Collect kubernetes audit logs
This page outlines how to collect Kubernetes audit logs. I'd like to also add our own example to the list here.
A few questions for this issue:
- Is there anything additional we need to do to collect this data?
- I'd like to see what our docs would look like on this page so that we can add it.
- Is there anything additional we need to do to collect this data?
We'll need to deploy vector is a specific way - we'll cover this out of the box for the users via our Helm Chart(s?).
- I'd like to see what our docs would look like on this page so that we can add it.
The exact details will be available later, but we will expose this via our Helm Chart, and configuring that is done via values.yml. In general, we should get ready for pretty much the whole AuditPolicy. Maybe offer an intelligent configurator like we have for vector.toml?
What's the status here? How can be audit logs for kubernetes / openshift configured as source in vector?
Is file source a good option?