This document outlines the steps to set up a Google Kubernetes Engine (GKE) cluster, run Quark to capture eBPF events, and ship them to Elasticsearch using a repurposed Auditbeat. The goal is to verify that system events are enriched with Kubernetes ECS metadata (container.*, orchestrator.*, etc.).
Ensure you have the following tools installed on your local machine (Debian/Ubuntu assumed):