Falco Logs Suspicious Events on Your K8s and Servers




DevOps and Docker Talk: Cloud Native Interviews and Tooling show

Summary: <p>Bret and his co-host, Matt, are joined by Jason Dellaluce and Luca Guerra from Sysdig to talk about Falco, a tool I recommend for production clusters and knowing about any bad behavior on your servers. </p><p><br>Falco is a security tool I've mentioned multiple times on this show, because I mostly think that a low level security focused logging product is something that every production server needs. The ability to log unexpected events and behaviors on your Linux host is powerful and necessary to be able to audit what's really happening on your infrastructure outside of your app itself. </p><p>Falco has been a CNCF incubating project for over four years, and I was immediately drawn to it in its early days, because it was container and Kubernetes aware and it could log and alert with default rules for everything, from someone starting a shell inside a container, to a bash history file being deleted, to a container trying to talk to the Kubernetes API. </p><p>This episode will be useful for those of you new to tools like Falco and for those familiar with its basics, but also wanting to learn about newer features and use cases, which I did some learning on myself in this episode.</p><p><br><a href="https://www.youtube.com/watch?v=QqxEinKAuy8"><strong>Live recording</strong></a><strong> of the complete show from April 6, 2023 is on YouTube (Ep. #210).</strong></p><p>★Topics★<br><a href="https://falco.org">Falco website</a><br><a href="https://www.cncf.io/projects/falco/">Falco on CNCF</a><strong></strong></p><p><br></p><p><strong>Support this show and get exclusive benefits on </strong><a href="https://patreon.com/BretFisher"><strong>Patreon</strong></a><strong>, </strong><a href="https://www.youtube.com/@BretFisher"><strong>YouTube</strong></a><strong>, or </strong><a href="https://www.bretfisher.com/"><strong>bretfisher.com</strong></a><strong>!</strong></p><p>★<strong>Join my Community</strong>★<br>Get on the waitlist for my next live <a href="https://bret.courses/autodeploy"><strong>course on CI automation and gitops deployments</strong></a><br>Best coupons for my <a href="https://www.bretfisher.com/courses"><strong>Docker and Kubernetes courses</strong></a><br>Chat with us and fellow students on our Discord Server <a href="https://devops.fan/"><strong>DevOps Fans</strong></a><strong><br></strong>Grab some merch at <a href="https://bretfisher.myspreadshop.com/"><strong>Bret's Loot Box</strong></a></p><p>Homepage <a href="https://bretfisher.com/"><strong>bretfisher.com</strong></a></p><br><strong>Creators &amp; Guests</strong><ul> <li> <a href="https://podcast.bretfisher.com/people/bret-fisher">Bret Fisher</a> - Host</li> <li> <a href="https://podcast.bretfisher.com/people/cristi-cotovan">Cristi Cotovan</a> - Editor</li> <li> <a href="https://podcast.bretfisher.com/people/beth-fisher">Beth Fisher</a> - Producer</li> <li> <a href="https://podcast.bretfisher.com/people/matt-williams">Matt Williams</a> - Host</li> <li> <a href="https://podcast.bretfisher.com/people/jason-dellaluce">Jason Dellaluce</a> - Guest</li> <li> <a href="https://podcast.bretfisher.com/people/luca-guerra">Luca Guerra</a> - Guest</li> </ul> <ul> <li>(00:00) - Intro</li> <li>(02:24) - Introducing the guests</li> <li>(05:25) - What is Falco? Why do we need it?</li> <li>(08:00) - What can Falco monitor?</li> <li>(17:11) - How are events logged?</li> <li>(30:59) - Does Falco classify alerts by severity?</li> </ul>