Skip to content

Webhook from Tracee-eBPF Directly? #732

Discussion options

You must be logged in to vote

Yes Tracee-eBPF doesn't can't call a webhook. This is by design, since raw trace is very verbose and an HTTP callback is not the best in this case, so Tracee-eBPF writes to a file which is a bit more suitable for the volume and velocity of events. Also, we consider Tracee-eBPF an internal component of Tracee, and the integration features (like webhook) are applied to Tracee and not that internal component.

If you can't read from the file, here's a quick workaround that will help you achieve what you wanted: just create a new Tracee Rule that matches everything. The effect is that when you run Tracee it will "detect" every raw event and call the webhook.Let me know if that needs clarificat…

Replies: 1 comment 5 replies

Comment options

You must be logged in to vote
5 replies
@itaysk
Comment options

@Brambopulos
Comment options

@itaysk
Comment options

@Brambopulos
Comment options

@itaysk
Comment options

Answer selected by Brambopulos
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants