Monitor security events across your containers, including deployment and runtime policy violations, vulnerabilities, malware, secrets, file integrity changes, Kubernetes audit logs, and pre-runtime Container Image Scanning results.
|
Deployment/continuous
|
View policy violations detected by Runtime Security.
|
|
Runtime Security
|
View activity on your running containers that violates your runtime security rulesets.
Learn how to enable Runtime Security on Kubernetes clusters.
|
|
Runtime Vulnerabilities
|
View vulnerabilities detected on clusters by Runtime Scanning.
|
|
Runtime Malware
|
View malware detections found on your running containers by Runtime Malware Scanning.
|
|
Runtime Secrets
|
View secret leaks detected in your running containers. Learn how to enable Runtime Secret Scanning on Kubernetes clusters.
|
|
File integrity monitoring
|
View file changes detected in critical areas of your containers by File integrity monitoring.
|
|
Kubernetes audit log
|
View Kubernetes API server audit events collected from your clusters. Learn how to enable audit log collection.
|
|
Container Image Scanning
|
Learn how to set up and deploy artifact scanners in your CI/CD pipelines. After artifact scanning is set up, you can view the scan
results of registry image artifacts for vulnerabilities, malware, and secrets from
this page.
|
Runtime Security detects security policy violations in your existing clusters. Once
a
violation is detected on a container, the detection displays. The
Events screen outlines the different types of policies
deployed to your containers:
-
Continuous, Runtime Malware, Runtime Secret: Kubernetes only policies
-
Deployment, Runtime Vulnerabilities, Runtime Security, File integrity monitoring: Kubernetes or Amazon ECS policies
Deployment/continuous
The following table outlines the actions available in Deployment/continuous.
|
Action
|
Description
|
|
Filter the displayed data
|
Click Filter and select one or more of the following filters.
|
|
Locate triggered policies
|
Click the Policy link to locate the policy that triggered the detection in the Policies tab.
|
|
Export a list of events
|
Click the Export button to create and download a .CSV file listing all the events on the page.
|
|
Locate the affected clusters
|
Click the Cluster link to redirect and locate the affected cluster in Container Security.
|
