You must complete this task on the following cluster/nodes:
Cluster:trace
Master node:master
Worker node:worker1
You can switch the cluster/configuration context using the following command:
[desk@cli] $kubectl config use-context trace
Given: You may use Sysdig or Falco documentation.
Task:
Use detection tools to detect anomalies like processes spawning and executing something weird frequently in the single container belonging to Podtomcat.
Two tools are available to use:
1. falco
2. sysdig
Tools are pre-installed on the worker1 node only.
Analyse the container's behaviour for at least 40 seconds, using filters that detect newly spawning and executing processes.
Store an incident file at/home/cert_masters/report, in the following format:
[timestamp],[uid],[processName]
Note:Make sure to store incident file on the cluster's worker node, don't move it to master node.
Jaclyn
6 months agoLatanya
6 months agoKeith
6 months agoReiko
6 months agoParis
7 months agoWilletta
7 months agoTy
7 months agoTheresia
7 months agoBillye
7 months agoHollis
7 months agoSabra
7 months agoWhitley
7 months agoBrigette
7 months agoGuru Dayal Bhatt
3 years ago