The New Stack Podcast cover image

The New Stack Podcast

How Falco Brought Real-Time Observability to Infrastructure

Dec 26, 2024
Leonardo Grasso, Open Source Tech Lead Manager at Sysdig and a core maintainer of Falco, dives into the evolution of this innovative open-source runtime observability tool. The discussion highlights Falco’s integration with eBPF technology, enabling real-time event monitoring from the kernel. Grasso reveals the journey of Falco from its early days to its recent graduation from the Cloud Native Computing Foundation. He also discusses Falco Talon, a no-code response engine that enhances security automation, making runtime security more efficient than ever.
19:27

Episode guests

Podcast summary created with Snipd AI

Quick takeaways

  • Falco utilizes eBPF technology to enhance real-time observability and security in cloud-native infrastructures by collecting kernel events.
  • The introduction of Falco Talon provided a no-code response engine, enabling real-time automated actions in response to security alerts.

Deep dives

Overview of Falco and Its Purpose

Falco is an open-source cloud-native security runtime designed to monitor and secure cloud infrastructures by detecting suspicious events in real time. Developed by Sysdig, Falco aims to address the gap in security monitoring post-deployment, where traditional methods focus primarily on static code analysis. It operates by collecting system events directly from the kernel and uses context such as pod names and namespaces to enrich this data, enabling it to identify anomalous behaviors. This proactive approach distinguishes Falco from other security tools that rely solely on pre-deployment vulnerability scans.

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode