mirror of
https://github.com/falcosecurity/falco.git
synced 2025-09-13 05:22:34 +00:00
Updated Falco Default and Local Rules Files (markdown)
@@ -2,6 +2,8 @@ Starting with Falco 0.8.0, falco officially supports the notion of a _default_ r
|
||||
|
||||
The default rules file is always read first, followed by the local rules file.
|
||||
|
||||
When installed via rpm/debian packages, both rules files, as well as the falco configuration file, are flagged as "config" files, meaning they are not overridden on package upgrade/uninstall if modified.
|
||||
|
||||
## Default Rules File
|
||||
|
||||
The default falco rules file is installed at `/etc/falco/falco_rules.yaml`. It contains a predefined set of rules designed to provide good coverage in a variety of situations. The intent is that this rules file is not modified, and is replaced with each new software version.
|
||||
|
Reference in New Issue
Block a user