| name | cis-gke-v170-5.7.1 |
| description | Ensure Logging and Cloud Monitoring is Enabled (Automated) |
| category | cis-gke |
| version | 1.7.0 |
| author | cyberstrike-official |
| tags | ["cis","gke","kubernetes","gcp","logging","monitoring","cloud-operations","stackdriver"] |
| cis_id | 5.7.1 |
| cis_benchmark | CIS Google Kubernetes Engine (GKE) Benchmark v1.7.0 |
| tech_stack | ["kubernetes","gcp","gke"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
5.7.1 Ensure Logging and Cloud Monitoring is Enabled (Automated)
Profile Applicability
Description
Send logs and metrics to a remote aggregator to mitigate the risk of local tampering in the event of a breach.
Rationale
Exporting logs and metrics to a dedicated, persistent datastore such as Cloud Operations for GKE ensures availability of audit data following a cluster security event, and provides a central location for analysis of log and metric data collated from multiple sources.
Impact
None.
Audit
Using Google Cloud Console:
LOGGING AND CLOUD MONITORING SUPPORT (PREFERRED):
- Go to Kubernetes Engine by visiting https://console.cloud.google.com/kubernetes/list
- From the list of clusters, click on the cluster of interest.
- Under the details pane, within the Features section, ensure that
Logging is Enabled.
- Also ensure that
Cloud Monitoring is Enabled.
LEGACY STACKDRIVER SUPPORT:
This option cannot be checked in the GCP console.
Using Command Line:
LOGGING AND CLOUD MONITORING SUPPORT (PREFERRED):
Run the following commands:
gcloud container clusters describe <cluster_name> --zone <compute_zone> --format json | jq '.loggingService'
gcloud container clusters describe <cluster_name> --zone <compute_zone> --format json | jq '.monitoringService'
The output of the above commands should return logging.googleapis.com/kubernetes and monitoring.googleapis.com/kubernetes respectively if Logging and Cloud Monitoring is Enabled.
LEGACY STACKDRIVER SUPPORT:
Note: This functionality was decommissioned on 31st March 2021, kept here for posterity (see: https://cloud.google.com/stackdriver/docs/deprecations/legacy for more information).
Both Logging and Monitoring support must be enabled.
For Logging, run the following command:
gcloud container clusters describe <cluster_name> --zone <compute_zone> --format json | jq '.loggingService'
The output should return logging.googleapis.com if Legacy Stackdriver Logging is Enabled.