mirror of
https://github.com/falcosecurity/falco.git
synced 2025-09-17 07:18:26 +00:00
Instead of running bash as the sysdig container does, run falco. This makes sense as falco doesn't have a general purpose use like sysdig does. To make it easier to run both in docker and as a daemon using the default command line, enable both syslog and stdout/stderr output by default. Now that falco dups stdout/stderr to /dev/null when daemonizing, the stdout/stderr is just thrown away. And when running in docker, the syslog output will just be discarded unless someone plumbs the container's syslog output. Update README.md to reflect that specifying the falco command is not necessary.