Wazuh and Kubernetes: collecting cluster audit logs and seeing who does what (part 5/6)
Part 5 of the Wazuh series: taking the SIEM beyond individual hosts and into Kubernetes — audit policy and its levels, shipping logs with Fluent Bit, a decoder for audit JSON, and rules for exec, secrets reads, and privileged pods mapped to MITRE ATT&CK for Containers.