Managing Security Events
Control panel
Authorization log
Using the authorization log, you can find out who used the account and when. You can receive information about authorizations from a new IP address by email.
The account owner sees the authorizations of all account users. Invited users see only their own authorizations. See more in the instruction Access Control in Selectel Products.
If you notice suspicious activity, reset all sessions and change your password.
Audit logs
Only the Account Owner has access to audit logs.
Using audit logs, you can find out about events that occur in your account. Events reflect operations with resources or users:
- authentication and the start or end of a session in the Control panel;
- reading specific data (accessing the Secrets service, reading encryption keys, etc. );
- managing access rights and security services (users, roles, passwords, tokens, access keys, secrets, certificates, etc. );
- mutating operations on resources (creating, modifying, or deleting servers, networks, volumes, etc. ).
Audit logs contain successful and unsuccessful events, as well as events not permitted by security policies. Once an event occurs, it is added to the audit logs and becomes available within a few minutes.
Audit logs are collected automatically and stored for 90 days. You can download audit logs manually, configure automatic export to an S3 bucket, or configure export via API.
Cloud and dedicated servers
In cloud and dedicated servers, operating system events and information security events can be collected and exported to external security event management systems using free tools:
Additional options for security event generation can be implemented using utilities:
Auditd— for Linux OS;Sysmon— for Windows OS.
Managed Kubernetes
In Managed Kubernetes clusters, you can receive logs — cluster logs, container logs, and audit logs.
Cluster logs display events that occur in the cluster. For example, cluster creation, changing node groups, or updating certificates and versions. If a request was performed automatically, for example, a scheduled certificate update occurred, this action will also appear in the logs. You can view cluster logs in the Control Panel.
Container logs contain events that occur with containers. For example, creating and deleting a container. Container log files are stored in the /var/log/pods/ or /var/log/containers directory. You can view the logs of an individual container using kubectl logs <container_name>, where <container_name> is the container name. If there are many containers in a Managed Kubernetes cluster, you can configure container log delivery via Filebeat.
Audit logs display events that occur in the cluster. For example, in pods or services. These events can be initiated by users, applications, or the Control Plane. The list of events included in the logs and their parameters depend on the policy (audit policy). The policy applied to Managed Kubernetes audit logs can be found in the Selectel documentation on GitHub.
Audit logs can be sent to a security event management system. For example, to the SIEM system Wazuh. To receive audit logs from a Managed Kubernetes cluster, configure the integration.