Free cookie consent management tool by TermsFeed
Falco horizontal logo_teal2Falco
  • About
    What is Falco? Learn about Falco and how it works Why choose Falco? Benefits of Falco for runtime security Falco use cases Threat detection and regulatory compliance Case studies Discover how the industry is adopting Falco Falco ecosystem Integrations and plugins FAQ The most common questions about the whole Falco
    ecosystem
  • Docs
  • Blog
  • Community
    About the community For users and contributors Events Meet and learn about Falco Contributors The people who build Falco Falco brand Brand guidelines
  • Training
  • Versions
    v0.35 v0.34 v0.33 v0.32 v0.31 v0.30 v0.29 v0.28 v0.27 v0.26
English
中文 Chinese 한국어 Korean 日本語 Japanese മലയാളം Malayalam
Try Falco

About

What is Falco?
Learn about Falco and how it works
Why choose Falco?
Benefits of Falco for runtime security
Falco use cases
Threat detection and regulatory compliance
Case studies
Discover how the industry is adopting Falco
Falco ecosystem
Integrations and plugins
FAQ
The most common questions about the whole Falco
ecosystem

Docs

Blog

Community

About the community
For users and contributors
Events
Meet and learn about Falco
Contributors
The people who build Falco
Falco brand
Brand guidelines

Training

English
中文 Chinese 한국어 Korean 日本語 Japanese മലയാളം Malayalam
  • The Falco Project
Edit this page Create child page Create documentation issue Create project issue

Falco Rules

Default rules and macros, supported events, rule fields and examples
Rule fields

Understand what role each field in a rule plays

Default Macros

Use the default macros to simplify Falco Rules

Macros to Override

Control the behavior of some rules by enabling or disabling these default macros

Supported Events

Find out which events Falco supports

Supported Fields for Conditions and Outputs

Events fields that you can use in conditions and outputs of Falco Rules

Rules Examples

Several examples of Falco Rules

Was this page helpful?

Let us know! You feedback will help us to improve the content and to stay in touch with our users.

Glad to hear it! Please tell us how we can improve.

Sorry to hear that. Please tell us how we can improve.


About Docs Blog Community Training
© 2023 The Falco Authors | Documentation Distributed under CC BY 4.0
© 2023 The Linux Foundation ®. All Rights Reserved
The Linux Foundation has registered trademarks and uses trademarks. For a list of trademarks of The Linux Foundation, please see our Trademark Usage page. Privacy Policy and Terms of Use.