Skip to content

[FEAT] tracee source flag #4425

Open
Open
@NDStrahilevitz

Description

@NDStrahilevitz
  1. Remove analyze subcommand
  2. Integrate functionality as a source flag in tracee - "analyze" will merely be a reingestion of event input into the pipeline
  3. Split pipeline beginning into an interface for a source program
  4. Two implemented source subprograms - eBPF and json file - which can feed the pipeline
  5. Open Question: How do we prevent an already derived event from rederiving and introducing duplicates in the output

Metadata

Metadata

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions