Skip to main content

Managing Security Events

Control panel

Using the authorization log, you can find out who used the account and when. You can receive information about authorizations from a new IP address by email.

The account owner sees the authorizations of all account users. Invited users see only their own authorizations. See the Access Management in Servercore Products guide for more details.

If you notice suspicious activity, reset all sessions and change your password.

Cloud and dedicated servers

In cloud and dedicated servers, operating system events and information security events can be collected and exported to external security event management systems using free tools:

Additional options for security event generation can be implemented using utilities:

  • Auditd — for Linux OS;
  • Sysmon — for Windows OS.

Managed Kubernetes

In Managed Kubernetes clusters, you can receive logs — cluster logs, container logs, and audit logs.

Cluster logs display events that occur in the cluster. For example, cluster creation, node group changes, and certificate and version updates. If a request was performed automatically, such as a scheduled certificate update, this action will also be logged. You can view cluster logs in the Control Panel.

Container logs capture events that occur in containers, such as container creation and deletion. Container log files are stored in the /var/log/pods/ or /var/log/containers directory. Logs for an individual container can be viewed using kubectl logs <container_name>, where <container_name> is the container name. If there are many containers in a Managed Kubernetes cluster, you can configure container log collection via Filebeat.

Audit logs display events that occur in the cluster, such as those in pods or services. These events can be initiated by users, applications, or the Control Plane. The list of events included in the logs and their parameters depend on the policy (audit policy).

Audit logs can be sent to a security event management system, such as the Wazuh SIEM system. To receive audit logs from a Managed Kubernetes cluster, configure the integration.