Improving tracee-rules output #581
Replies: 2 comments
-
|
related comment by @yanivagman #573 (comment): I think that each signature should have its own output context, which should be submitted by the signature itself. |
Beta Was this translation helpful? Give feedback.
-
|
more useful examples from @yanivagman #573 (comment): I think that some of these fields should not be printed on every signature match. A signature that is triggered by multiple events (connect, accept, dup, etc...) - the current event name is not relevant |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Let's discuss how to improve the output format of tracee-rules
There are a couple of tracee-rules specific needs to address:
Finding.Contextto present is relevant--output format:/path/to/template)Beta Was this translation helpful? Give feedback.
All reactions