3 ms·
I'd argue no. While you still receive all the syscalls that are made within each container, there is no way to differentiate those calls from ones made directly
by rkv 10y ago
I'd argue no. While you still receive all the syscalls that are made within each container, there is no way to differentiate those calls from ones made directly on the host. So no filtering or analytics can be made for containers. This is a known issue of the audit framework in Linux.