Vinod Kumar Nair:
Hi @Vijin Palazhi, I could not understand how to debug the logs for this specific query on Falco labs…the hint says just analyze the logs…but not sure how to trace the error that was generated as per the options given which are related to apt-get, etc…in error I do not see anything related to apt-get…any idea if I’m missing anything here, thanks:-
Jun 21 07:58:57 node01 falco[7849]: 07:58:57.014843665: Error File below /etc opened for writing (user=root user_loginuid=0 command=vi /etc/falco/falco_rules.yaml parent=bash pcmdline=bash file=/etc/falco/.falco_rules.yaml.swx program=vi gparent=sshd ggparent=sshd gggparent=systemd container_id=host image=<NA>)
Jun 21 07:58:57 node01 falco[7849]: 07:58:57.014925669: Error File below /etc opened for writing (user=root user_loginuid=0 command=vi /etc/falco/falco_rules.yaml parent=bash pcmdline=bash file=/etc/falco/.falco_rules.yaml.swp program=vi gparent=sshd ggparent=sshd gggparent=systemd container_id=host image=<NA>)
Jun 21 08:03:05 node01 falco[7849]: 08:03:05.547468556: Error File below /etc opened for writing (user=root user_loginuid=0 command=vi /etc/falco/falco_rules.yaml parent=bash pcmdline=bash file=/etc/falco/4913 program=vi gparent=sshd ggparent=sshd gggparent=systemd container_id=host image=<NA>)
Jun 21 08:03:05 node01 falco[7849]: 08:03:05.547543148: Error File below /etc opened for writing (user=root user_loginuid=0 command=vi /etc/falco/falco_rules.yaml parent=bash pcmdline=bash file=/etc/falco/falco_rules.yaml program=vi gparent=sshd ggparent=sshd gggparent=systemd container_id=host image=<NA>)
Jun 21 08:03:05 node01 falco[7849]: 08:03:05.547468556: Error File below /etc opened for writing (user=root user_loginuid=0 command=vi /etc/falco/falco_rules.yaml parent=bash pcmdline=bash file=/etc/falco/4913 program=vi gparent=sshd ggparent=sshd gggparent=systemd container_id=host image=<NA>)
Jun 21 08:03:05 node01 falco[7849]: 08:03:05.547543148: Error File below /etc opened for writing (user=root user_loginuid=0 command=vi /etc/falco/falco_rules.yaml parent=bash pcmdline=bash file=/etc/falco/falco_rules.yaml program=vi gparent=sshd ggparent=sshd gggparent=systemd container_id=host image=<NA>)