We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
This issue keeps track of all deprecated Falco features that will be removed in Falco 1.0.0:
append
override
- rule: Write below etc enabled: false
- rule: Write below etc enabled: false override: enabled: replace
enabled
- rule: legit_rule desc: legit rule description condition: evt.type=open output: user=%user.name command=%proc.cmdline file=%fd.name priority: INFO enabled: false
The text was updated successfully, but these errors were encountered:
Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale.
/remove-lifecycle stale
Stale issues rot after an additional 30d of inactivity and eventually close.
If this issue is safe to close now please do so with /close.
/close
Provide feedback via https://github.com/falcosecurity/community.
/lifecycle stale
Sorry, something went wrong.
#3162 deprecated old rules_file config key in favor of new rules_files.
rules_file
rules_files
No branches or pull requests
This issue keeps track of all deprecated Falco features that will be removed in Falco 1.0.0:
append
in Falco rule is deprecated in favor ofoverride
(see update(rule_loader): deprecate theappend
flag in falco rules #2992)override
(see update(rule_loader): deprecate theappend
flag in falco rules #2992).enabled
key is only deprecated when used as an override! So a rule like this is perfectly legit:The text was updated successfully, but these errors were encountered: