aWxkZXIiLCJpbml0aWFsQWN0aXZlSW50ZXJmYWNlIjoibnJxbEVkaXRvciIsImluaXRpYWxOcnFsVmFsdWUiOiIiLCJpbml0aWFsUXVlcmllcyI6W3sibnJxbCI6IkZST00gTG9nIFNFTEVDVCBjb3VudCgqKSB3aGVyZSBuZXdyZWxpYy5zb3VyY2U9JyVvdGxwJScgVElNRVNFUklFUyJ9XSwiaW5pdGlhbENoYXJ0U2V0dGluZ3MiOnsiY2hhcnRUeXBlIjoiQ0hBUlRfTElORSIsImxpbWl0Ijo3NTQyLCJsaW5rZWRFbnRpdHlHdWlkIjpudWxsLCJsaW5rZWREYXNoYm9hcmRJZCI6bnVsbCwieVNjYWxlIjp7InN0YXRpYyI6ZmFsc2UsImRvbWFpbiI6W251bGwsbnVsbF19LCJ5WmVybyI6dHJ1ZX19Cg==).
    \* See \[OpenTelemetry APM UI](/docs/opentelemetry/get-started/apm-monitoring/opentelemetry-apm-ui) for more information.

If you can't find your entity and don't see your data with NRQL, see \[OTLP troubleshooting](/docs/opentelemetry/best-practices/opentelemetry-otlp-troubleshooting).
You can find the data collected by the eBPF agent in the New Relic Opentelementry UI.

 \*/

## Upgrade the eBPF agent [#upgrade]

To upgrade the eBPF agent in a Kubernetes cluster:

-   **For a standard upgrade**: Use the following Helm command to upgrade to the latest version:

```bash
KSM_IMAGE_VERSION="v2.13.0" && helm repo add newrelic https://helm-charts.newrelic.com && helm repo update && kubectl create namespace "newrelic" ; helm upgrade --install nr-ebpf-agent newrelic/nr-ebpf-agent --set licenseKey=<key> --set cluster="<cluster-name>" --namespace=newrelic
```

-   **For a specific version upgrade:** To upgrade to a specific version, use the `--version` flag:

```bash
KSM_IMAGE_VERSION="v2.13.0" && helm repo add newrelic https://helm-charts.newrelic.com && helm repo update && kubectl create namespace "newrelic" ; helm upgrade --install nr-ebpf-agent newrelic/nr-ebpf-agent --set licenseKey=<key> --set cluster="<cluster-name>" --namespace=newrelic --version=0.2.5
```

Replace `<key>` with your New Relic license key and `<cluster-name>` with your cluster name.

## Configuration parameters [#config-params]

The [`values.yaml`](https://github.com/newrelic/helm-charts/blob/master/charts/nr-ebpf-agent/values.yaml) file contains the following configuration sections:

> #### 💡 TIP
>
> The eBPF agent automatically generates entity names differently depending on the environment:
>
> -   In hosts or Docker, these names are a combination of the process name, its directory or container ID, and the listening port. For example, `ruby:/home/ubuntu/app:[5678]` or `java:f4aead533895:[8080]`.
>
> -   In Kubernetes, these names are derived from the service name for example, `mysql-database-service`.
>
> Assigning custom name to applications:
>
> -   You can assign a custom name to your application by setting the `NEW_RELIC_APP_NAME` environment variable for both Kubernetes and on-host applications.

**General configuration**

These parameters control the core identity and data destination for the eBPF agent.

| Parameter                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Data Type | Example                                              |
| ------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------- | ---------------------------------------------------- |
| `cluster`                                  | Specifies the name of your Kubernetes cluster. This field is mandatory.                                                                                                                                                                                                                                                                                                                                                                                               | `String`  | `"production-cluster"`                               |
| `licenseKey`                               | Specifies your New Relic license key. Required if `customSecretName` is not used.                                                                                                                                                                                                                                                                                                                                                                                     | `String`  | `"8356...FFFFNRAL"`                                  |
| `customSecretName`                         | Specifies the name of a Kubernetes secret that contains your license key. Use this to avoid providing the key directly.                                                                                                                                                                                                                                                                                                                                               | `String`  | `"newrelic-license-secret"`                          |
| `customSecretLicenseKey`                   | Specifies the key within the secret where the license key value is stored. Used with `customSecretName`.                                                                                                                                                                                                                                                                                                                                                              | `String`  | `"license"`                                          |
| `namespaceLicenseKeys`                     | Maps each Kubernetes namespace to a New Relic license key for multi-account OTLP export routing. Namespaces not present in the map fall back to the global `licenseKey`.                                                                                                                                                                                                                                                                                              | `Object`  | `{"team-a": "NRAK-aaa...", "team-b": "NRAK-bbb..."}` |
| `customSecretNamespaceLicenseKeys`         | Specifies an existing Kubernetes secret that contains a `NAMESPACE_LICENSE_KEY_MAP` key with a JSON-encoded namespace-to-license-key map. Use this instead of `namespaceLicenseKeys` to avoid storing license keys in values.yaml.                                                                                                                                                                                                                                    | `String`  | `"namespace-license-keys-secret"`                    |
| `region`                                   | Specifies your New Relic account region. Accepted values: `US`, `EU`, `JP`, `GOV`. Leave empty for `US` (default). Required when using `customSecretName`.                                                                                                                                                                                                                                                                                                            | `String`  | `"US"`                                               |
| `fedramp.enabled`                          | Enables FedRAMP-compliant endpoints (`gov-otlp.nr-data.net`). This is the preferred way to enable FedRAMP compliance and takes precedence over region-based detection (equivalent to `region="GOV"`). You can also configure it with `global.fedramp.enabled`.                                                                                                                                                                                                        | `Boolean` | `false`                                              |
| `logLevel`                                 | Defines the logging verbosity level for the agent. Valid options: `OFF`, `FATAL`, `ERROR`, `WARNING`, `INFO`, `DEBUG`.                                                                                                                                                                                                                                                                                                                                                | `String`  | `"INFO"`                                             |
| `logFilePath`                              | Specifies a file path inside the agent container for log output. If the path is invalid, logs are directed to stdout.                                                                                                                                                                                                                                                                                                                                                 | `String`  | `"/var/log/nr-ebpf-agent.log"`                       |
| `downloadedPackagedHeadersPath`            | Sets the absolute path of the complete directory where the required linux headers are manually downloaded and placed for the eBPF agent to use. This is useful under restricted environments where agent is not able to download required linux headers. The required headers are identified by the agent based on the kernel version. The absolute path in case of K8s should also be prepended with /host when necessary. Use only after NR support recommendation. | `String`  | `"/path/to/downloaded/headers/dir"`                  |
| `distroKernelHeadersPath`                  | Sets the absolute path of the complete directory where the linux headers are present for the eBPF agent to use. This is useful where required linux headers could not be installed or path could not be determined. The absolute path in case of K8s should also be prepended with /host when necessary. Use only after NR support recommendation.                                                                                                                    | `String`  | `"/host/usr/src/linux-headers-6.8.0-pl"`             |
| `reportApmData`                            | Controls APM data reporting. Accepted values: `"true"` (always send), `"false"` (never send), `"auto"` (send only when neither APM nor OTel agent is attached).                                                                                                                                                                                                                                                                                                       | `String`  | `"auto"`                                             |
| `reportNetworkMetrics`                     | Controls network metrics reporting. When enabled, the agent collects and reports network metrics including TCP statistics. Accepted values: `"true"` (always send), `"false"` (never send), `"auto"`.                                                                                                                                                                                                                                                                 | `String`  | `"auto"`                                             |
| `reportLogs`                               | Controls application log reporting. Accepted values: `"true"` (always send), `"false"` (never send), `"auto"` (send unless the attached APM agent is actively collecting logs itself, or an OTel agent is attached at all). See [Automatic detection and backoff](https://docs.newrelic.com/docs/ebpf/logs/#automatic-backoff) for details.                                                                                                                           | `String`  | `"false"`                                            |
| `agentMetadataReporting`                   | Enables agent and entity metadata reporting. By default, the agent exports agent and entity metadata to New Relic over HTTP. Set this to `false` to disable the metadata reporting HTTP export path entirely.                                                                                                                                                                                                                                                         | `Boolean` | `true`                                               |
| `customOtlpEndpoint`                       | Custom OTLP endpoint URL. When set, this takes precedence over the region-based static endpoints.                                                                                                                                                                                                                                                                                                                                                                     | `String`  | `""`                                                 |
| `customOtlpEndpointTlsEnabled`             | Whether TLS is enabled on the OTLP endpoint. Only overridden when both `customOtlpEndpoint` and this field are explicitly set.                                                                                                                                                                                                                                                                                                                                        | `Boolean` | `true`                                               |
| `customOtlpEndpointTlsCertSecret`          | Name of the Kubernetes secret containing the CA certificate for the custom OTLP endpoint. Only used when `customOtlpEndpoint` is set. Must be provided together with `customOtlpEndpointTlsCertSecretKey`.                                                                                                                                                                                                                                                            | `String`  | `""`                                                 |
| `customOtlpEndpointTlsCertSecretKey`       | Key within the secret that contains the CA certificate. Only used when `customOtlpEndpoint` is set. Must be provided together with `customOtlpEndpointTlsCertSecret`.                                                                                                                                                                                                                                                                                                 | `String`  | `""`                                                 |
| `otlpProxy.host`                           | HTTP/HTTPS proxy hostname for routing OTLP telemetry data through a corporate proxy. If empty, no proxy is used.                                                                                                                                                                                                                                                                                                                                                      | `String`  | `"proxy.example.com"`                                |
| `otlpProxy.port`                           | Proxy port for the OTLP proxy.                                                                                                                                                                                                                                                                                                                                                                                                                                        | `Integer` | `""`                                                 |
| `otlpProxy.scheme`                         | Proxy URL scheme. Accepted values: `http`, `https`.                                                                                                                                                                                                                                                                                                                                                                                                                   | `String`  | `"http"`                                             |
| `otlpProxy.user`                           | Username for proxy Basic Authentication. If empty, no authentication is used.                                                                                                                                                                                                                                                                                                                                                                                         | `String`  | `""`                                                 |
| `otlpProxy.password`                       | Password for proxy Basic Authentication. Only used together with `otlpProxy.user`. For security, prefer `otlpProxy.existingSecret` instead of setting the password directly.                                                                                                                                                                                                                                                                                          | `String`  | `""`                                                 |
| `otlpProxy.url`                            | Complete proxy URL. When set, this overrides the individual `otlpProxy.host`, `port`, `scheme`, `user`, and `password` settings. Format: `http://[user:pass@]host:port`.                                                                                                                                                                                                                                                                                              | `String`  | `""`                                                 |
| `otlpProxy.existingSecret`                 | Name of an existing Kubernetes secret containing proxy credentials. The secret must contain the keys `proxy-user` and `proxy-password`.                                                                                                                                                                                                                                                                                                                               | `String`  | `""`                                                 |
| `ai_monitoring.enabled`                    | Controls GenAI telemetry reporting. Accepted values: `"true"` (always send), `"false"` (never send), `"auto"` (send only when no language APM or OTel agent is already reporting AI monitoring data for the entity).                                                                                                                                                                                                                                                  | `String`  | `"false"`                                            |
| `ai_monitoring.samplingLatency`            | Defines the latency-based sampling threshold for exporting GenAI spans. Supports any percentile from `p0` to `p99`.                                                                                                                                                                                                                                                                                                                                                   | `String`  | `"p50"`                                              |
| `ai_monitoring.samplingErrorRate`          | Defines the error-rate threshold for a GenAI route where surpassing it means the corresponding spans of the route are exported. Options: `1`-`100`.                                                                                                                                                                                                                                                                                                                   | `String`  | `""`                                                 |
| `ai_monitoring.genAICaptureMessageContent` | When `true`, captures full prompt and completion content for GenAI interactions. Only takes effect when `ai_monitoring.enabled` is `true` or `auto`. Use with caution.                                                                                                                                                                                                                                                                                                | `Boolean` | `false`                                              |
| `httpPathNormalizationPatterns`            | Defines HTTP path normalization patterns. Each pattern must contain at least one `*` wildcard. Use a `!` prefix for exclusion patterns to preserve paths as is (skip auto-clustering). The agent applies these patterns before auto-clustering, and they take precedence over it.                                                                                                                                                                                     | `List`    | `["/api/users/*", "/api/orders/*", "!/health/*"]`    |
| `httpBodyLimitBytes`                       | Sets the maximum number of bytes captured from an HTTP request/response body. Default: `1048576` (1 MB) when `ai_monitoring.enabled` is `true` or `auto`, otherwise `1024` (1 KB). Increase this value if New Relic truncates AI monitoring payloads.                                                                                                                                                                                                                 | `Integer` | `2097152`                                            |
| `entityLabels`                             | Custom labels to be added to all entities reported by the eBPF agent. These labels are sent as the `NEW_RELIC_LABELS` environment variable in the format `"key1:value1;key2:value2"`.                                                                                                                                                                                                                                                                                 | `Map`     | `{}`                                                 |

> #### ⚠️ IMPORTANT
>
> The eBPF agent supports HTTP CONNECT proxies using the `http://` scheme only. Due to gRPC limitations, the `https://` scheme (a TLS-encrypted connection directly to the proxy) isn't supported. However, your telemetry data is always TLS-encrypted **end-to-end** between the agent and the New Relic OTLP endpoint. The `http://` prefix dictates only how the agent talks to the proxy to establish the tunnel. The proxy itself only sees encrypted traffic and never has access to your data. For full setup instructions, see [Configure a proxy for the eBPF agent](https://docs.newrelic.com/docs/ebpf/proxy-configuration).

**All data filters**

This section configure filters to drop all types of Network Metrics and APM data based on provided configuration.

| Parameter                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Data Type | Example           |
| ------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------- | ----------------- |
| `allDataFilters.dropNewRelicBundle`        | Drop data from the newrelic `namespace` and `newrelic-bundle` services. This field is renamed from `dropDataNewRelic`. The old name is deprecated but remains supported for backward compatibility.                                                                                                                                                                                                                                                              | `Boolean` | `true`            |
| `allDataFilters.dropNamespaces`            | List of Kubernetes namespaces for which all data should be dropped by the agent. Use either dropNamespaces or keepNamespaces to filter namespaces, not both. If both are provided, keepNamespaces takes precedence.                                                                                                                                                                                                                                              | `List`    | `["kube-system"]` |
| `allDataFilters.keepNamespaces`            | List of Kubernetes namespaces for which all data should be sent by the agent. Use either dropNamespaces or keepNamespaces to filter namespaces, not both. If both are provided, keepNamespaces takes precedence.                                                                                                                                                                                                                                                 | `List`    | `[]`              |
| `allDataFilters.dropPodLabels`             | Pod labels to match for filtering all data. Empty map means no label-based filtering. For example: `{ "app": "frontend", "env": "production" }`. Use either dropPodLabels or keepPodLabels to filter based on pod labels, not both. If both are provided, keepPodLabels takes precedence.                                                                                                                                                                        | `Map`     | `{}`              |
| `allDataFilters.keepPodLabels`             | Pod labels to match for keeping all data. Empty map means no label-based filtering. For example: `{ "app": "frontend", "env": "production" }`. Use either dropPodLabels or keepPodLabels to filter based on pod labels, not both. If both are provided, keepPodLabels takes precedence.                                                                                                                                                                          | `Map`     | `{}`              |
| `allDataFilters.dropServiceNameRegex`      | Define a regex to match k8s service names to drop. For example `"kube-dns|otel-collector|\\bblah\\b"`. Use either dropServiceNameRegex or keepServiceNameRegex to filter service names, not both. If both are provided, keepServiceNameRegex takes precedence.                                                                                                                                                                                                   | `String`  | `""`              |
| `allDataFilters.keepServiceNameRegex`      | This config acts as a bypass for the `dropServiceNameRegex` config. Service names that match this regex will not have their data dropped by the `dropServiceNameRegex`. Use either dropServiceNameRegex or keepServiceNameRegex to filter service names, not both. If both are provided, keepServiceNameRegex takes precedence. This field is renamed from `allowServiceNameRegex`. The old name is deprecated but remains supported for backward compatibility. | `String`  | `""`              |
| `allDataFilters.dropApmAgentEnabledEntity` | Drop all data for applications or entities that have NewRelic or OTEL APM agents running.                                                                                                                                                                                                                                                                                                                                                                        | `Boolean` | `false`           |

**APM data filters**

Configure filters to drop ebpf APM data based on config provided

| Parameter                            | Description                                                                                                                                                    | Data Type | Example |
| ------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------- | ------- |
| `apmDataFilters.dropPodLabels`       | Pod labels to match for filtering APM data. Empty map means no label-based filtering. For example: dropPodLabels: `{ "app": "frontend", "env": "production" }` | `Map`     | `{}`    |
| `apmDataFilters.dropEntityName`      | List of entity names to drop eBPF APM data                                                                                                                     | `List`    | `[]`    |
| `apmDataFilters.keepEntityName`      | List of entity names to always keep APM data. By default all entities are kept/enabled. This config bypasses `dropEntityName` filter.                          | `List`    | `[]`    |
| `apmDataFilters.jvmMetricsReporting` | Enable JVM metrics reporting. When enabled, the agent collects and reports JVM metrics for Java applications.                                                  | `Boolean` | `true`  |

**Network metrics data filters**

Configure filters to drop/keep Network metrics data based on config provided

| Parameter                                 | Description                                                                                                                                                                | Data Type | Example |
| ----------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------- | ------- |
| `networkMetricsDataFilter.dropPodLabels`  | Pod labels to match for filtering Network metrics data. Empty map means no label-based filtering. For example: dropPodLabels: `{ "app": "frontend", "env": "production" }` | `Map`     | `{}`    |
| `networkMetricsDataFilter.dropEntityName` | List of entity names to drop Network metrics data.                                                                                                                         | `List`    | `[]`    |
| `networkMetricsDataFilter.keepEntityName` | List of entity names to always keep Network metrics data. By default all entities are kept/enabled. This config bypasses `dropEntityName` filter.                          | `List`    | `[]`    |

**Log data filters**

Configure filters to control the application logs the eBPF agent collects and reports. These settings only take effect when `reportLogs` is set to `"true"` or `"auto"`.

| Parameter                                                         | Description                                                                                                                                                                   | Data Type | Example     |
| ----------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------- | ----------- |
| `logDataFilters.applicationLogReporting.enabled`                  | Enables log collection from entities matching the filters below.                                                                                                              | `Boolean` | `true`      |
| `logDataFilters.applicationLogReporting.fileRegex`                | Regular expression to match log file names to include.                                                                                                                        | `String`  | `".*.log$"` |
| `logDataFilters.applicationLogReporting.logLevelThreshold`        | Minimum log level to report (for example, `TRACE`, `DEBUG`, `INFO`, `WARN`, `ERROR`).                                                                                         | `String`  | `"INFO"`    |
| `logDataFilters.applicationLogReporting.maxSamplesPerMinute`      | Maximum number of log samples to collect per minute from an entity. Once this limit is reached, events are sampled to maintain an even distribution across the harvest cycle. | `Integer` | `10000`     |
| `logDataFilters.applicationLogReporting.keepStdStreamEntityRegex` | Regular expression to match entity names to keep logs from STDOUT and STDERR. Use `.*` to forward logs for all entities.                                                      | `String`  | `".*"`      |
| `logDataFilters.applicationLogReporting.keepFileEntityRegex`      | Regular expression to match entity names to keep logs from log files. Use `.*` to forward logs for all entities.                                                              | `String`  | `".*"`      |

**Protocol tracing configuration**

This section allows you to enable monitoring for specific network protocols and configure how trace data (spans) is collected. You can enable or disable monitoring for protocols like HTTP, MySQL, and others, and set parameters for span collection based on latency or error rates. The following protocols are supported:

-   HTTP
-   Thrift
-   MySQL
-   MariaDB
-   Aurora MySQL
-   PostgreSQL
-   MongoDB
-   Apache Cassandra
-   Redis
-   DynamoDB
-   MSSQL
-   Kafka
-   AMQP
-   DNS

MySQL protocol tracing (`protocols.mysql`) also covers MariaDB and Aurora MySQL, as both engines use the same wire protocol as MySQL. Configuration doesn't require a separate `mariadb` or `aurora_mysql` section; enabling or disabling `protocols.mysql` controls tracing for all supported engines. The agent automatically detects the specific database flavor per connection during the server handshake and reports it on each record. You can't configure this detection manually.

| Parameter                                                | Description                                                                                                                                                                   | Data Type | Example |
| -------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------- | ------- |
| `protocols.global.max_unlinked_spans`                    | Controls maximum unlinked spans reported per protocol. Set to 0 to disable limit. Unlinked spans are spans that the eBPF agent captures but cannot associate with its parent. | `String`  | `"100"` |
| `protocols.global.unlinked_spans_error_quota_percentage` | Reserves a configurable percentage of the unlinked span quota for error spans, ensuring error visibility even when normal spans arrive first.                                 | `String`  | `"30"`  |
| `protocols.<protocol-name>.enabled`                      | If `true`, enables monitoring for the specified protocol for example, `http`, `mysql`, and any others.                                                                        | `Boolean` | `true`  |
| `protocols.<protocol-name>.spans.enabled`                | If `true`, exports trace spans for the enabled protocol.                                                                                                                      | `Boolean` | `true`  |
| `protocols.<protocol-name>.spans.samplingLatency`        | Defines the latency-based sampling threshold for exporting spans. Supports values from `p0` to `p99`.                                                                         | `String`  | `"p50"` |
| `protocols.<protocol-name>.spans.samplingErrorRate`      | For HTTP and Thrift only. Exports spans from any route where the error rate exceeds the specified percentage (1-100).                                                         | `String`  | `"5"`   |

**DaemonSet configurations**

These sections control the deployment settings for the solution's main components. An asterisk `(*)` denotes the component name.

| Parameter                     | Description                                                                | Data Type | Example                                      |
| ----------------------------- | -------------------------------------------------------------------------- | --------- | -------------------------------------------- |
| `*.image.repository`          | Specifies the container image repository for the component.                | `String`  | `"docker.io/newrelic/newrelic-ebpf-agent"`   |
| `*.image.pullPolicy`          | Defines the pull policy for the container image.                           | `String`  | `"IfNotPresent"`                             |
| `*.image.tag`                 | Specifies the version tag of the container image to deploy.                | `String`  | `"agent-0.2.4"`                              |
| `*.resources.limits.memory`   | Defines the maximum memory the container can use.                          | `String`  | `"2Gi"`                                      |
| `*.resources.requests.cpu`    | Defines the minimum CPU requested for the container at startup.            | `String`  | `"100m"`                                     |
| `*.resources.requests.memory` | Defines the minimum memory requested for the container at startup.         | `String`  | `"250Mi"`                                    |
| `*.tolerations`               | Defines pod tolerations to allow scheduling on nodes with specific taints. | `Objects` | `[{"key": "special", "operator": "Exists"}]` |
| `*.affinity`                  | Defines pod affinity and anti-affinity rules for scheduling.               | `Object`  | `{}`                                         |
| `*.podAnnotations`            | Specifies custom annotations to add to the component pod.                  | `Object`  | `{"iam.amazonaws.com/role": "my-role"}`      |

**Global pod and scheduling configuration**

These parameters apply to all pods deployed by the Helm chart, unless overridden by a component-specific setting.

| Parameter           | Description                                                             | Data Type | Example                     |
| ------------------- | ----------------------------------------------------------------------- | --------- | --------------------------- |
| `podLabels`         | Specifies additional labels to apply to all pods deployed by the chart. | `Object`  | `{"team": "observability"}` |
| `priorityClassName` | Specifies the `PriorityClass` for all pods.                             | `String`  | `"high-priority"`           |
| `nodeSelector`      | Constrains pods to only run on nodes with matching labels.              | `Object`  | `{"disktype": "ssd"}`       |

## Uninstall the eBPF agent [#uninstall]

To uninstall the eBPF agent from your Kubernetes cluster:

```bash
helm uninstall nr-ebpf-agent -n newrelic
```

> #### 💡 TIP
>
> This command will remove all eBPF agent components from your cluster. The namespace will remain unless you explicitly delete it.

[eBPF Linux installation](https://docs.newrelic.com/docs/ebpf/linux-installation/)

Learn how to set up the New Relic eBPF agent for your Linux host.

[Troubleshooting eBPF](https://docs.newrelic.com/docs/ebpf/troubleshooting/no-ui-data/)

Learn how to troubleshoot issues with the New Relic eBPF agent.

[eBPF best practices](https://docs.newrelic.com/docs/ebpf/best-practices/)

Learn about best practices for using the New Relic eBPF agent.
