The New Stack Podcast

How Falco Brought Real-Time Observability to Infrastructure

7 snips
Dec 26, 2024
Leonardo Grasso, Open Source Tech Lead Manager at Sysdig and a core maintainer of Falco, dives into the evolution of this innovative open-source runtime observability tool. The discussion highlights Falco’s integration with eBPF technology, enabling real-time event monitoring from the kernel. Grasso reveals the journey of Falco from its early days to its recent graduation from the Cloud Native Computing Foundation. He also discusses Falco Talon, a no-code response engine that enhances security automation, making runtime security more efficient than ever.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Falco's Real-Time Approach

  • Falco collects real-time system events directly from the kernel, enriching them with metadata like pod names.
  • Unlike static analysis tools, Falco monitors events as they occur, correlating them with customizable rules to detect suspicious activity.
INSIGHT

Falco's Use of eBPF

  • Falco leverages eBPF technology for enhanced safety and performance in interacting with the kernel.
  • While eBPF simplifies installation, Falco also maintains support for its original kernel module for broader compatibility.
ANECDOTE

From User to Maintainer

  • Thomas Labarussias, initially an SRE and Falco community member, used Falco in production for years.
  • Sysdig later hired him, recognizing his expertise and dedication to the open-source project.
Get the Snipd Podcast app to discover more snips from this episode
Get the app