Support
How to get help and support
First Aid
The first things to check when Edge is not doing what you expect, in the order that finds the cause fastest.
Emergency Fix - Disable Interception:
If you suspect that the Edge is not working properly but don't have time to investigate, you should first disable all interception rules by adding a skip rule for all namespaces.
rules:
- name: "emergency-skip-all"
action: skip
scope:
namespace: allComplete Removal:
If disabling interception is not enough, you can remove Edge completely. It's still recommended to disable all interception first. Uninstalling leaves the auditty namespace and the node directory /var/lib/auditty/edge (lines not yet archived to the Vault) for you to remove.
helm uninstall auditty-edge -n audittyWhat Happens After Changes:
- Disabling interception takes effect within about a minute (a fleet rule within seconds)
- Logs will continue to flow normally without any Auditty modifications
- Complete removal will delete all Auditty pods from the cluster
- You can safely reinstall/reconfigure at any time
Contact Us
How to reach the Auditty support team for assistance.
Email Support:
We will respond as soon as possible.
When Contacting Support:
- Include your cluster information and Auditty version
- Describe the issue and steps to reproduce
- Include relevant pod logs if available
- Mention if this is a POC or production environment
Common Issues
Pods Not Starting
Check the pod status and logs:
kubectl get pods -n auditty
kubectl logs -n auditty -l app.kubernetes.io/name=auditty-edge --max-log-requests=50Common causes: insufficient resources, RBAC issues, image pull errors
Logs Not Being Intercepted
Verify your rules are configured correctly:
kubectl get configmap auditty-config -n auditty -o yamlEnsure intercept rules match your workload namespaces and names
High Resource Usage
Check resource consumption:
kubectl top pods -n audittyIf resource usage is high, consider reducing scope of intercept rules or increasing resource limits
Metrics Not Showing in Auditty
Metrics leave the cluster through Edge API every 5 minutes, so a node that just started appears in Auditty within a few minutes. Check its logs for delivery errors:
kubectl logs -n auditty -l app.kubernetes.io/name=auditty-edge-api --since=1h | grep -i "hivemind\|error"Check that hivemind_api_key is correct and network policies allow egress. If you run with edgeApi.enabled: false, check the DaemonSet pods (app.kubernetes.io/name=auditty-edge) instead; they send metrics directly.
License Expired
If the dashboard shows a license-expiry banner, your Edge license has expired. Edge has a 3-day grace period after expiration; during this window it continues processing logs normally. Within 12 hours of the grace period ending, Edge stops intercepting and your logs flow unchanged; an Edge restarted after that will not start until the license is renewed.
Contact [email protected] to renew your license. After renewal, update the license in your ConfigMap/secret and restart Edge; an Edge whose license expired has stopped intercepting and does not resume on its own:
kubectl rollout restart -n auditty daemonset/auditty-edgeDebugging Tips
View Edge Logs
kubectl logs -n auditty -l app.kubernetes.io/name=auditty-edge --max-log-requests=50 --tail=100 -fCheck Configuration
kubectl get configmap auditty-config -n auditty -o yamlVerify RBAC
kubectl auth can-i get pods --as=system:serviceaccount:auditty:auditty-edge-api -n audittyK8s API RBAC (pods, deployments, etc.) is granted to the Edge API service account, not the DaemonSet; the DaemonSet itself has no ClusterRole.
Check DaemonSet Status
kubectl get daemonset -n auditty
kubectl describe daemonset auditty-edge -n audittyFrequently Asked Questions
Does Auditty Edge affect my application performance?
No. Edge works on the node, on logs your containers have already written; your application does not wait on it.
Can I temporarily disable Auditty without uninstalling?
Yes. Add a skip rule for all namespaces (see Emergency Fix above); interception stops within about a minute while Edge keeps running.
What happens if an Edge pod restarts?
Every line is kept. On a clean stop Edge stops intercepting before it exits, and each container’s output flows on as it did before Auditty. On an unexpected exit, Kubernetes restarts it at once and the new process does the same within milliseconds of starting; every line the containers wrote in between reaches your platform.
Can I customize resource limits?
Yes. Adjust the daemonSet.resources section in your values.yaml file during installation or upgrade.
How do I upgrade to a new version?
Use helm upgrade with the new version tag. Your configuration will be preserved.
helm upgrade auditty-edge oci://ghcr.io/auditty/helm-charts/auditty-edge --version <new-tag> -n auditty --values values.yamlWhat happens when my license expires?
See License Expired above: three days of grace, then Edge stops intercepting within 12 hours and your logs flow unchanged until the license is renewed and Edge restarted.