User Guide

Cloud Pulse

Operational monitoring that sits next to your cost data — logs, security, health, and Kubernetes observability, unified across Azure, AWS, and GCP.

One operational picture#

Cloud Pulse is CCO's operations module. It pulls the signals you'd otherwise chase across a dozen consoles into one place, normalized across clouds and scoped to what each user is allowed to see.

📜

Logs & network logs

Activity, diagnostic, and audit logs, plus NSG/VPC flow, firewall, and WAF logs — with multi-source filtering by action, direction, protocol, and IP.
🛡️

Security findings

Defender for Cloud (posture and threat alerts), AWS Security Hub and GuardDuty, and GCP Security Command Center — one severity-ranked feed.
🎯

Ops insights & alerts

Advisor, Trusted Advisor, Compute Optimizer, and Recommender guidance, alongside Monitor, CloudWatch, and Cloud Monitoring alarms.
☸️

Kubernetes observability

Live pod logs and cluster events via the K8s Log Explorer, plus CPU/memory utilization metrics.

Logs#

Fetch logs over a preset window or an exact custom range for troubleshooting a specific incident. Network logs get their own view with source→destination flow, action badges, and per-provider columns.

  • ✓Activity / diagnostic / audit logs across all three clouds
  • ✓Network logs — NSG/VPC flow, firewall, and WAF (9 sources)
  • ✓Search by IP, rule, or resource; filter by action, direction, and protocol
  • ✓Retention is tunable — high-volume flow logs kept shorter than activity logs

Security and ops#

Security findings and ops recommendations are normalized so a critical finding reads the same whether it came from Defender, GuardDuty, or Security Command Center.

Critical findings become alerts
A critical security finding automatically surfaces in the Alerts & Notifications hub and can fire a notification rule — no extra wiring. The provider advisors also feed the Ops Recommendations report, kept distinct from CCO's own cost-savings recommendations.

Kubernetes Log Explorer#

A stateless, real-time view into your clusters — nothing is stored:

  • ✓Cascading selectors: connection → namespace → pod → container
  • ✓Terminal-style pod logs with color-coded levels and live streaming
  • ✓Cluster events in a filterable table
  • ✓Respects each connection's namespace scope
Tip
Cloud Pulse's Kubernetes metrics feed CCO's right-sizing recommendations, and its security findings pair with Cloud Map's static analysis of container configuration — the modules reinforce each other.