aquasecurity / tracee

Linux Runtime Security and Forensics using eBPF
https://aquasecurity.github.io/tracee/latest
Apache License 2.0
3.39k stars 396 forks source link

Add support to OpenTelemetry semantic conventions #3235

Open josedonizetti opened 1 year ago

josedonizetti commented 1 year ago

We should have a printer that supports Elastic Common Schema

yanivagman commented 10 months ago

Since ecs is in the process of being merged with otel (https://github.com/open-telemetry/oteps/blob/main/text/0199-support-elastic-common-schema-in-opentelemetry.md), we should add an otel printer instead

trisch-me commented 3 months ago

Hey, I'm working on ECS donation from Elastic side, focusing more on security namespaces. We have also a proposal for security working group which should start hopefully next week.

Have you worked already on this issue or maybe you have in mind what ECS namespaces are important for your product from security perspective? I am happy to invite you to the WG if you have things to share. Thanks!

yanivagman commented 3 months ago

Hey, I'm working on ECS donation from Elastic side, focusing more on security namespaces. We have also a proposal for security working group which should start hopefully next week.

Have you worked already on this issue or maybe you have in mind what ECS namespaces are important for your product from security perspective? I am happy to invite you to the WG if you have things to share. Thanks!

Hi! We actually used ECS/OTEL as a reference when considering Tracee's new event structure: https://github.com/aquasecurity/tracee/issues/2870#issuecomment-1681701124

itaysk commented 3 months ago

@trisch-me thanks for reaching out. we have followed the contribution process (back then) and wasn't sure where it's headed. we would be happy to have a call to raise some questions/understand the ecs and otel status.

trisch-me commented 3 months ago

Hey @itaysk! thanks, let's have a talk, I will ping you on CNCF slack :)