Skip to content

Commit

Permalink
Add container check to Clear Log Activities rule
Browse files Browse the repository at this point in the history
Signed-off-by: Brenno Oliveira <brenno.oliveira@deliveryhero.com>
  • Loading branch information
brennoo authored and poiana committed Oct 7, 2023
1 parent d119706 commit 93310c5
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions rules/falco_rules.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -928,6 +928,7 @@
relevant to your environment, and adjust the profiled containers you wish not to be alerted on.
condition: >
open_write
and container
and access_log_files
and evt.arg.flags contains "O_TRUNC"
and not trusted_logging_images
Expand Down

0 comments on commit 93310c5

Please sign in to comment.