Skip to main content

Kubernetes Activity Anomaly Alerts

Lacework generates Kubernetes-activity-based alerts when there are Kubernetes-activity-related vulnerabilities detected. You can define alert rules to trigger alerts when Kubernetes-activity-related vulnerabilities are found. See Alert Rules.

Alert List

The following table lists all the Kubernetes-activity-based alerts.

Alert NameAlert TypeAlert Subcategory
K8s audit log cluster role createdNewK8sAuditLogClusterRoleKubernetes Activity
K8s audit log cluster role binding createdNewK8sAuditLogClusterRoleBindingKubernetes Activity
K8s audit log cluster role bindings to adminNewK8sAuditLogClusterRoleBindingsToAdminKubernetes Activity
K8s audit log cluster role bindings to cluster adminNewK8sAuditLogClusterRoleBindingsToClusterAdminKubernetes Activity
K8s audit log cluster role bindings to editNewK8sAuditLogClusterRoleBindingsToEditKubernetes Activity
K8s audit log cluster role bindings to systemNewK8sAuditLogClusterRoleBindingsToSystemKubernetes Activity
K8s audit log cluster role with all resourcesNewK8sAuditLogClusterRoleWithAllResourcesKubernetes Activity
K8s audit log cluster role with pod execNewK8sAuditLogClusterRoleWithPodExecKubernetes Activity
K8s audit log cluster role with pods writeNewK8sAuditLogClusterRoleWithPodsWriteKubernetes Activity
K8s audit log cluster role with secretsNewK8sAuditLogClusterRoleWithSecretsKubernetes Activity
K8s audit log ingress createdNewK8sAuditLogIngressKubernetes Activity
K8s audit log namespace createdNewK8sAuditLogNamespaceKubernetes Activity
K8s audit log resource createdNewK8sAuditLogResourceKubernetes Activity
K8s audit log role createdNewK8sAuditLogRoleKubernetes Activity
K8s audit log role binding createdNewK8sAuditLogRoleBindingKubernetes Activity
K8s audit log role bindings to adminNewK8sAuditLogRoleBindingsToAdminKubernetes Activity
K8s audit log role bindings to cluster adminNewK8sAuditLogRoleBindingsToClusterAdminKubernetes Activity
K8s audit log role bindings to editNewK8sAuditLogRoleBindingsToEditKubernetes Activity
K8s audit log role bindings to systemNewK8sAuditLogRoleBindingsToSystemKubernetes Activity
K8s audit log role with all resourcesNewK8sAuditLogRoleWithAllResourcesKubernetes Activity
K8s audit log role with pod execNewK8sAuditLogRoleWithPodExecKubernetes Activity
K8s audit log role with pods writeNewK8sAuditLogRoleWithPodsWriteKubernetes Activity
K8s audit log role with secretsNewK8sAuditLogRoleWithSecretsKubernetes Activity
K8s audit log workload createdNewK8sAuditLogWorkloadKubernetes Activity
New K8s workload created with privilege escalationNewK8sAuditLogWorkloadAllowsEscalationKubernetes Activity
New K8s workload created with host accessNewK8sAuditLogWorkloadWithHostAccessKubernetes Activity

Suppress an Alert

Suppressing specific Kubernetes-activity alerts reduces the number of alerts and allows you to focus on the assets that are most important to you. For details, see Suppress Behavior Anomaly Alerts.