Event Sources

Falco can consume events from a variety of different sources and apply rules to these events to detect abnormal behavior.

Falco natively supports the System Call event source (syscall) via the drivers. Since Falco 0.31, Falco also supports additional event sources through the Plugin System:

In addition to these plugins hosted by the Falcosecurity organization, others have written third-party plugins that support additional event sources. Please refer to the official Plugin Registry for the most up-to-date information regarding the Falco plugins acknowledged by the community.