Closed juju4 closed 7 years ago
We haven't yet done a falco release that incorporates sysdig code that implements proc.pcmdline. 0.5.0 was released Dec 22, and we added proc.pcmdline to the ruleset on Jan 20. Falco does depend on sysdig code, but it pulls it in at compile time so it's separate from any sysdig version that's installed.
I do plan on a falco release in the next couple of weeks, though.
I'm about to release 0.6.0, so I'll close this for now. Try 0.6.0 out and let me know if you still run into this problem.
I still get this issue when trying latest ruleset event with recent sysdig update
=> force to disable parent_ansible_running_python