---
title: "Auditing Kubernetes API activity"
description: "How can you reconstruct user activity from Kubernetes audit events?"
status: "coming-soon"
language: "en"
canonical: "https://bulnik.dev/en/articles/topics/T33.10/"
topicId: "T33.10"
---

> Coming soon — this article is being prepared. Below are its question, intended outcome, and place in the story.

## The question

How can you reconstruct user activity from Kubernetes audit events?

## What we will work through

Reconstruct user activity from Kubernetes audit events.

## Before you begin

Previously covered: Application access to the Kubernetes API; Audit logs and product event logs.

- [Application access to the Kubernetes API](/en/articles/topics/T33.05/)
- [Audit logs and product event logs](/en/articles/topics/T23.08/)
