Closed spyer closed 3 months ago
This is a good point and an easy fix. I'll work on that asap.
Thanks
Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale
.
Stale issues rot after an additional 30d of inactivity and eventually close.
If this issue is safe to close now please do so with /close
.
Provide feedback via https://github.com/falcosecurity/community.
/lifecycle stale
/remove-lifecycle stale
FYI, I created an issue to do the change at the Falco level, this is why PR is still WIP https://github.com/falcosecurity/falco/issues/2985
Will be fixed in the upcoming 2.29
Thank you!
Describe the bug Opsgenie output duplicates time in the output field and it's messes up with alert grouping in opsgenie, resulting in hundreds of alerts for each log entry.
related rule (standard one):
Discussion on this issue can also be found here: https://lists.cncf.io/g/cncf-falco-dev/topic/falco_falcosidekick_and/84086875
How to reproduce it
Run falco + falco sidekick with opsgenie output
Expected behaviour Remove evt.time (which I thnik added by falco itself), since it's not in the rule template.
Or add capability to edit output field.
Screenshots
Environment
Falco version: 0.36.0 falcosidekick: 2.29.0-rc.3
System info: { "machine": "x86_64", "nodename": "preprod-app-01", "release": "5.15.0-3.60.5.1.el9uek.x86_64", "sysname": "Linux", "version": "#2 SMP Wed Oct 19 20:27:31 PDT 2022" }
OS: Oracle Linux Server release 9.1