Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Falco dashboard provides no data #19

Open
khurlic opened this issue Jan 13, 2025 · 0 comments
Open

Falco dashboard provides no data #19

khurlic opened this issue Jan 13, 2025 · 0 comments

Comments

@khurlic
Copy link

khurlic commented Jan 13, 2025

I followed this blog post to the letter.
https://openobserve.ai/blog/how-to-setup-falco-on-kubernetes

I imported the dashboard from
https://raw.githubusercontent.com/openobserve/dashboards/refs/heads/main/falco_security/Kubernetes_security_dashboard.json

The data on the dashboard is empty.
After looking at the dashboard. I see that the queries are looking for body_output fields from the default stream.

Following the steps, There's nothing in the article that mentions needing to modify the queries in the dashboard or providing a function to the default stream to parse the body field in order to ensure it's translated to body_*.

https://github.com/openobserve/dashboards/blob/91893f34d82697b7b19c78ac8f3d3215cd26e1d7/falco_security/Kubernetes_security_dashboard.json#L174C38-L174C49

I would like to know what parsing function you are using for the translation.
If the parsing function can not be provided, Can you update the dashboard to use the correct fields?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant