Discussion about this post

User's avatar
Vandan Bhuva's avatar

The schema-first approach and utilizing the Bronze-Silver-Gold architecture makes a ton of sense for eliminating the technical debt of multi-cloud environments.

I noticed most of your examples focus on API and control plane logs. I'm really curious about your take on deep kernel telemetry like eBPF. With how noisy and complex eBPF data gets, do you actually push it through this same normalization pipeline for detections? Or do you mostly stick to native cloud logs to keep the signal-to-noise ratio manageable?

No posts

Ready for more?