mtremsal
02/25/2019, 8:54 PMinotify
-based file_events
table, how do you handle containers? Specifically:
- how do you dynamically configure osquery to apply FIM queries to new containerd containers?
- how do you get container metadata, such as k8s pod and deployment info, added to each file_event
result?8p8c
02/25/2019, 10:41 PMmtremsal
02/26/2019, 3:39 PM