One question about the <https://kodekloud.com/courses/1378608/lectures/31733998> . . .

beyler:
One question about the https://kodekloud.com/courses/1378608/lectures/31733998 It’s mentioned that audit log can be store on an auditt file or send to falco. Could you provide the way to configure it with falco ?

Fernando Jordan Silva:
You have to enable the integration in falco ( https://falco.org/docs/event-sources/kubernetes-audit/ ) to listen to audit events. In falco you will find a configuration file ( k8s_audit_rule.yaml ) where you can configure which audit events you want falco to listen

Fernando Jordan Silva:
Please be careful with the falco’s version because in old versions falco used a dynamic webhook for audit events and now that way is deprecated and is not working anymore

beyler:
Thanks @Fernando Jordan Silva