elastic / ebpf

Elastic's eBPF
Other
67 stars 11 forks source link

Add COMM to process events fork/exec/exit #192

Closed haesbaert closed 6 months ago

haesbaert commented 6 months ago

This is needed by quark and it makes sense at any rate since we don't track COMM changes explicitly (setproctitle and friends).