Monitoring Linux system calls with Falco

Conclusion

Falco is a system call monitoring solution that lets you create your own rules and then log or output events that match those rules. You set up Falco on a single, monolithic Linux system, or you can use it in a distributed setting. Falco is used extensively for monitoring Kubernetes systems.

The Author

Michael K. Aboagye is a systems security engineer interested in deploying secured virtualised systems as well as securing monolith and distributed systems.

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • Kernel News

     

  • File Inspector

    Spotify, the Internet music service, collects data about its users and their taste in music. Mike Schilli requested a copy of his files to investigate them with Go.

  • Core Technologies

    Look for intruders and study the health of your system with Linux auditing tools.

  • auditctl

    Use the kernel auditing system to set watches on critical files and system calls and log the activity for later anaylsis.

  • Security Lessons: auditd

    The auditd tool can provide system logging capabilities to satisfy even the most paranoid users.

comments powered by Disqus