mtremsal
02/25/2019, 8:54 PMinotify-based file_events table, how do you handle containers? Specifically:
- how do you dynamically configure osquery to apply FIM queries to new containerd containers?
- how do you get container metadata, such as k8s pod and deployment info, added to each file_event result?8p8c
02/25/2019, 10:41 PMmtremsal
02/26/2019, 3:39 PM