Skip to content

eBPF Security Monitoring

Before getting started, make sure you have:

  • AlertKick account set up (see Account Setup)
  • Server monitoring configured (see Server Monitoring)
  • Root or sudo access to your Linux servers
  • Understanding of your security requirements

eBPF technology provides real-time security event detection and monitoring for your Linux servers.

  1. Navigate to Security -> eBPF Agents
  2. Select your server from the list
  3. Click “Install eBPF Agent”
  4. Follow the installation instructions provided in the Security section
  5. Verify installation by checking the agent status

Security profiles define what security events to monitor:

  1. Go to Security -> Security Profiles
  2. Click “Create New Profile”
  3. Configure profile settings:
    • Profile Name: “Sensitive File Monitoring”
    • Description: “Monitor changes to critical system files”
  4. Add security rules:
    • File Changes: Monitor changes to /etc/ directory
    • SSH Access: Track SSH logins at specific times
    • Privilege Escalation: Monitor sudo usage
    • Network Connections: Track suspicious network activities
  1. Navigate to Security -> eBPF Agents
  2. Select your server
  3. Assign security profile: Choose your custom or default profile
  4. Configure event streaming: Ensure events are sent to AlertKick backend

Create separate escalation policies for security events:

  1. Create new policy: “Security Alerts”
  2. Configure immediate escalation: Security events need faster response
  3. Set shorter timeouts: 2-5 minutes for critical security events
  4. Include security team: Ensure security specialists are notified
  • Time-based routing: Different policies for business hours vs. after hours
  • Severity-based routing: Critical vs. warning alerts
  • Server-based routing: Different teams for different server types
  • Security-specific routing: Separate escalation for security events
  1. Verify eBPF agent: Check that the eBPF agent is running and connected
  2. Test security events: Trigger test events (e.g., modify files in /etc/)
  3. Check event streaming: Verify events appear in AlertKick UI under Events
  4. Test security alerts: Ensure security events trigger appropriate alerts
  5. Review event dashboard: Check that events are properly categorized

Use the AlertKick security dashboard to:

  • View security events: See all eBPF security events
  • Monitor active security alerts: Track current security issues
  • Review event patterns: Analyze security event trends
  • Security team performance: Monitor response times to security events
  • Generate security reports: Create reports for security stakeholders
  1. Start with basic security profiles: Use predefined security rules for common security scenarios
  2. Customize security rules: Create specific rules for your environment’s security needs
  3. Monitor sensitive areas: Focus on /etc/, /home/, and other critical directories
  4. Set up security alerts: Configure immediate alerts for critical security events
  5. Regular security review: Update security profiles based on threat landscape changes
  1. Include security specialists: Ensure team members with security expertise are on-call
  2. Clear security procedures: Document who gets notified for security events
  3. Security incident reviews: Learn from security event responses
  4. Regular security training: Keep team updated on security monitoring features

Security events not appearing:

  • Verify eBPF agent installation and status
  • Check security profile assignment
  • Review event streaming configuration
  • Test with manual security events

Security alerts not triggering:

  • Check security alert thresholds
  • Verify security escalation policies
  • Review security team assignments
  • Test with critical security events

eBPF agent not connecting:

  • Check network connectivity from server to AlertKick
  • Verify eBPF agent token is correct
  • Review firewall settings for agent traffic
  • Check eBPF agent service status

After setting up security monitoring:

  1. Configure alerts and escalation - See Escalation Policies
  2. Set up team rosters - See Roster Management

Need help with security monitoring? Contact our support team at support [at] alertkick [dot] com or check out our complete documentation.