-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Auditbeat - Enrich process events with K8 information #9668
Comments
@exekias any plans for this one? Its come up a few times. |
Sorry I have been out for a while, didn't have much time to look into this yet. Also pinging @elastic/secops |
Doesn't work still, kubernetes support for auditbeat is very limited. |
|
I can confirm that with 7.7 will be possible to enrich process events with K8s info, I have opened a PR to add this to the reference manifest: #17431 |
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
Describe the enhancement:
Support Enrichment of Auditbeat process events with Kubernetes and docker metadata. Currently this isn't supported.
We believe this isn't working because cgroup names are different for docker containers when they are launched by Kubernetes, hence
add_docker_metadata
doesn't work. This information in turn isn't available foradd_kubernetes_metadata
. Proposal is adding logic onadd_kubernetes_metadata
with the k8s pattern for cgroup names.@exekias to add more details
Describe a specific use case for the enhancement or feature:
Kubernetes and tracking process executions + being able to attribute these to a specific container.
The text was updated successfully, but these errors were encountered: