Skip to content

Alert Outputs

Falco is designed to output alerts in various formats, enabling integration with monitoring systems like Prometheus, ELK (Elasticsearch, Logstash, Kibana), and cloud-native logging platforms. Configuring these outputs requires modifying Falco's configuration file (falco.yaml) to define the desired destinations. Below are examples for each integration.


Configuring Falco for Prometheus Integration

Falco can send alerts to Prometheus via the remote write protocol. This requires a Prometheus server or Prometheus Operator instance to receive the metrics.

Example Configuration

outputs:
  - type: prometheus
    url: http://prometheus-server:9090/api/v1/write

Command to Run Falco

falco --config /path/to/falco.yaml

Notes: - Ensure the Prometheus server is accessible at the specified URL. - Use the Prometheus Operator for Kubernetes environments to manage the Prometheus instance.


Config

outputs:
  - type: http
    url: http://elasticsearch:9200
    format: json

Command to Run Falco

falco --config /path/to/falco.yaml

Notes: - Elasticsearch must be running and accessible at the specified URL. - For advanced parsing, use Logstash to process the JSON logs before indexing them in Elasticsearch.


Configuring Falco for Cloud-Native Logging Systems

Fluentd Integration

Falco can send logs to a Fluentd instance using the TCP protocol.

Example Configuration

outputs:
  - type: fluentd
    address: tcp://fluentd:24224

Command to Run Falco

falco --config /path/to/falco.yaml

Notes: - Fluentd must be running and listening on the specified address. - Use Fluentd's plugins to enrich or route logs further.

Loki Integration

Falco can push logs directly to Loki via HTTP.

Example Configuration

outputs:
  - type: loki
    url: http://loki:3100/loki/api/v1/push

Command to Run Falco

falco --config /path/to/falco.yaml

Notes: - Loki must be running and accessible at the specified endpoint. - Loki's ingestion endpoint is typically /loki/api/v1/push.


Key takeaways

  • Prometheus: Use the prometheus output type with a remote write URL to send metrics.
  • ELK: Configure the http output with Elasticsearch's endpoint for log storage.
  • Cloud-Native Logging: Use fluentd for TCP-based logging or loki for HTTP-based ingestion.
  • Always validate network connectivity and adjust URLs based on your environment's deployment.