For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-cev.md. A documentation index is available at /llms.txt.

GKE clusters should have monitoring and logging enabled

Description

This control validates the configuration of logging and monitoring on GKE Clusters. Exporting logs and metrics to a dedicated, persistent datastore such as Cloud Operations for GKE ensures availability of audit data following a cluster security event, and provides a central location for analysis of log and metric data collected from multiple sources.

Remediation

To enable audit logs for your GKE cluster, see Observability for GKE.