From 27df0ad29b9ee5b989ca21b2e1cd0f654d74db89 Mon Sep 17 00:00:00 2001 From: Mark Stemm Date: Wed, 8 Nov 2017 13:38:07 -0800 Subject: [PATCH] Add nagios as a monitoring binary Runs lots of shells --- rules/falco_rules.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rules/falco_rules.yaml b/rules/falco_rules.yaml index 709cb933..674b8a4b 100644 --- a/rules/falco_rules.yaml +++ b/rules/falco_rules.yaml @@ -242,7 +242,7 @@ items: [bro, broctl] - list: monitoring_binaries - items: [icinga2, nrpe, npcd, check_sar_perf., qualys-cloud-ag, S99qualys-cloud] + items: [icinga2, nrpe, npcd, check_sar_perf., qualys-cloud-ag, S99qualys-cloud, nagios] - macro: system_procs condition: proc.name in (coreutils_binaries, user_mgmt_binaries)