I was about to use sysdig with the container image (on amazon linux) and I noticed that /usr/bin/scap-driver-loader and sysdig/csysdig use two different naming:
scap-driver-loader has FALCO_BPF_PROBE
the tools has SYSDIG_BPF_PROBE
Workaround: pass -e FALCO_BPF_PROBE="" -e SYSDIG_BPF_PROBE="" to docker
I was about to use sysdig with the container image (on amazon linux) and I noticed that
/usr/bin/scap-driver-loader
andsysdig
/csysdig
use two different naming:Workaround: pass
-e FALCO_BPF_PROBE="" -e SYSDIG_BPF_PROBE=""
to docker