Audit logging Kubernetes : qui a fait quoi, après coup
RBAC empêche, Falco détecte en direct, l'audit logging répond après l'incident. Sans Audit Policy activée, cette question n'a tout simplement pas de réponse.
RBAC empêche, Falco détecte en direct, l'audit logging répond après l'incident. Sans Audit Policy activée, cette question n'a tout simplement pas de réponse.
RBAC prevents, Falco detects live, audit logging answers after the incident. Without an Audit Policy enabled, that question simply has no answer.
Un Event Kubernetes disparaît après 1 heure par défaut, pas après un an. La preuve d'un incident survenu la veille a souvent déjà été purgée avant qu'on la cherche.
A Kubernetes Event vanishes after 1 hour by default, not a year. The proof of yesterday's incident has usually already been purged before anyone looks.