Summary
This chapter covered how to create an enhanced auditing system to your Kubernetes cluster. We started the chapter by introducing Falco, an auditing add-on that was donated to the CNCF by Sysdig. Falco adds a level of auditing that Kubernetes does not include, and combined with the including auditing functionality, provides an audit trail for everything from API access to actions in a pod.
Logs aren't beneficial if you can't store them in a logging system that allows you to store logs on persistent storage and usually offers a management interface to search logs and create dashboards. We installed the common EFK stack on our KinD cluster and created a custom dashboard to show Falco events in Kibana.
With the topics you learned in this chapter, you should have a strong foundational knowledge of how to add Falco to a cluster and use EFK to store logs and present data in visualizations and dashboards.
While logging and auditing are important, it is equally important...