VOOZH about

URL: https://thenewstack.io/how-falco-brought-real-time-observability-to-infrastructure/

⇱ How Falco Brought Real-Time Observability to Infrastructure - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2024-12-26 05:52:45
How Falco Brought Real-Time Observability to Infrastructure
podcast,sponsor-cncf,sponsored-podcast-day-of-podcasting,video,
eBPF / Observability / Open Source / Security

How Falco Brought Real-Time Observability to Infrastructure

In this episode of The New Stack Makers, three maintainers of the Falco project tell how the runtime security project evolved and what's next.
Dec 26th, 2024 5:52am by Heather Joslyn
👁 Featued image for: How Falco Brought Real-Time Observability to Infrastructure
CNCF sponsored this post.

SALT LAKE CITY — Falco was designed to solve a particular problem: How to gain observability of an application at runtime.

Loris Degioanni, founder and now CTO of Sysdig, spearheaded the creation of Falco, “a tool able to collect events that are happening at inside the kernel, the core of the system,” said Thomas Labarussias in this On the Road episode of The New Stack Makers.

Labarussias, a senior developer advocate at Sysdig, along with two of his colleagues, joined me to talk about Falco’s evolution as an open source project and what’s ahead for it, in this episode of Makers recorded at KubeCon + CloudNativeCon North America in November.

The runtime observability and security project graduated in February from the Cloud Native Computing Foundation, six years after it entered the CNCF sandbox. It collects data including pod names, name spaces and other elements of events, and then correlates them with rules.

“It’s really particularly different from the other systems, in that we are not doing analysis, static analysis, of the code base of the images we are in,” Labarussias said. “We are collecting events on the fly, like a stream, We are trying to be, as much as possible, real time.”

The tool uses a kernel module to collect events directly from the kernel, said Luca Guerra, senior open source engineer at Sysdig. And it uses eBPF technology to accomplish its tasks.

“Recently, we had great advancements with eBPF that allows us to essentially have much better safety on our kernel side, which is the closer part to the operating system, where every bug might be a bigger problem than it is in other applications,” Guerra said.

He also credited work by the Linux Foundation that has made it easier to install Falco, “without having to provide separate packages for all different kernel versions that that we might be running.”

The project maintainers want to make Falco “easy to install in every environment, whether the systems are new, whether you are using the latest and greatest technologies or some old and stable versions. We want Falco to cover everything, pretty much.”

Falco’s Roadmap

Since Falco moved to the CNCF incubator from the sandbox in 2020, the project maintainers’s focus has been on achieving technical maturity, said Leonardo Grasso, open source tech lead manager at Sysdig.

The only true obstacle the team encountered, he said, was that the process of finally achieving graduation lasted so long; the team wound up giving the CNCF feedback about streamlining the process going forward.

Looking ahead, Grasso said, the team is focused on two things. One is extending Falco’s core functionality.  “For example, we are introducing a lot of options to customize the rules or even the format of the alerts,” he said. “But also, most importantly, we are extending the syntax that is used to describe the rules.”

Another destination on the roadmap: Falco Talon, a “no-code, tailor-made response engine for Falco,” Guerra said.

Open source Talon was introduced in September. “The missing part in our organization or ecosystem was a reaction. So we have a lot of things for the detections, for the notifications, for the visualization, but there was a missing part and people were asking that for a long time,” he said.

“So we introduced something called Talon. And basically, you write tools like you do for Falco, but to correlate Falco alerts with actions, to fire, to remediate, to these alerts, once again, we are trying to do it in real time, in as short a time as possible.”

Check out the full episode for more on Falco’s past, present and future.

The Cloud Native Computing Foundation (CNCF) hosts critical components of the global technology infrastructure including Kubernetes, OpenTelemetry, and Argo. CNCF is the neutral home for cloud native collaboration, bringing together the industry’s top developers, end users, and vendors.
Learn More
The latest from CNCF
TRENDING STORIES
Heather Joslyn is the former editor-in-chief of The New Stack. She previously worked as editor-in-chief of Container Solutions, a Cloud Native consulting company, and as an editor/reporter at The Chronicle of Philanthropy and the Baltimore City Paper.
Read more from Heather Joslyn
CNCF sponsored this post.
SHARE THIS STORY
TRENDING STORIES
TNS owner Insight Partners is an investor in: Sysdig.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.