Improving tracee-rules output #581
Replies: 2 comments
-
related comment by @yanivagman #573 (comment): I think that each signature should have its own output context, which should be submitted by the signature itself. |
Beta Was this translation helpful? Give feedback.
-
more useful examples from @yanivagman #573 (comment): I think that some of these fields should not be printed on every signature match. A signature that is triggered by multiple events (connect, accept, dup, etc...) - the current event name is not relevant |
Beta Was this translation helpful? Give feedback.
-
Let's discuss how to improve the output format of tracee-rules
There are a couple of tracee-rules specific needs to address:
Finding.Context
to present is relevant--output format:/path/to/template
)Beta Was this translation helpful? Give feedback.
All reactions