Skip to content

Commit 2a87787

Browse files
committed
Update security events docs
Added some missed updates to CE version. Fixed an outdated prerequisite in CC version. DOCS-2386
1 parent c158876 commit 2a87787

7 files changed

Lines changed: 170 additions & 28 deletions

File tree

‎calico-cloud/threat/security-event-management.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Security events indicate that a threat actor may be present in your Kubernetes c
2020

2121
**Required**
2222

23-
-- [Container threat detection is enabled](./container-threat-detection)
23+
- [WAF is enabled](./web-application-firewall.mdx)
2424

2525
**Limitations**
2626

‎calico-cloud_versioned_docs/version-21-2/threat/security-event-management.mdx‎

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ Security events indicate that a threat actor may be present in your Kubernetes c
2020

2121
**Required**
2222

23-
-- [Container threat detection is enabled](./container-threat-detection)
23+
- [WAF is enabled](./web-application-firewall.mdx)
2424

2525
**Limitations**
2626

@@ -31,7 +31,7 @@ Security events indicate that a threat actor may be present in your Kubernetes c
3131

3232
The **Security Events Dashboard** page gives you a high-level view of recent security events.
3333
You can use this visual reference to get an overall sense of your cluster's health.
34-
If you find anything that merits further investigation, you can click on an event for more details.
34+
If you find anything that merits further investigation, you can click on an event for more details.
3535

3636
* In the web console, go to **Threat defense > Security Events Dashboard**.
3737

@@ -40,7 +40,7 @@ If you find anything that merits further investigation, you can click on an even
4040
## Security Events
4141

4242
The **Security Events** page lists all the security events that have been detected for your cluster.
43-
You can view and filter your security events to focus on
43+
You can view and filter your security events to focus on
4444

4545
* In the web console, go to **Threat Defense > Security Events**.
4646

@@ -119,4 +119,4 @@ Security events generated from older managed clusters will not have values for t
119119

120120
**Where can I view security event logs?**
121121

122-
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.
122+
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.

‎calico-enterprise/threat/security-event-management.mdx‎

Lines changed: 40 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,13 @@ Manage security events from your cluster in a single place.
88

99
## Value
1010

11-
Security events indicate that a threat actor may be present in your cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
11+
Security events indicate that a threat actor may be present in your Kubernetes cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
1212

1313
- A filtered list of critical events with recommended remediation
1414
- Identify impacts on applications
1515
- Understand the scope and frequency of the issue
1616
- Manage alert noise by dismissing events (show/hide)
17+
- Manage alert noise by creating exceptions
1718

1819
## Before you begin
1920

@@ -26,9 +27,44 @@ Security events indicate that a threat actor may be present in your cluster. For
2627
- Only WAF basic security events. Over time, the dashboard will contain a full range of $[prodname] security events.
2728
- You cannot control which users can view or edit the page using fine-grained role-based access controls
2829

29-
## Security events dashboard
30+
## Security Events Dashboard
3031

31-
In the web console, go to **Threat defense**, **Security Events**.
32+
The **Security Events Dashboard** page gives you a high-level view of recent security events.
33+
You can use this visual reference to get an overall sense of your cluster's health.
34+
If you find anything that merits further investigation, you can click on an event for more details.
35+
36+
* In the web console, go to **Threat defense > Security Events Dashboard**.
37+
38+
![Security Events Dashboard](/img/calico-enterprise/security-events-dashboard.png)
39+
40+
## Security Events
41+
42+
The **Security Events** page lists all the security events that have been detected for your cluster.
43+
You can view and filter your security events to focus on
44+
45+
* In the web console, go to **Threat Defense > Security Events**.
46+
47+
### Dismiss a security event
48+
49+
You can clear your security events list by dismissing events that you've finished reviewing.
50+
When you dismiss an event, that event is no longer visibile in the list.
51+
52+
1. In the web console, go to **Threat Defense > Security Events**.
53+
1. Find a security event in the list, and then click **Action > Dismiss Security Event**.
54+
55+
### Create a security event exception
56+
57+
You can prevent certain kinds of security events from appearing in the list by creating a security event exception.
58+
This is helpful if you want to reduce alert noise for workloads that you know are safe.
59+
When you create an exception, all matching security events are removed from the security events list.
60+
Future matches will not appear in the list.
61+
62+
1. In the web console, go to **Threat Defense > Security Events**.
63+
1. Find a security event in the list, and then click **Action > Add exception**.
64+
1. On the **Create an Exception** dialog, select a scope for the exception and click **Create Exception**.
65+
66+
You can manage your exceptions by clicking **Threat Defense > Security Events > Exceptions**.
67+
You can browse, edit, and delete exceptions on the list.
3268

3369
### UI help
3470

@@ -83,4 +119,4 @@ Security events generated from older managed clusters will not have values for t
83119

84120
**Where can I view security event logs?**
85121

86-
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.
122+
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.

‎calico-enterprise_versioned_docs/version-3.19-2/threat/security-event-management.mdx‎

Lines changed: 5 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,12 +1,10 @@
11
---
2-
description: Get alerts on threats in a single dashboard.
2+
description: Manage security events from your cluster in a single place.
33
---
44

55
# Security event management
66

7-
## Big picture
8-
9-
Get alerts on security events in a single dashboard.
7+
Manage security events from your cluster in a single place.
108

119
## Value
1210

@@ -33,7 +31,7 @@ Security events indicate that a threat actor may be present in your Kubernetes c
3331

3432
The **Security Events Dashboard** page gives you a high-level view of recent security events.
3533
You can use this visual reference to get an overall sense of your cluster's health.
36-
If you find anything that merits further investigation, you can click on an event for more details.
34+
If you find anything that merits further investigation, you can click on an event for more details.
3735

3836
* In the web console, go to **Threat defense > Security Events Dashboard**.
3937

@@ -42,7 +40,7 @@ If you find anything that merits further investigation, you can click on an even
4240
## Security Events
4341

4442
The **Security Events** page lists all the security events that have been detected for your cluster.
45-
You can view and filter your security events to focus on
43+
You can view and filter your security events to focus on
4644

4745
* In the web console, go to **Threat Defense > Security Events**.
4846

@@ -121,4 +119,4 @@ Security events generated from older managed clusters will not have values for t
121119

122120
**Where can I view security event logs?**
123121

124-
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.
122+
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.

‎calico-enterprise_versioned_docs/version-3.20-2/threat/security-event-management.mdx‎

Lines changed: 40 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,13 @@ Manage security events from your cluster in a single place.
88

99
## Value
1010

11-
Security events indicate that a threat actor may be present in your cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
11+
Security events indicate that a threat actor may be present in your Kubernetes cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
1212

1313
- A filtered list of critical events with recommended remediation
1414
- Identify impacts on applications
1515
- Understand the scope and frequency of the issue
1616
- Manage alert noise by dismissing events (show/hide)
17+
- Manage alert noise by creating exceptions
1718

1819
## Before you begin
1920

@@ -26,9 +27,44 @@ Security events indicate that a threat actor may be present in your cluster. For
2627
- Only WAF basic security events. Over time, the dashboard will contain a full range of $[prodname] security events.
2728
- You cannot control which users can view or edit the page using fine-grained role-based access controls
2829

29-
## Security events dashboard
30+
## Security Events Dashboard
3031

31-
In the web console, go to **Threat defense**, **Security Events**.
32+
The **Security Events Dashboard** page gives you a high-level view of recent security events.
33+
You can use this visual reference to get an overall sense of your cluster's health.
34+
If you find anything that merits further investigation, you can click on an event for more details.
35+
36+
* In the web console, go to **Threat defense > Security Events Dashboard**.
37+
38+
![Security Events Dashboard](/img/calico-enterprise/security-events-dashboard.png)
39+
40+
## Security Events
41+
42+
The **Security Events** page lists all the security events that have been detected for your cluster.
43+
You can view and filter your security events to focus on
44+
45+
* In the web console, go to **Threat Defense > Security Events**.
46+
47+
### Dismiss a security event
48+
49+
You can clear your security events list by dismissing events that you've finished reviewing.
50+
When you dismiss an event, that event is no longer visibile in the list.
51+
52+
1. In the web console, go to **Threat Defense > Security Events**.
53+
1. Find a security event in the list, and then click **Action > Dismiss Security Event**.
54+
55+
### Create a security event exception
56+
57+
You can prevent certain kinds of security events from appearing in the list by creating a security event exception.
58+
This is helpful if you want to reduce alert noise for workloads that you know are safe.
59+
When you create an exception, all matching security events are removed from the security events list.
60+
Future matches will not appear in the list.
61+
62+
1. In the web console, go to **Threat Defense > Security Events**.
63+
1. Find a security event in the list, and then click **Action > Add exception**.
64+
1. On the **Create an Exception** dialog, select a scope for the exception and click **Create Exception**.
65+
66+
You can manage your exceptions by clicking **Threat Defense > Security Events > Exceptions**.
67+
You can browse, edit, and delete exceptions on the list.
3268

3369
### UI help
3470

@@ -83,4 +119,4 @@ Security events generated from older managed clusters will not have values for t
83119

84120
**Where can I view security event logs?**
85121

86-
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.
122+
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.

‎calico-enterprise_versioned_docs/version-3.21-2/threat/security-event-management.mdx‎

Lines changed: 40 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,13 @@ Manage security events from your cluster in a single place.
88

99
## Value
1010

11-
Security events indicate that a threat actor may be present in your cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
11+
Security events indicate that a threat actor may be present in your Kubernetes cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
1212

1313
- A filtered list of critical events with recommended remediation
1414
- Identify impacts on applications
1515
- Understand the scope and frequency of the issue
1616
- Manage alert noise by dismissing events (show/hide)
17+
- Manage alert noise by creating exceptions
1718

1819
## Before you begin
1920

@@ -26,9 +27,44 @@ Security events indicate that a threat actor may be present in your cluster. For
2627
- Only WAF basic security events. Over time, the dashboard will contain a full range of $[prodname] security events.
2728
- You cannot control which users can view or edit the page using fine-grained role-based access controls
2829

29-
## Security events dashboard
30+
## Security Events Dashboard
3031

31-
In the web console, go to **Threat defense**, **Security Events**.
32+
The **Security Events Dashboard** page gives you a high-level view of recent security events.
33+
You can use this visual reference to get an overall sense of your cluster's health.
34+
If you find anything that merits further investigation, you can click on an event for more details.
35+
36+
* In the web console, go to **Threat defense > Security Events Dashboard**.
37+
38+
![Security Events Dashboard](/img/calico-enterprise/security-events-dashboard.png)
39+
40+
## Security Events
41+
42+
The **Security Events** page lists all the security events that have been detected for your cluster.
43+
You can view and filter your security events to focus on
44+
45+
* In the web console, go to **Threat Defense > Security Events**.
46+
47+
### Dismiss a security event
48+
49+
You can clear your security events list by dismissing events that you've finished reviewing.
50+
When you dismiss an event, that event is no longer visibile in the list.
51+
52+
1. In the web console, go to **Threat Defense > Security Events**.
53+
1. Find a security event in the list, and then click **Action > Dismiss Security Event**.
54+
55+
### Create a security event exception
56+
57+
You can prevent certain kinds of security events from appearing in the list by creating a security event exception.
58+
This is helpful if you want to reduce alert noise for workloads that you know are safe.
59+
When you create an exception, all matching security events are removed from the security events list.
60+
Future matches will not appear in the list.
61+
62+
1. In the web console, go to **Threat Defense > Security Events**.
63+
1. Find a security event in the list, and then click **Action > Add exception**.
64+
1. On the **Create an Exception** dialog, select a scope for the exception and click **Create Exception**.
65+
66+
You can manage your exceptions by clicking **Threat Defense > Security Events > Exceptions**.
67+
You can browse, edit, and delete exceptions on the list.
3268

3369
### UI help
3470

@@ -83,4 +119,4 @@ Security events generated from older managed clusters will not have values for t
83119

84120
**Where can I view security event logs?**
85121

86-
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.
122+
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.

‎calico-enterprise_versioned_docs/version-3.22-1/threat/security-event-management.mdx‎

Lines changed: 40 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,13 @@ Manage security events from your cluster in a single place.
88

99
## Value
1010

11-
Security events indicate that a threat actor may be present in your cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
11+
Security events indicate that a threat actor may be present in your Kubernetes cluster. For example, a DNS request to a malicious hostname, a triggered WAF rule, or the opening of a sensitive file. $[prodname] provides security engineers and incident response teams with a single dashboard to manage threat alerts. Benefits include:
1212

1313
- A filtered list of critical events with recommended remediation
1414
- Identify impacts on applications
1515
- Understand the scope and frequency of the issue
1616
- Manage alert noise by dismissing events (show/hide)
17+
- Manage alert noise by creating exceptions
1718

1819
## Before you begin
1920

@@ -26,9 +27,44 @@ Security events indicate that a threat actor may be present in your cluster. For
2627
- Only WAF basic security events. Over time, the dashboard will contain a full range of $[prodname] security events.
2728
- You cannot control which users can view or edit the page using fine-grained role-based access controls
2829

29-
## Security events dashboard
30+
## Security Events Dashboard
3031

31-
In the web console, go to **Threat defense**, **Security Events**.
32+
The **Security Events Dashboard** page gives you a high-level view of recent security events.
33+
You can use this visual reference to get an overall sense of your cluster's health.
34+
If you find anything that merits further investigation, you can click on an event for more details.
35+
36+
* In the web console, go to **Threat defense > Security Events Dashboard**.
37+
38+
![Security Events Dashboard](/img/calico-enterprise/security-events-dashboard.png)
39+
40+
## Security Events
41+
42+
The **Security Events** page lists all the security events that have been detected for your cluster.
43+
You can view and filter your security events to focus on
44+
45+
* In the web console, go to **Threat Defense > Security Events**.
46+
47+
### Dismiss a security event
48+
49+
You can clear your security events list by dismissing events that you've finished reviewing.
50+
When you dismiss an event, that event is no longer visibile in the list.
51+
52+
1. In the web console, go to **Threat Defense > Security Events**.
53+
1. Find a security event in the list, and then click **Action > Dismiss Security Event**.
54+
55+
### Create a security event exception
56+
57+
You can prevent certain kinds of security events from appearing in the list by creating a security event exception.
58+
This is helpful if you want to reduce alert noise for workloads that you know are safe.
59+
When you create an exception, all matching security events are removed from the security events list.
60+
Future matches will not appear in the list.
61+
62+
1. In the web console, go to **Threat Defense > Security Events**.
63+
1. Find a security event in the list, and then click **Action > Add exception**.
64+
1. On the **Create an Exception** dialog, select a scope for the exception and click **Create Exception**.
65+
66+
You can manage your exceptions by clicking **Threat Defense > Security Events > Exceptions**.
67+
You can browse, edit, and delete exceptions on the list.
3268

3369
### UI help
3470

@@ -83,4 +119,4 @@ Security events generated from older managed clusters will not have values for t
83119

84120
**Where can I view security event logs?**
85121

86-
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.
122+
Go to: **Logs**, Kibana index, `tigera_secure_ee_events`.

0 commit comments

Comments
 (0)