You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The current analyze mode is a replacement of the previous tracee-rules binary but misses many new features developed since then.
It needs to support at least a few things, such as:
access to process tree information through data sources
access to container enrichment info through data sources
For the data source to be available to the analyze mode, some steps being taken during the pipe line stages will have to be disabled (like realtime procfs access) and the data source might have to be serialized in a way it can be consumed later (for example).
The text was updated successfully, but these errors were encountered:
rafaeldtinoco
changed the title
Change analyze mode to use the normal pipeline
Analyze mode should support same (or similar) features as regular pipeline.
Oct 10, 2023
The current analyze mode is a replacement of the previous tracee-rules binary but misses many new features developed since then.
It needs to support at least a few things, such as:
For the data source to be available to the analyze mode, some steps being taken during the pipe line stages will have to be disabled (like realtime procfs access) and the data source might have to be serialized in a way it can be consumed later (for example).
The text was updated successfully, but these errors were encountered: