This skill covers WizTelemetry Auditing, the KubeSphere observability component that collects, processes and stores audit events from Kubernetes and KubeSphere. The extension ships a single component, `kube-auditing`, enabled by default, and requires two others to be present: the WizTelemetry Platform Service and the WizTelemetry Data Pipeline. It also explains how audit events are collected and how to read them back through the audit query API.
Prerequisites come first: list the clusters and have you confirm the targets unless you named them, then look up the latest extension version. The InstallPlan has to be named `whizard-auditing`. Its YAML config must follow the provided template exactly, with no extra fields and no change to the structure, and every placeholder must be replaced with a real value before the plan is applied.