Kubernetes
Use the IBM® QRadar® Custom Properties for Kubernetes to closely monitor your Kubernetes deployment.
Important: To avoid content errors in this content extension, keep the associated DSMs
up to date. DSMs are updated as part of the automatic updates. If automatic updates are not enabled,
download the most recent version of the associated DSMs from IBM Fix Central
(https://www.ibm.com/support/fixcentral).
IBM Security QRadar Custom Properties for Kubernetes
IBM Security QRadar Custom Properties for Kubernetes V1.0.2
The following table shows the custom properties that are new or updated in IBM Security QRadar Custom Properties for Kubernetes V1.0.2.
Name | Optimized | Capture Group | Expressions |
---|---|---|---|
Container Image | Yes |
|
IBM Security QRadar Custom Properties for Kubernetes V1.0.1
The following table shows the custom properties that are new or updated in IBM Security QRadar Custom Properties for Kubernetes V1.0.1.
Name | Optimized | Capture Group | Expressions |
---|---|---|---|
Namespace | Yes | 1 | objectRef[\":{]resource[":]+namespaces[\":]+,[\"]+name":"(.*?)" |
Privileged Container | Yes | 1 | securityContext[\":\{]privileged[":](true) |
Priviliged Container Name | No | 1 | securityContext[\":{]+privileged[":]+true}+,[\":\{]+name":"(.*?)" |
Source Mount Point | Yes | 1 | volumeMounts"\:[{.*?\"mountPath[\":]([^\"]) |
IBM Security QRadar Custom Properties for Kubernetes V1.0.0
The following table shows the custom properties in IBM Security QRadar Custom Properties for Kubernetes V1.0.0.
Name | Optimized | Regex Capture Group | Expressions |
---|---|---|---|
API Path | No |
|
|
Container Image | No |
|
|
Container Name | No |
|
|
MessageID | No |
|
|
Namespace | Yes |
|
|
Privileged Container | Yes | 1 |
|
Priviliged Container Name | No | 1 |
|
Process CommandLine | Yes |
|
|
Reason | Yes |
|
|
Resource | Yes |
|
|
Resource Name | Yes |
|
|
Role | Yes |
|
|
Role Actions | Yes |
|
|
Role Assigned Resources | Yes |
|
|
Target User Name | Yes | 1 |
|
User Agent | No |
|