opensearch-project / opensearch-project/security-analytics
[FEATURE]: Support logs from Kubernetes audit logs
Nobody has claimed this yet.
- Dominant language
- Java
- Stars
- 111
- Forks
- 111
- Avg merge
- 1d 17h
- Merged PRs (30d)
- 13
Description
Is your feature request related to a problem?
Support security event logs from Kubernetes audit logs
https://opensearch.slack.com/archives/C051Y637FKK/p1680689503576889
What solution would you like?
Support security event logs from Kubernetes audit logs
What alternatives have you considered?
N/A - Additional log source support
https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/#audit-backends
Do you have any additional context?
Add any other context or screenshots about the feature request here.
https://falco.org/docs/event-sources/kubernetes-audit/
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No repository files, tests, or entry points are named. Start with the Kubernetes audit-backends and Falco Kubernetes audit event-source documentation linked in the issue; done means the project supports Kubernetes audit logs as a security-event source with its expected behavior validated.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, kubernetes
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100