Monitoring Linux system calls with Falco

Conclusion

Falco is a system call monitoring solution that lets you create your own rules and then log or output events that match those rules. You set up Falco on a single, monolithic Linux system, or you can use it in a distributed setting. Falco is used extensively for monitoring Kubernetes systems.

The Author

Michael K. Aboagye is a systems security engineer interested in deploying secured virtualised systems as well as securing monolith and distributed systems.

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • Kernel News

     

  • File Inspector

    Spotify, the Internet music service, collects data about its users and their taste in music. Mike Schilli requested a copy of his files to investigate them with Go.

  • Core Technologies

    Look for intruders and study the health of your system with Linux auditing tools.

  • auditctl

    Use the kernel auditing system to set watches on critical files and system calls and log the activity for later anaylsis.

  • Security Lessons: auditd

    The auditd tool can provide system logging capabilities to satisfy even the most paranoid users.

comments powered by Disqus
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Subscribe to our ADMIN Newsletters

Support Our Work

Linux Magazine content is made possible with support from readers like you. Please consider contributing when you’ve found an article to be beneficial.

Learn More

News