AWS EKS Log Monitoring

Integration Overview

AWS Elastic Kubernetes Service (EKS) is a managed Kubernetes service that allows you to easily deploy, manage, and scale containerized applications using Kubernetes. Using EKS, you can run Kubernetes on AWS without the need to manage your own Kubernetes control plane or worker nodes. Panther can collect, normalize, and monitor EKS logs to help you identify suspicious activity in real time. Your normalized data is then retained to power future security investigations in a serverless data lake powered by Snowflake.

Use Cases for EKS Audit Logs

EKS audit logs provide a record of the individual users, administrators, or system components that have affected your cluster. Common security use cases for EKS logs include:

  • Detecting any unauthorized access attempts within your Kubernetes environment
  • Triggering alerts when resources are out of compliance
  • Using AWS EKS to simplify compliance auditing and reporting

Onboarding EKS Logs in Panther

Panther supports ingesting AWS EKS logs via AWS S3. To pull EKS logs into Panther, you’ll need to enable EKS control plane logging in AWS to direct your EKS logs to CloudWatch logs, and then configure a Kinesis Data Firehose to transport them to a S3 bucket.

For more detailed steps on onboarding AWS EKS logs or for supported log schema, you can view our AWS EKS documentation here.

Parsing, Normalizing, and Analyzing

As Panther ingests AWS EKS logs, they are parsed, normalized, and stored in a Snowflake security data lake. This allows security teams to write detections, detect anomalies, and conduct investigations on logs in the context of days, weeks, or months of data.

Panther applies normalization fields to all log records, which standardizes names for attributes and empowers users to correlate data across all log types. Panther’s search tools empower you to investigate your normalized logs for suspicious activity or vulnerabilities. For more on searching log data in Panther, check out our documentation on Investigations & Search.

Detection as Code

With Panther, your team won’t be confined to rigid detection rules as seen in most legacy SIEM platforms. Panther is built with detection-as-code principles, allowing you to use Python to define detection logic and to integrate external systems like version control and CI/CD pipelines into your detection engineering workflows. This results in powerful, flexible, and reusable scripting of detections for your security team.

Pre-built detections for EKS logs are available by default in Panther, offering users immediate value for monitoring common IoCs and threats. You can explore our built-in detection coverage for EKS here.

Configuring Alerts

Panther fires alerts when your detection rules or policies are triggered, and integrates with a variety of alert destinations to allow for easy access and management of any EKS alerts. Alerts can also be sent to alert context or SOAR platforms for more remediation options.

Alerts are categorized within five different severity levels: Info, Low, Medium, High, and Critical. Security teams have the option to dynamically assign severity level based on specific log event attributes.

Customer Support

If you have any questions about configuring or monitoring EKS logs in Panther, we’re here to help. All customers have access to our technical support team via a dedicated Slack channel, email, or in-app messenger.

You can view our documentation on EKS and monitoring AWS EKS logs here, or customers can sign up for the Panther Community to share best practices or custom detections for monitoring EKS.

The Ideal SIEM for AWS EKS

With Panther, security teams don’t have to pay skyrocketing costs to keep up with cloud data volume, struggle with restrictive detection logic, or waste time and resources on operational overhead. Panther was founded by a team of veteran security practitioners who struggled with legacy SIEM challenges first-hand, and built an intuitive, cloud-native platform to solve them.

Panther is a cloud-native SIEM built for security operations at scale, offering flexible detection-as-code, intuitive security workflows, and actionable real-time alerts to keep up with the needs of today’s security teams. For a powerful, flexible, and scalable SIEM solution for AWS EKS, request a demo today.

Escape Cloud Noise. Detect Security Signal.
Request a Demo