The API server audit log files should be rotated once the file reaches 100 MB or more

Set up the kubernetes integration.

This page is not yet available in Spanish. We are working on its translation.
If you have any questions or feedback about our current translation project, feel free to reach out to us!

Description

On the API server, the log file should be at least 100 MB in size prior to log rotation. Retaining old log files ensures that you have sufficient log data available for carrying out any investigation or correlation.

Remediation

Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the master node and set the --audit-log-maxsize parameter to an appropriate size in MB.

PREVIEWING: dgreen15/adding-custom-entities