Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add analog of sysdig's -pk, -pc, -pm to provide container/k8s/mesos specific information #131

Closed
mstemm opened this issue Oct 12, 2016 · 0 comments · Fixed by #134
Closed

Comments

@mstemm
Copy link
Contributor

mstemm commented Oct 12, 2016

Currently, all falco rules provide general information for each notification that contains host-level information like the process name, arguments, file being read/written/etc, network connection, etc.

It would be nice if you could also provide container level information like the container name, kubernetes level information like the pod, mesos level information like the app, etc. in the notification output, without having to add it to each rule's output format string.

Sysdig does this via -pk, -pc, and -pm arguments that change the default output format. We could do a similar thing here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant