Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

New command 'search' #653

Open
Issif opened this issue Oct 28, 2024 · 4 comments
Open

New command 'search' #653

Issif opened this issue Oct 28, 2024 · 4 comments

Comments

@Issif
Copy link
Member

Issif commented Oct 28, 2024

What would you like to be added:

A new command search:

  • to search for rules, lists and macros
  • the search can be global among all rules listed in the registries or filtered/scoped
  • the search can be by registry, by rule name, by priority, by source, by source version, by status (enabled/disabled), by engine version
  • allow to search for the dependencies of the rules (macros/lists), of the macros (macros/lists)
  • allow to search for the "children" of "macros" and "lists" (rules using them)
  • the search can be global among all rules listed in the registries or filtered/scoped

Why is this needed:

This will allow the users to find the rules files to install for their use cases, and see more easily what attack patterns are covered

@TusharMohapatra07
Copy link

Hey @Issif, Iam new to Go and cncf in general. I was exploring some projects to contribute to and came across this issue. Will i (being completely new to the code base) able to help in resolving this issue ?

@Issif
Copy link
Member Author

Issif commented Nov 4, 2024

Hi and welcome @TusharMohapatra07,

This feature might be hard for a beginner in Go and with the project, it requires a lot of skills and deep understanding of the usages from the users. We discussed with @alacuku about it, we should expose more specs if you want to do it anyway.

@TusharMohapatra07
Copy link

@Issif Thanks for your consideration. I'll probably study the codebase a little bit and then try working on this. Please don't assign me this issue as we may lose any potential contributor who might fix this issue quickly and efficiently. I'd love to have a chat with you and the team about the project so please do share any public channel for this.

@Issif
Copy link
Member Author

Issif commented Nov 4, 2024

Join us on the official Slack channel: https://kubernetes.slack.com #falco

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants