Thomas Labarussias, SRE & Falcosidekick Creator
Jonah Jones, Containers Partner Solutions Architect, AWS
Falcosidekick is an open-source micro service based event aggregator and forwarder with a UI for viewing Falco data in time-series format. Falcosidekick was originally developed by Thomas Labarussias, and is a community project for the Incubating CNCF project Falcosecurity. The Falcosidekick application is a data aggregation point which is capable of receiving, filtering, enriching, displaying, and forwarding falco events to over 35 different sources. This talk will cover some of the design decisions made to make Falcosidekick scalable when handling large amounts of data, and inputs. In addition we talk about enriching, and filtering event’s in real-time for forwarding, and discuss how the data path looks from kernel to alert. We will conclude with a demo of using Falcosidekick to react and alert on Security events in your Kubernetes cluster detected by Falco.
Learn more about CNDM Days, subscribe to the CNDM Days newsletter to receive updates about webinars, events, and latest news: https://cndmday.com/