How to Import from Google Cloud Kubernetes Engine
The / Forensic Acquisition and Investigation platform allows you to collect key logs and forensic artifacts from Google Cloud Kubernetes Engine (GKE) containers.
Known Limitations
- / Forensic Acquisition and Investigation can acquire artifacts from containers built with distroless containers and private clusters using / Forensic Acquisition and Investigation Host only. Containers with the 
gcr.io/distrolessimage tag will be hidden. For more details, see Kubernetes Deployments. - / Forensic Acquisition and Investigation will hide pods running under the following namespaces, which are generally system-level namespaces running a distroless environment:
kube-system,kube-public,kube-node-leasegke-gmp-system,aks-commandgmp-system,calico-system,tigera-operator