Toggle navigation
Guilgo Blog
EspaƱol
English
☾
All Posts
tips
ARCHIVE
ABOUT
Guilgo Blog
Notes from my daily work with technology.
Auditing Kubernetes with Wazuh: API server audit logs into your SIEM
Webhook listener, audit policy, and custom detection rules for create/delete events
Step-by-step guide to audit Kubernetes with Wazuh: API server audit logs to the SIEM, webhook listener, audit policy and rules in local_rules.xml. Kubernetes security monitoring.
Posted by David Guillermo on Thursday, February 26, 2026
Sysadmin, self-taught by curiosity.
FEATURED TAGS
adguard
docker
homelab
kubernetes
linux
microsoft
monitoring
parental-control
powershell
security
siem
sysadmin
telegram
wazuh
wsus