If you are using Sumo Logic, you can forward alerts from Red Hat Advanced Cluster Security for Kubernetes to Sumo Logic.
The following steps represent a high-level workflow for integrating Red Hat Advanced Cluster Security for Kubernetes with Sumo Logic:
Add a new Custom App in Sumo Logic, set the HTTP source, and get the HTTP URL.
Use the HTTP URL to integrate Sumo Logic with Red Hat Advanced Cluster Security for Kubernetes.
Identify the policies you want to send notifications for, and update the notification settings for those policies.
Use the Setup Wizard to set up Streaming Data and get the HTTP URL.
Log in to your Sumo Logic Home page and select Setup Wizard.
Move your cursor over to Set Up Streaming Data and select Get Started.
On the Select Data Type page, select Your Custom App.
On the Set Up Collection page, select HTTP Source.
Enter a name for Source Category, for example, rhacs
and click Continue.
Copy the generated URL.
Create a new integration in Red Hat Advanced Cluster Security for Kubernetes by using the HTTP URL.
On the RHACS portal, navigate to Platform Configuration → Integrations.
Scroll down to the Notifier Integrations section and select Sumo Logic.
Click New Integration (add
icon).
Enter a name for Integration Name.
Enter the generated HTTP URL in the HTTP Collector Source Address field.
Click Test (checkmark
icon) to test that the integration with Sumo Logic is working.
Click Create (save
icon) to create the configuration.
Enable alert notifications for system policies.
On the RHACS portal, navigate to Platform Configuration → Policies.
Select one or more policies for which you want to send alerts.
Under Bulk actions, select Enable notification.
In the Enable notification window, select the Sumo Logic notifier.
If you have not configured any other integrations, the system displays a message that no notifiers are configured. |
Click Enable.
|
You can view alerts from Red Hat Advanced Cluster Security for Kubernetes in Sumo Logic.
Log in to your Sumo Logic Home page and click Log Search.
In the search box, enter _sourceCategory=rhacs
.
Make sure to use the same Source Category name that you entered while configuring Sumo Logic.
Select the time and then click Start.