Skip to content

Kubernetes.audit_logs: add support for cloud providers - #14554

Merged
chemamartinez merged 7 commits into
elastic:mainfrom
chemamartinez:5799-kubernetes-audit-cloud
Aug 28, 2025
Merged

chemamartinez merged 7 commits into
elastic:mainfrom
chemamartinez:5799-kubernetes-audit-cloud

Conversation

@chemamartinez

Copy link
Copy Markdown
Contributor

Proposed commit message

Extend the Kubernetes audit_logs data stream to support collecting audit logs from managed Kubernetes clusters in major cloud providers:

  • AWS EKS via CloudWatch Logs
  • Azure AKS via Event Hub
  • Google GKE via Pub/Sub

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
  • I have verified that any added dashboard complies with Kibana's Dashboard good practices

Related issues

Screenshots

Add-integration-Kubernetes-Integrations-Elastic-07-15-2025_06_49_PM Edit-integration-Elastic-Agent-elastic-package-Agent-policies-Fleet-Elastic-07-15-2025_06_52_PM Screenshot 2025-07-15 at 18 52 48 Screenshot 2025-07-15 at 18 53 07

@chemamartinez chemamartinez self-assigned this Jul 15, 2025
@chemamartinez chemamartinez added enhancement New feature or request Integration:kubernetes Kubernetes Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations] Team:obs-ds-hosted-services Observability Hosted Services team [elastic/obs-ds-hosted-services] labels Jul 15, 2025
@andrewkroh andrewkroh added the documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. label Jul 15, 2025
@chemamartinez
chemamartinez force-pushed the 5799-kubernetes-audit-cloud branch from c66a453 to c77254f Compare July 16, 2025 05:37
@chemamartinez
chemamartinez marked this pull request as ready for review July 16, 2025 05:37
@chemamartinez
chemamartinez requested a review from a team as a code owner July 16, 2025 05:37
@elasticmachine

Copy link
Copy Markdown

Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@chemamartinez
chemamartinez requested review from a team July 16, 2025 10:14
# audit-logs

audit-logs integration collects and parses Kubernetes audit logs.
Audit logs integration collects and parses Kubernetes audit logs.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Audit logs integration collects and parses Kubernetes audit logs.
Audit-logs integration collects and parses Kubernetes audit logs.

@@ -0,0 +1,103 @@
{{#unless log_group_name}}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Wondering if those files should be placed under relevant aws-cloudwatch integration (and similarly under azure and gcp). I am thinking that it would be difficult for our users to figure out that we have audit logs support and to check on k8s when initially are on a CSP integration.

@zmoog wdyt on this?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

After some discussions (see #5799 (comment) and further comments), that option was on the table but it shows some inconveniences in terms of maintenance mainly).

Happy to hear your thoughts on this point.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@chemamartinez - This is amazing and thank you for putting in the PR.

@gizas - Definitely a great question. My two cents:

For AKS at least, most Azure data sources are tied to the single Azure integration. Entra ID, Activity, Diagnostic, Platform, etc. logs are all in the Azure integration as a separate data stream, rather than having their own integrations. However, Azure may be unique in this perspective since all logs, regardless of service, are forwarded to an Event Hub, thus putting them in a centralized location for us to ingest from. From a detection rule perspective, if we wanted to correlate activity between - for instance - Entra ID sign-ins and K8s, two separate integration installations are required instead of one. However, for AWS, most rules are written on CloudTrail audit logs, so we still would require a separate integration, CloudWatch, for this.

On the flip side - K8s as a separate integration may make more sense to isolate the data streams (both local and CSP-based) as being done here and point users with K8s requirements to a single integration and pick which provider. We know that K8s is a very popular integration as-is so it may be good to roll this out with what is already adopted heavily.

- append:
field: error.message
value: '{{{ _ingest.on_failure_message }}}'
value: >

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

description: Pipeline for processing Kubernetes audit logs.
processors:
- rename:
field: message

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What would be the default criteria for this in Obs integrations? We usually keep the original raw message in event.original and message gets removed so it is not duplicated.

mappings:
dynamic: false
streams:
- input: aws-cloudwatch

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread packages/kubernetes/docs/audit-logs.md Outdated
# audit-logs

audit-logs integration collects and parses Kubernetes audit logs.
Audit logs integration collects and parses Kubernetes audit logs.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Audit logs integration collects and parses Kubernetes audit logs.
Audit-logs integration collects and parses Kubernetes audit logs.

@elastic-sonarqube

Copy link
Copy Markdown

Quality Gate failed Quality Gate failed

Failed conditions
19.7% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube

@Mikaayenson
Mikaayenson requested review from a team and removed request for a team July 30, 2025 12:27
@imays11

imays11 commented Aug 11, 2025

Copy link
Copy Markdown
Contributor

This looks good to me, thank you for the changes. I agree with Terrance it's probably best to modify the K8s intregration which is already heavily used rather than modify each individual CSP integration. This will also help us maintain a single K8s ruleset, and will make K8s audit log ingest more user friendly for everyone.

@chemamartinez
chemamartinez requested a review from gizas August 12, 2025 08:00
Comment thread packages/kubernetes/manifest.yml Outdated
Comment thread packages/kubernetes/manifest.yml Outdated
Comment thread packages/kubernetes/data_stream/audit_logs/fields/ecs.yml
Comment on lines +107 to +108

- append:

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Do you think its worth adding cloud.* fields depending on input.type?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cloud metadata is not present in events, do you mean using the add_cloud_metadata processor?

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You are right. The metadata is not present in all inputs and only see it in Cloudwatch input.
https://github.com/elastic/beats/blob/main/x-pack/filebeat/input/awscloudwatch/processor.go#L62-L65

Eventhub defines some, but that cannot be used in cloud.* fields. https://github.com/elastic/beats/blob/main/x-pack/filebeat/input/azureeventhub/v2_input.go#L483-L495

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We can set cloud.provider based on ctx.input.type.

  - set:
      field: cloud.provider
      value: aws
      if: ctx.input?.type == "aws-cloudwatch"

@chemamartinez
chemamartinez requested a review from kcreddy August 28, 2025 12:23
@chemamartinez
chemamartinez requested a review from kcreddy August 28, 2025 13:19

@kcreddy kcreddy left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM. Thanks Chema.

@elasticmachine

Copy link
Copy Markdown

💚 Build Succeeded

History

cc @chemamartinez

@elastic-sonarqube

Copy link
Copy Markdown

Quality Gate failed Quality Gate failed

Failed conditions
27.6% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube

@chemamartinez
chemamartinez merged commit f90519b into elastic:main Aug 28, 2025
8 of 9 checks passed
@chemamartinez
chemamartinez deleted the 5799-kubernetes-audit-cloud branch August 28, 2025 15:05
@elastic-vault-github-plugin-prod

Copy link
Copy Markdown
Contributor

Package kubernetes - 1.81.0 containing this change is available at https://epr.elastic.co/package/kubernetes/1.81.0/

@leandrojmp

Copy link
Copy Markdown
Contributor

Hello @chemamartinez,

With this change I understand that now I can get the AKS logs using this integration instead of using the Cloudwatch integration and a reroute processor on a custom pipeline? Is that right?

@chemamartinez

Copy link
Copy Markdown
Contributor Author

@leandrojmp yes, now you should be able to configure this integration to directly collect the EKS Audit logs as the same way you did for the AWS Cloudwatch integration, and data will automatically be processed by the Kubernetes Audit logs pipeline with no need to reroute.

tehbooom pushed a commit to tehbooom/integrations that referenced this pull request Nov 19, 2025
Extend the Kubernetes audit_logs data stream to support
collecting audit logs from managed Kubernetes clusters
in major cloud providers:
- AWS EKS via CloudWatch Logs
- Azure AKS via Event Hub
- Google GKE via Pub/Sub
@bryans3c bryans3c mentioned this pull request Aug 14, 2026
15 of 16 tasks
@bryans3c bryans3c mentioned this pull request Sep 3, 2026
14 of 16 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

documentation Improvements or additions to documentation. Applied to PRs that modify *.md files. enhancement New feature or request Integration:kubernetes Kubernetes Team:obs-ds-hosted-services Observability Hosted Services team [elastic/obs-ds-hosted-services] Team:Security-Service Integrations Security Service Integrations team [elastic/security-service-integrations]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Kubernetes Audit Logs] [AWS Cloudwatch] Create a new datastream for Ingesting EKS Audit Logs

8 participants