Skip to content

Conversation

Aegrah
Copy link
Contributor

@Aegrah Aegrah commented Jun 17, 2025

Summary

This rule is very noisy, as runc and other management tools are constantly ran through non-interactive shells, via e.g. busybox in minikube. This tuning reduces noise from 30k+ alerts last 30d to 40.

@tradebot-elastic
Copy link

tradebot-elastic commented Jun 17, 2025

⛔️ Test failed

Results
  • ❌ Container Management Utility Run Inside A Container (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
@tradebot-elastic
Copy link

tradebot-elastic commented Jun 17, 2025

⛔️ Test failed

Results
  • ❌ Container Management Utility Run Inside A Container (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
@tradebot-elastic
Copy link

tradebot-elastic commented Jun 17, 2025

⛔️ Test failed

Results
  • ❌ Container Management Utility Run Inside A Container (eql)
    • coverage_issue: no_rta
    • stack_validation_failed: no_rta
@Aegrah Aegrah merged commit 103fbf1 into main Jun 17, 2025
85 of 117 checks passed
@Aegrah Aegrah deleted the tuning-management-tool-ran-in-container branch June 17, 2025 12:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment