Data Source: Kubernetes Falco

Description

Data source object for Kubernetes Falco

Details

Property Value
Source kubernetes
Sourcetype kube:container:falco

Event Fields

+ Fields
  <span class="pill kill-chain">_time</span>
  
  <span class="pill kill-chain">command</span>
  
  <span class="pill kill-chain">container_id</span>
  
  <span class="pill kill-chain">container_image</span>
  
  <span class="pill kill-chain">container_image_tag</span>
  
  <span class="pill kill-chain">container_name</span>
  
  <span class="pill kill-chain">date_hour</span>
  
  <span class="pill kill-chain">date_mday</span>
  
  <span class="pill kill-chain">date_minute</span>
  
  <span class="pill kill-chain">date_month</span>
  
  <span class="pill kill-chain">date_second</span>
  
  <span class="pill kill-chain">date_wday</span>
  
  <span class="pill kill-chain">date_year</span>
  
  <span class="pill kill-chain">date_zone</span>
  
  <span class="pill kill-chain">evt_type</span>
  
  <span class="pill kill-chain">exe_flags</span>
  
  <span class="pill kill-chain">host</span>
  
  <span class="pill kill-chain">index</span>
  
  <span class="pill kill-chain">k8s_ns</span>
  
  <span class="pill kill-chain">k8s_pod_name</span>
  
  <span class="pill kill-chain">linecount</span>
  
  <span class="pill kill-chain">parent</span>
  
  <span class="pill kill-chain">proc_exepath</span>
  
  <span class="pill kill-chain">process</span>
  
  <span class="pill kill-chain">punct</span>
  
  <span class="pill kill-chain">source</span>
  
  <span class="pill kill-chain">sourcetype</span>
  
  <span class="pill kill-chain">splunk_server</span>
  
  <span class="pill kill-chain">terminal</span>
  
  <span class="pill kill-chain">timeendpos</span>
  
  <span class="pill kill-chain">timestartpos</span>
  
  <span class="pill kill-chain">user</span>
  
  <span class="pill kill-chain">user_loginuid</span>
  
  <span class="pill kill-chain">user_uid</span>
  
</div>

Example Log

112:18:18.691725165: Notice A shell was spawned in a container with an attached terminal (evt_type=execve user=root user_uid=0 user_loginuid=-1 process=bash proc_exepath=/usr/lib/splunk-otel-collector/agent-bundle/bin/bash parent=runc command=bash -il terminal=34816 exe_flags=EXE_WRITABLE container_id=7a2566e8e462 container_image=quay.io/signalfx/splunk-otel-collector container_image_tag=0.88.0 container_name=otel-collector k8s_ns=default k8s_pod_name=my-splunk-otel-collector-agent-9sdhr)

Source: GitHub | Version: 1