falco icon indicating copy to clipboard operation
falco copied to clipboard

How do I use falco for auditing kubernetes events in an EKS cluster

Open saiharshitachava opened this issue 2 years ago • 4 comments

How do I use falco for auditing kubernetes events in an EKS cluster

Is this an available option right now?

saiharshitachava avatar Apr 27 '22 14:04 saiharshitachava

EKS audit logs directly go to cloudwatch. What you can do is similar to https://github.com/sysdiglabs/ekscloudwatch, just replace sysdig agents with falco.

Kaizhe avatar May 06 '22 04:05 Kaizhe

Issues go stale after 90d of inactivity.

Mark the issue as fresh with /remove-lifecycle stale.

Stale issues rot after an additional 30d of inactivity and eventually close.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle stale

poiana avatar Aug 04 '22 09:08 poiana

@saiharshitachava FYI, I'm working on a plugin for audit logs from EKS, it's almost ready https://github.com/falcosecurity/plugins/pull/134

Issif avatar Aug 22 '22 14:08 Issif

Stale issues rot after 30d of inactivity.

Mark the issue as fresh with /remove-lifecycle rotten.

Rotten issues close after an additional 30d of inactivity.

If this issue is safe to close now please do so with /close.

Provide feedback via https://github.com/falcosecurity/community.

/lifecycle rotten

poiana avatar Sep 21 '22 15:09 poiana

Rotten issues close after 30d of inactivity.

Reopen the issue with /reopen.

Mark the issue as fresh with /remove-lifecycle rotten.

Provide feedback via https://github.com/falcosecurity/community. /close

poiana avatar Oct 21 '22 15:10 poiana

@poiana: Closing this issue.

In response to this:

Rotten issues close after 30d of inactivity.

Reopen the issue with /reopen.

Mark the issue as fresh with /remove-lifecycle rotten.

Provide feedback via https://github.com/falcosecurity/community. /close

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

poiana avatar Oct 21 '22 15:10 poiana