Skip to content

Commit 7507b93

Browse files
bcmmbagabragininimlsmaycon
authored
[management] Network traffic events docs (#291)
* Rename Network Activity Logging to Audit Activity Logging Signed-off-by: bcmmbaga <[email protected]> * refactor the audit events doc Signed-off-by: bcmmbaga <[email protected]> * add management traffic event doc Signed-off-by: bcmmbaga <[email protected]> * Update audit events logging image Signed-off-by: bcmmbaga <[email protected]> * Update event streaming image Signed-off-by: bcmmbaga <[email protected]> * Update src/pages/how-to/traffic-events-logging.mdx Co-authored-by: Misha Bragin <[email protected]> * Update src/pages/how-to/traffic-events-logging.mdx Co-authored-by: Misha Bragin <[email protected]> * Update src/pages/how-to/traffic-events-logging.mdx Co-authored-by: Misha Bragin <[email protected]> * Update docs to clarify feature availability Signed-off-by: bcmmbaga <[email protected]> * add link --------- Signed-off-by: bcmmbaga <[email protected]> Co-authored-by: Misha Bragin <[email protected]> Co-authored-by: Maycon Santos <[email protected]>
1 parent 94a6853 commit 7507b93

File tree

7 files changed

+54
-8
lines changed

7 files changed

+54
-8
lines changed
14.1 KB
Loading
359 KB
Loading
Binary file not shown.
428 KB
Loading

src/components/NavigationDocs.jsx

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,8 @@ export const docsNavigation = [
158158
{
159159
title: 'Activity',
160160
links: [
161-
{ title: 'Network Activity Logging', href: '/how-to/monitor-system-and-network-activity' },
161+
{ title: 'Audit Events Logging', href: '/how-to/audit-events-logging' },
162+
{ title: 'Traffic Events Logging', href: '/how-to/traffic-events-logging' },
162163
{
163164
title: 'Stream Activity Events',
164165
href: '/how-to/activity-event-streaming',

src/pages/how-to/monitor-system-and-network-activity.mdx renamed to src/pages/how-to/audit-events-logging.mdx

Lines changed: 7 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
1-
# Network Activity Logging
1+
# Audit Events Logging
22

3-
The network activity logging functionality in NetBird allows you to observe and track changes to your network infrastructure.
3+
The Audit events logging functionality in NetBird allows you to observe and track changes to your network infrastructure.
44
This includes events such as when a new machine or user has joined your network, when access control policies have been modified,
55
and many other key network events.
66

@@ -11,11 +11,11 @@ To get started with event logging in NetBird, watch this introductory video:
1111
<iframe width="560" height="315" src="https://www.youtube.com/embed/UlnMo1KYXPU?si=JdzEr9v2EZHlP7lc" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen></iframe>
1212

1313

14-
## Access the Activity Logging View
15-
The activity logging feature is enabled by default for every NetBird network. You can access the activity log in the web UI under the [Activity tab](https://app.netbird.io/activity). This view provides a centralized log of network events. You can use the search bar to search by activity name, and apply filters for timeframes, event types, and users.
14+
## Access the Audit Events Logging View
15+
The audit events logging feature is enabled by default for every NetBird network. You can access the activity log in the web UI under the [Audit Events tab](https://app.netbird.io/events/audit). This view provides a centralized log of network events. You can use the search bar to search by activity name, and apply filters for timeframes, event types, and users.
1616

1717
<p>
18-
<img src="/docs-static/img/how-to-guides/activity-monitoring.webp" alt="activity-monitoring" className="imagewrapper-big"/>
18+
<img src="/docs-static/img/how-to-guides/activity-monitoring.png" alt="activity-monitoring" className="imagewrapper-big"/>
1919
</p>
2020

2121
The current version of NetBird tracks a wide range of network changes that occur in the Management server, such as modifications to peers, groups, system settings, setup keys, and access control policies.
@@ -120,9 +120,9 @@ Future versions will also support connection events that occur in NetBird agents
120120
If the configuration files have been generated by the `configure.sh` script, you can find the previous encryption key in the backup files in the same folder as the script. Look for the <b>DataStoreEncryptionKey</b> field in the `management.json` backup file.
121121
</Note>
122122

123-
## Enable Activity Event Streaming to SIEM Systems
123+
## Enable Audit Events Streaming to SIEM Systems
124124

125-
NetBird can stream activity events to your Security Information and Event Management (SIEM) system in real-time. With this feature enabled, you can monitor and analyze NetBird network changes within your SIEM infrastructure. Check the [integrations guide](/how-to/activity-event-streaming) for more information about the supported integrations and how to enable them.
125+
NetBird can stream audit events to your Security Information and Event Management (SIEM) system in real-time. With this feature enabled, you can monitor and analyze NetBird network changes within your SIEM infrastructure. Check the [integrations guide](/how-to/activity-event-streaming) for more information about the supported integrations and how to enable them.
126126

127127
## Get Started
128128

Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
# Traffic Events Logging
2+
3+
<Note>
4+
This feature is available only in the NetBird cloud and on the [Business plan](https://www.netbird.io/pricing?utm_source=docs&utm_content=traffic-events).
5+
It is an experimental feature, and its functionality and behavior may evolve, including changes to how data is collected
6+
or reported.
7+
To use this feature, ensure you have NetBird client version 0.39 or higher.
8+
</Note>
9+
10+
11+
The traffic events logging functionality enables comprehensive monitoring and analysis of connections across your infrastructure.
12+
It captures network activity, including peer-to-peer, site-to-site, peer-to-resource, and other network traffic events.
13+
14+
It provides detailed visibility into connections and network traffic flow, helping to answer key questions such as who initiated
15+
the connection, what resource was accessed, when it happened, where it originated, and why it was allowed. By enhancing
16+
network monitoring capabilities, it strengthens security measures and delivers actionable operational insights, empowering
17+
you to better manage and secure your environment.
18+
19+
20+
## Enabling Traffic Events Logging
21+
22+
Traffic events logging is disabled by default. To enable it on the NetBird dashboard, navigate to `Settings > Networks`.
23+
Under the Experimental section, you’ll find the `Enable Traffic Events` option. Toggle the switch to enable traffic event logging.
24+
25+
By default, traffic reporting in userspace is always enabled, providing basic logging of network interactions.
26+
However, packet size reporting at the kernel level is disabled by default to minimize CPU usage.
27+
28+
<Note>
29+
You can optionally enable `Traffic Reporting (Kernel)` to capture additional details, such as network packet sizes,
30+
at the kernel level. Be aware that enabling this option may lead to higher CPU usage on the NetBird client.
31+
</Note>
32+
33+
34+
<p>
35+
<img src="/docs-static/img/how-to-guides/traffic-events-logging-settings.png" alt="traffic-events-logging-settings" className="imagewrapper-big"/>
36+
</p>
37+
38+
39+
## Enable Traffic Events Streaming to SIEM Systems
40+
41+
NetBird allows you to stream traffic events directly to your Security Information and Event Management (SIEM) system in real time.
42+
By enabling this feature, you can seamlessly monitor and analyze NetBird network flow events within your existing SIEM infrastructure,
43+
enhancing your ability to detect and respond to security events.
44+
45+
For detailed instructions on supported integrations and how to set them up, refer to the [integrations guide](/how-to/activity-event-streaming).

0 commit comments

Comments
 (0)