Documentation ¶
Index ¶
Constants ¶
View Source
const ( AuditOnlyDefault = true UniqueDefault = false )
View Source
const ( AuditOnlyParam = "audit-only" UniqueParam = "unique" )
Variables ¶
This section is empty.
Functions ¶
func GetColumns ¶
Types ¶
type Event ¶
type Event struct { eventtypes.Event eventtypes.WithMountNsID Pid uint32 `json:"pid,omitempty" column:"pid,template:pid"` Comm string `json:"comm,omitempty" column:"comm,template:comm"` Syscall string `json:"syscall,omitempty" column:"syscall,template:syscall"` Uid uint32 `json:"uid" column:"uid,template:uid,hide"` Gid uint32 `json:"gid" column:"gid,template:gid,hide"` Cap int `json:"cap,omitempty" column:"cap,width:3,fixed"` CapName string `json:"capName,omitempty" column:"capName,width:18,fixed"` Audit int `json:"audit,omitempty" column:"audit,minWidth:5"` Verdict string `json:"verdict,omitempty" column:"verdict,width:7,fixed"` InsetID *bool `json:"insetid,omitempty" column:"insetid,width:7,fixed,hide"` TargetUserNs uint64 `json:"targetuserns,omitempty" column:"targetuserns,template:ns"` CurrentUserNs uint64 `json:"currentuserns,omitempty" column:"currentuserns,template:ns"` Caps uint64 `json:"caps,omitempty" column:"caps,hide"` CapsNames []string `json:"capsNames,omitempty" column:"capsnames,hide"` }
func Base ¶
func Base(ev eventtypes.Event) *Event
Click to show internal directories.
Click to hide internal directories.