We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Describe the bug
On falco 0.31.0 I am seeing Informational rules being loaded when the priority in the config is set to only load Notice and above.
How to reproduce it
I'm running falco.yaml with:
priority: notice
with no overrides for info-level rules. However, informational rules are still being loaded, and are alerting at the Notice level.
Expected behaviour
It is expected that when priority: notice, only Notice, Warning, Error, Critical, Alert, and Emergency rules will be loaded and fired.
Screenshots
Note that this rule is supposed to be INFO level:
falco/rules/falco_rules.yaml
Lines 1886 to 1894 in f86423d
Environment
Additional context
I'm wondering if this code may be the problem:
falco/userspace/engine/lua/rule_loader.lua
Lines 61 to 66 in 2f82a9b
Note that Notice and Informational are both set to level 5.
I can open a PR from master...mike-stewart:patch-2 if that would be helpful.
The text was updated successfully, but these errors were encountered:
Potential fix for falcosecurity#1884
6f20c69
Great catch @mike-stewart ! Thank you for noticing, would you mind opening a PR?
Sorry, something went wrong.
70f7f8f
Signed-off-by: Mike Stewart <mike.stewart@introhive.com>
Potential fix for #1884
ee2f7c5
Successfully merging a pull request may close this issue.
Describe the bug
On falco 0.31.0 I am seeing Informational rules being loaded when the priority in the config is set to only load Notice and above.
How to reproduce it
I'm running falco.yaml with:
with no overrides for info-level rules. However, informational rules are still being loaded, and are alerting at the Notice level.
Expected behaviour
It is expected that when
priority: notice
, only Notice, Warning, Error, Critical, Alert, and Emergency rules will be loaded and fired.Screenshots
![Screen Shot 2022-02-01 at 5 57 39 PM](https://user-images.githubusercontent.com/2521245/152058280-50a57a26-5fa3-46cf-908e-377d2be5e2e6.png)
Note that this rule is supposed to be INFO level:
falco/rules/falco_rules.yaml
Lines 1886 to 1894 in f86423d
Environment
Additional context
I'm wondering if this code may be the problem:
falco/userspace/engine/lua/rule_loader.lua
Lines 61 to 66 in 2f82a9b
Note that Notice and Informational are both set to level 5.
I can open a PR from master...mike-stewart:patch-2 if that would be helpful.
The text was updated successfully, but these errors were encountered: