Managing Security Events
Control panel
Authorization log
Using the authorization log, you can find out who used the account and when. You can receive information about authorizations from a new IP address by email.
The account owner sees the authorizations of all account users. Invited users see only their own authorizations. See the Access Management in Selectel Products guide for more details.
If you notice suspicious activity, reset all sessions and change your password.
Audit logs
Only the Account Owner has access to audit logs.
Using audit logs, you can find out about events occurring in the account. Events reflect operations performed on resources or users:
- authentication and the start or end of a session in the Control panel;
- reading specific data (accessing the Secrets service, reading encryption keys, etc. );
- managing access rights and security services (users, roles, passwords, tokens, access keys, secrets, certificates, etc. );
- mutating operations on resources (creating, modifying, or deleting servers, networks, volumes, etc. ).
Audit logs include successful and unsuccessful events, as well as events disallowed by security policies. Once an event occurs, it is logged and becomes available within a few minutes.
Audit logs are collected automatically and stored for 90 days. You can export audit logs manually, configure auto-export to an S3 bucket, or configure export via API.
Cloud and dedicated servers
In cloud and dedicated servers, operating system events and information security events can be collected and exported to external security event management systems using free tools:
Additional options for security event generation can be implemented using utilities:
Auditd— for Linux OS;Sysmon— for Windows OS.
Managed Kubernetes
In Managed Kubernetes clusters, you can receive logs — cluster logs, container logs, and audit logs.
Cluster logs display events that occur in the cluster. For example, cluster creation, node group changes, and certificate and version updates. If a request was performed automatically, such as a scheduled certificate update, this action will also be logged. You can view cluster logs in the Control Panel.
Container logs capture events that occur in containers, such as container creation and deletion. Container log files are stored in the /var/log/pods/ or /var/log/containers directory. Logs for an individual container can be viewed using kubectl logs <container_name>, where <container_name> is the container name. If there are many containers in a Managed Kubernetes cluster, you can configure container log collection via Filebeat.
Audit logs display events that occur in the cluster, such as those in pods or services. These events can be initiated by users, applications, or the Control Plane. The list of events included in the logs and their parameters depend on the policy (audit policy). The policy applied to Managed Kubernetes audit logs can be viewed in the Selectel documentation on GitHub.
Audit logs can be sent to a security event management system, such as the Wazuh SIEM system. To receive audit logs from a Managed Kubernetes cluster, configure the integration.