eBPF Security Monitoring
Prerequisites
Section titled “Prerequisites”Before getting started, make sure you have:
- AlertKick account set up (see Account Setup)
- Server monitoring configured (see Server Monitoring)
- Root or sudo access to your Linux servers
- Understanding of your security requirements
Installing eBPF Security Agents
Section titled “Installing eBPF Security Agents”eBPF technology provides real-time security event detection and monitoring for your Linux servers.
Installing eBPF Security Agents
Section titled “Installing eBPF Security Agents”- Navigate to Security -> eBPF Agents
- Select your server from the list
- Click “Install eBPF Agent”
- Follow the installation instructions provided in the Security section
- Verify installation by checking the agent status
Creating Security Profiles
Section titled “Creating Security Profiles”Security profiles define what security events to monitor:
Creating Security Profiles
Section titled “Creating Security Profiles”- Go to Security -> Security Profiles
- Click “Create New Profile”
- Configure profile settings:
- Profile Name: “Sensitive File Monitoring”
- Description: “Monitor changes to critical system files”
- Add security rules:
- File Changes: Monitor changes to
/etc/directory - SSH Access: Track SSH logins at specific times
- Privilege Escalation: Monitor sudo usage
- Network Connections: Track suspicious network activities
- File Changes: Monitor changes to
Assigning Security Profiles
Section titled “Assigning Security Profiles”- Navigate to Security -> eBPF Agents
- Select your server
- Assign security profile: Choose your custom or default profile
- Configure event streaming: Ensure events are sent to AlertKick backend
Security Alert Configuration
Section titled “Security Alert Configuration”Security Alert Escalation
Section titled “Security Alert Escalation”Create separate escalation policies for security events:
- Create new policy: “Security Alerts”
- Configure immediate escalation: Security events need faster response
- Set shorter timeouts: 2-5 minutes for critical security events
- Include security team: Ensure security specialists are notified
Advanced Security Features
Section titled “Advanced Security Features”- Time-based routing: Different policies for business hours vs. after hours
- Severity-based routing: Critical vs. warning alerts
- Server-based routing: Different teams for different server types
- Security-specific routing: Separate escalation for security events
Testing Security Monitoring
Section titled “Testing Security Monitoring”Test Security Monitoring
Section titled “Test Security Monitoring”- Verify eBPF agent: Check that the eBPF agent is running and connected
- Test security events: Trigger test events (e.g., modify files in
/etc/) - Check event streaming: Verify events appear in AlertKick UI under Events
- Test security alerts: Ensure security events trigger appropriate alerts
- Review event dashboard: Check that events are properly categorized
Security Event Dashboard
Section titled “Security Event Dashboard”Use the AlertKick security dashboard to:
- View security events: See all eBPF security events
- Monitor active security alerts: Track current security issues
- Review event patterns: Analyze security event trends
- Security team performance: Monitor response times to security events
- Generate security reports: Create reports for security stakeholders
Best Practices
Section titled “Best Practices”Security Monitoring
Section titled “Security Monitoring”- Start with basic security profiles: Use predefined security rules for common security scenarios
- Customize security rules: Create specific rules for your environment’s security needs
- Monitor sensitive areas: Focus on
/etc/,/home/, and other critical directories - Set up security alerts: Configure immediate alerts for critical security events
- Regular security review: Update security profiles based on threat landscape changes
Security Team Management
Section titled “Security Team Management”- Include security specialists: Ensure team members with security expertise are on-call
- Clear security procedures: Document who gets notified for security events
- Security incident reviews: Learn from security event responses
- Regular security training: Keep team updated on security monitoring features
Troubleshooting
Section titled “Troubleshooting”Common Issues
Section titled “Common Issues”Security events not appearing:
- Verify eBPF agent installation and status
- Check security profile assignment
- Review event streaming configuration
- Test with manual security events
Security alerts not triggering:
- Check security alert thresholds
- Verify security escalation policies
- Review security team assignments
- Test with critical security events
eBPF agent not connecting:
- Check network connectivity from server to AlertKick
- Verify eBPF agent token is correct
- Review firewall settings for agent traffic
- Check eBPF agent service status
Next Steps
Section titled “Next Steps”After setting up security monitoring:
- Configure alerts and escalation - See Escalation Policies
- Set up team rosters - See Roster Management
Support
Section titled “Support”Need help with security monitoring? Contact our support team at support [at] alertkick [dot] com or check out our complete documentation.