Falco Community Call - January 17, 2024
Author: Melissa Kilby (@incertum)
Proposals
docs(proposals): introduce on host anomaly detection framework Falco proposal PR.
wip: new(userspace/libsinsp): MVP CountMinSketch Powered Probabilistic Counting and Filtering libs draft PR.
New plugin anomalydetection
New family of plugin -> creates a new class of libsinsp state, in addition to new filterchecks (Field Extraction). No event source plugin, instead on top of existing event sources. Also leverages existing libsinsp filter fields to create composite fields.