You must complete this task on the following cluster/nodes:
Cluster:trace
Master node:master
Worker node:worker1
You can switch the cluster/configuration context using the following command:
[desk@cli] $kubectl config use-context trace
Given: You may use Sysdig or Falco documentation.
Task:
Use detection tools to detect anomalies like processes spawning and executing something weird frequently in the single container belonging to Podtomcat.
Two tools are available to use:
1. falco
2. sysdig
Tools are pre-installed on the worker1 node only.
Analyse the container's behaviour for at least 40 seconds, using filters that detect newly spawning and executing processes.
Store an incident file at/home/cert_masters/report, in the following format:
[timestamp],[uid],[processName]
Note:Make sure to store incident file on the cluster's worker node, don't move it to master node.
Jaclyn
4 months agoLatanya
5 months agoKeith
5 months agoReiko
5 months agoParis
5 months agoWilletta
5 months agoTy
5 months agoTheresia
5 months agoBillye
6 months agoHollis
6 months agoSabra
6 months agoWhitley
6 months agoBrigette
6 months agoGuru Dayal Bhatt
3 years ago