Closed lclin56 closed 7 months ago
Hey @lclin56! Thank you for the issue! As far as I know, the behaviour that you are describing is the expected behaviour and I couldn't think of a way to solve the issue. 🤔 However, this behaviour is not directly managed by sysdig but it's delegated to the libs
(https://github.com/falcosecurity/libs , the main building block of sysdig). Feel free to open an issue there! 😄
Hey @therealbobo! Thank you for your response. I will try to solve this problem with an alternative approach.
I want to trace all descendant processes created after specifying proc.apid=xxx to track them from pid=xxx (for example, the pid of a sh session). However, when I try the following demo, sysdig loses track of the child processes.
After the parent process exits, the child process is managed by the process with pid=1, and at that point, its proc.apid becomes the pid of that process. Considering specifying proc.name or proc.aname in the tracking conditions can solve the issue of losing track of orphan processes when the process name doesn't change. However, in cases like the one in my demo, proc.name or proc.aname also changes. Is there any way to solve my problem? Currently, the only solution I can think of is running the target program inside a container and tracking events for the entire container.