<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exclude noisy alerts from Falco (classicfullstack) - Warning Detected ptrace PTRACE_ATTACH attempt (proc_pcmdline=oneagenthelper in Dynatrace tips</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-tips/Exclude-noisy-alerts-from-Falco-classicfullstack-Warning/m-p/238789#M1192</link>
    <description>&lt;P&gt;&lt;SPAN class=""&gt;Hello&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;everyone!&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="falco.png" style="width: 89px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/18040i53DBEA8F3CEE6B3D/image-dimensions/89x89?v=v2" width="89" height="89" role="button" title="falco.png" alt="falco.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can see some noisy alerts from Falco&amp;nbsp; after installation Dynatrace with&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Dynatrace operator, mode classicfullstack&lt;/STRONG&gt;.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%" height="30px"&gt;&lt;SPAN&gt;Warning Detected ptrace PTRACE&lt;/SPAN&gt;&lt;SPAN&gt;_ATTACH attempt &lt;/SPAN&gt;&lt;SPAN&gt;(proc&lt;/SPAN&gt;&lt;SPAN&gt;_pcmdline&lt;/SPAN&gt;&lt;SPAN&gt;=oneagenthelper...&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;This is example alert from falco for&amp;nbsp;&lt;SPAN&gt;proc&lt;/SPAN&gt;&lt;SPAN&gt;.name&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;oneagenthelper&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Romanenkov_Al3x_0-1709544058086.png" style="width: 999px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/18037i81BE10EEE44F55F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Romanenkov_Al3x_0-1709544058086.png" alt="Romanenkov_Al3x_0-1709544058086.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To avoid this behavior you can easly add oneagenthelper in list know_ptrace_binaries:&lt;/P&gt;&lt;P&gt;1) You can easly disable this noisy alert with changing &lt;A href="https://github.com/falcosecurity/rules/blob/dc7970d175a921aa01090d10461ce76974848022/rules/falco_rules.yaml#L1090C1-L1091C12" target="_self"&gt;rules configuration&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;sudo vi /etc/falco/falco_rules.yaml&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
- list: known_ptrace_binaries
  items: []
...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) and addoneagenthelper like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
- list: known_ptrace_binaries
  items: [oneagenthelper]
...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Romanenkov_Al3x_1-1709544630851.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/18038i9E9346295ED510FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Romanenkov_Al3x_1-1709544630851.png" alt="Romanenkov_Al3x_1-1709544630851.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3) &lt;STRONG&gt;Restart service&lt;/STRONG&gt; via systemctl (to find proper service you can use: &lt;STRONG&gt;systemctl list-units | grep falco&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;sudo systemctl restart falco-modern-bpf.service&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;or&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;sudo systemctl restart falco-bpf.service&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alex Romanenkov&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2024 09:55:26 GMT</pubDate>
    <dc:creator>Romanenkov_Al3x</dc:creator>
    <dc:date>2024-03-04T09:55:26Z</dc:date>
    <item>
      <title>Exclude noisy alerts from Falco (classicfullstack) - Warning Detected ptrace PTRACE_ATTACH attempt (proc_pcmdline=oneagenthelper</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-tips/Exclude-noisy-alerts-from-Falco-classicfullstack-Warning/m-p/238789#M1192</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hello&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;everyone!&lt;span class="lia-inline-image-display-wrapper lia-image-align-right" image-alt="falco.png" style="width: 89px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/18040i53DBEA8F3CEE6B3D/image-dimensions/89x89?v=v2" width="89" height="89" role="button" title="falco.png" alt="falco.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You can see some noisy alerts from Falco&amp;nbsp; after installation Dynatrace with&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Dynatrace operator, mode classicfullstack&lt;/STRONG&gt;.&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%" height="30px"&gt;&lt;SPAN&gt;Warning Detected ptrace PTRACE&lt;/SPAN&gt;&lt;SPAN&gt;_ATTACH attempt &lt;/SPAN&gt;&lt;SPAN&gt;(proc&lt;/SPAN&gt;&lt;SPAN&gt;_pcmdline&lt;/SPAN&gt;&lt;SPAN&gt;=oneagenthelper...&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;This is example alert from falco for&amp;nbsp;&lt;SPAN&gt;proc&lt;/SPAN&gt;&lt;SPAN&gt;.name&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;oneagenthelper&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Romanenkov_Al3x_0-1709544058086.png" style="width: 999px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/18037i81BE10EEE44F55F5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Romanenkov_Al3x_0-1709544058086.png" alt="Romanenkov_Al3x_0-1709544058086.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To avoid this behavior you can easly add oneagenthelper in list know_ptrace_binaries:&lt;/P&gt;&lt;P&gt;1) You can easly disable this noisy alert with changing &lt;A href="https://github.com/falcosecurity/rules/blob/dc7970d175a921aa01090d10461ce76974848022/rules/falco_rules.yaml#L1090C1-L1091C12" target="_self"&gt;rules configuration&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;sudo vi /etc/falco/falco_rules.yaml&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
- list: known_ptrace_binaries
  items: []
...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) and addoneagenthelper like this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;...
- list: known_ptrace_binaries
  items: [oneagenthelper]
...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Romanenkov_Al3x_1-1709544630851.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/18038i9E9346295ED510FA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Romanenkov_Al3x_1-1709544630851.png" alt="Romanenkov_Al3x_1-1709544630851.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;3) &lt;STRONG&gt;Restart service&lt;/STRONG&gt; via systemctl (to find proper service you can use: &lt;STRONG&gt;systemctl list-units | grep falco&lt;/STRONG&gt;&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;sudo systemctl restart falco-modern-bpf.service&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;or&lt;/P&gt;&lt;TABLE border="1" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="100%"&gt;sudo systemctl restart falco-bpf.service&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alex Romanenkov&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 09:55:26 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-tips/Exclude-noisy-alerts-from-Falco-classicfullstack-Warning/m-p/238789#M1192</guid>
      <dc:creator>Romanenkov_Al3x</dc:creator>
      <dc:date>2024-03-04T09:55:26Z</dc:date>
    </item>
  </channel>
</rss>

