Kubernetes Audit


Audit logs: The key to finding kubernetes events in an API server

Step-by-step guide

Create a cluster with Feature Logging (Self-hosted Elasticsearch/Kibana) enabled.

Download the audit-dashboard file you need:

  1. for Kibana 5.x (Kublr 1.9 or earlier)

  2. for Kibana 6.x (Kublr 1.10 or newer)

  3. for Centralized logging

Open Kibana (click the link from the cluster’s Overview page) and import the file with audit-dashboard:

  1. Log in into Kibana (with user/password from Kube Config File)
  2. Navigate Management > Saved Objects
  3. Click Import > Select the required file
  4. Audit-dashboard should be created with a name corresponding to the file name
  5. Navigate the Dashboard menu and click audit-dashboard

Audit Dashboard

Note: If you find import errors, you’ll need to import the dashboard again.