Container and Host Recipes

Container and Host Recipes

Added in v0.20.0

Collection recipes for Kubernetes audit logs, Docker events, and osquery results. Each recipe gives Vector, OpenTelemetry Collector, and Grafana Alloy configs for delivering the source’s native JSON to rsigma engine daemon with --schema-routing. Vector posts to /api/v1/events (--input http); the OTel Collector and Alloy use OTLP HTTP (/v1/logs), which needs the daemon-otlp feature (release archives include it). The overview has the schema table and a combined daemon config.

Kubernetes Audit Log

Kubernetes audit events have kind: Event, apiVersion: audit.k8s.io/, auditID, verb, and user.username.

Vector
OpenTelemetry
Alloy

Option A: kube-apiserver sink

The kube-apiserver has a built-in audit webhook that forwards events in JSON. Forward to a Vector HTTP listener:

[sources.k8s]
type = http_server
address = "0.0.0.0:9006"

[sinks.rsigma]
inputs = ["k8s"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json

Option B: audit log file

Forward the audit log JSON file with a tailing file input:

[sources.k8s]
type = file
include = ["/var/log/kubernetes/audit.log"]
read_from = beginning
encoding = "ndjson"

[sinks.rsigma]
inputs = ["k8s"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json
receivers:
  filelog:
    include: [/var/log/kubernetes/audit.log]
    operators:
      - type: json_parser
        parse_to: body
processors:
  batch: {}
exporters:
  otlphttp/rsigma:
    endpoint: "http://localhost:8952"
    compression: none
service:
  pipelines:
    logs:
      receivers: [filelog]
      processors: [batch]
      exporters: [otlphttp/rsigma]
otelcol.exporter.otlphttp "rsigma" {
    client {
        endpoint = "http://localhost:8952"
    }
}

otelcol.receiver.filelog "k8s" {
    include  = ["/var/log/kubernetes/audit.log"]
    start_at = "beginning"

    operators = [{
        type     = "json_parser",
        parse_to = "body",
    }]

    output {
        logs = [otelcol.exporter.otlphttp.rsigma.input]
    }
}

Docker Events

Docker events (docker events --format json or the API events endpoint) carry Type, Action, and Actor. The docker_events signature (specificity 70) uses these fields for recognition.

Vector
OpenTelemetry
Alloy
[sources.docker]
type = docker_events
format = pretty

[sinks.rsigma]
inputs = ["docker"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json

The native docker input (which taps into the Docker Engine API directly) may not capture all events the CLI --format json form does. Use the Docker Engine API’s /events endpoint via curl or a dedicated library for full coverage.

receivers:
  filelog:
    include: [/var/log/docker/events.json]
    operators:
      - type: json_parser
        parse_to: body
processors:
  batch: {}
exporters:
  otlphttp/rsigma:
    endpoint: "http://localhost:8952"
    compression: none
service:
  pipelines:
    logs:
      receivers: [filelog]
      processors: [batch]
      exporters: [otlphttp/rsigma]

Pipe docker events --format json into the file, or use a small sidecar that writes the Engine API /events stream as NDJSON.

otelcol.exporter.otlphttp "rsigma" {
    client {
        endpoint = "http://localhost:8952"
    }
}

otelcol.receiver.filelog "docker" {
    include  = ["/var/log/docker/events.json"]
    start_at = "beginning"

    operators = [{
        type     = "json_parser",
        parse_to = "body",
    }]

    output {
        logs = [otelcol.exporter.otlphttp.rsigma.input]
    }
}

osquery

osquery sends result lines (one JSON per table query) to configured log destinations. Each result carries name, action (added/removed/snapshot), hostIdentifier, and columns.

Vector
OpenTelemetry
Alloy
[sources.osquery]
type = file
include = ["/var/log/osquery/*.log"]
read_from = beginning

[sinks.rsigma]
inputs = ["osquery"]
type = http
uri = "http://localhost:8952/api/v1/events"
encoding.codec = json
receivers:
  filelog:
    include: [/var/log/osquery/*.log]
    operators:
      - type: json_parser
        parse_to: body
processors:
  batch: {}
exporters:
  otlphttp/rsigma:
    endpoint: "http://localhost:8952"
    compression: none
service:
  pipelines:
    logs:
      receivers: [filelog]
      processors: [batch]
      exporters: [otlphttp/rsigma]
otelcol.exporter.otlphttp "rsigma" {
    client {
        endpoint = "http://localhost:8952"
    }
}

otelcol.receiver.filelog "osquery" {
    include  = ["/var/log/osquery/*.log"]
    start_at = "beginning"

    operators = [{
        type     = "json_parser",
        parse_to = "body",
    }]

    output {
        logs = [otelcol.exporter.otlphttp.rsigma.input]
    }
}

See also