Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Configure the fields exported by events produced for Runtime Threat Detection ( node-agent) #488

Open
henrikrexed opened this issue Feb 17, 2025 · 1 comment
Assignees

Comments

@henrikrexed
Copy link

Overview

Currently the event produced by the Runtime Threat Detection provides lots of details with the k8s metadata, the process details...And more.

Problem

When collecting the logs to a o11ybackend the default size of the strings are limited. Therefore the data is cropped .
All this details consumes bytes exchanged between cloud provider ..and will end up increasing the cloud cost.

Solution

Having an option to configure a list of fields that we would like to export from the event will allow users to decide on the type of details they would like to export. this is a feature that tetragon provides to control the size of the events produced : https://tetragon.io/docs/concepts/events/#export-filtering

Alternatives

Create a Otel collector pipeline that filter the data out.

@matthyx matthyx moved this to Triage in Kubescaping Feb 18, 2025
@matthyx matthyx moved this from Triage to Feature in Kubescaping Feb 18, 2025
@matthyx
Copy link
Contributor

matthyx commented Feb 18, 2025

note to self, see if I can move it to node-agent project

@matthyx matthyx transferred this issue from kubescape/operator Feb 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: Feature
Development

No branches or pull requests

3 participants