diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 68236a34..8849d1c3 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -426,7 +426,7 @@ tags: [filesystem] - list: safe_etc_dirs - items: [/etc/cassandra, /etc/ssl/certs/java, /etc/logstash, /etc/nginx/conf.d, /etc/container_environment] + items: [/etc/cassandra, /etc/ssl/certs/java, /etc/logstash, /etc/nginx/conf.d, /etc/container_environment, /etc/hrmconfig] - macro: fluentd_writing_conf_files condition: (proc.name=start-fluentd and fd.name in (/etc/fluent/fluent.conf, /etc/td-agent/td-agent.conf))