-
Feature Request
-
Resolution: Done
-
Undefined
-
None
-
openshift-4.10
-
None
-
False
-
None
-
False
-
Not Selected
-
-
-
-
1. Proposed title of this feature request
Issue audit log only once per secret consultation when user stays on openshift console for long.
2. What is the nature and description of the request?
When user stays for long time on web console, it requests secret to the API and these details are issued in the audit logs. However, if the user stays on that page for a few hours, the audit logs continue to be issued. Reports created from the audit logs have too many lines of secret lookups. Customer is expecting to issue an audit log on secret consultation and not on regular interval. If a person changes page and comes back to the same secret, two traces must be issued.
3. Why does the customer need this? (List the business requirements here)
Customer mentioned below requirement:
In our security reports we see, incorrectly, a large number of queries to a secret, which can trigger alerts. Moreover we have to transfer more logs in our tools.
4. List any affected packages or components.
Api, openshift-console
- is related to
-
OCPSTRAT-568 Improve configuration of kube-apiserver audit logging
- Closed